Company
Insufficient legal basis for data processing
Päätöspäivä
15. maaliskuuta 2022
Viranomainen
Norwegian Supervisory Authority (Datatilsynet)
NO
Ala
Industry and Commerce
Maa
HU
Laki
GDPRTila
FINALKuvaus
The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact that after the employee's termination, both professional and private e-mails from the employee's mailbox were automatically forwarded to an e-mail address administrated by the managing director. During its investigation, the DPA found that the controller had automatically forwarded the e-mails without a valid legal basis. Also, the controller did not inform the former employee about the processing of the data by forwarding the e-mails, contrary to its obligation under Art. 13 GDPR. Finally, the DPA found that the controller did not properly comply with a request of objection to the processing submitted by the former employee.