Municipality of Frederiksberg
Insufficient technical and organisational measures to ensure information security
Dátum rozhodnutia
16. decembra 2021
Úrad
Danish Data Protection Authority (Datatilsynet)
DK
Sektor
Public Sector and Education
Krajina
DK
Právo
GDPRStav
FINALPopis
The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR. The municipality's dental care service had operated a system through which parents could access their children's dental care letters online. The municipality then extended this access to parents with joint custody. As a result, in several cases, parents gained access to information about the other parent and the child's address, even though the affected parent and child were registered with name and address protection. The DPA considered this to be a breach of the municipality's duty to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to the data subjects.