Bergen Municipality

€170,000

Insufficient technical and organisational measures to ensure information security

결정 날짜

2019년 3월 1일

권한

Norwegian Supervisory Authority (Datatilsynet)

NO

섹터

Public Sector and Education

국가

NO

법률

GDPR

상태

FINAL

설명

The incident relates to computer files with usernames and passwords to over 35000 user accounts in the municipality’s computer system. The user accounts related to both pupils in the municipality’s primary schools, and to the employees of the same schools. Due to insufficient security measures, these files have been unprotected and openly accessible. The lack of security measures in the system made it possible for anyone to log in to the school’s various information systems, and thereby to access various categories of personal data relating to the pupils and employees of the schools. The fact that the security breach encompasses personal data to over 35 000 individuals, and that the majority of these are children, were considered to be aggravating factors. The municipality had also been warned several times, both by the authority and an internal whistleblower, that the data security was inadequate.

법적 인용

Art. 5 (1)Art. 32

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.