Danish Immigration Agency

€20,100

Insufficient technical and organisational measures to ensure information security

Datum för beslut

17 augusti 2021

Myndighet

Danish Data Protection Authority (Datatilsynet)

DK

Sektor

Public Sector and Education

Land

DK

Lag

GDPR

Status

FINAL

Beskrivning

The Danish DPA has imposed a fine of EUR 20,100 on the Danish Immigration Agency. Media reports brought the DPA's attention to possible logging errors in one of the agency's IT systems, which could have an impact on the rights and freedoms of residents. The DPA consequently started an investigation at the agency. In spring and summer 2020, several security incidents occurred in the agency's systems, resulting in the loss of data records. The loss of data led to proceedings being initiated against a number of residents regarding the reduction of their cash benefits, and a number of residents being reported to the police for non-compliance with the provisions of the Foreigners Act. During its investigation, the DPA found that a lack of technical and organizational measures allowed the incident to occur. For instance, the agency had not made adequate backups of the data processed, although this would have been necessary in view of the legal consequences a loss of the data could mean for the immigrants.

Rättsliga hänvisningar

Art. 5 (1)Art. 32

Frågor och överträdelser

Insufficient technical and organisational measures to ensure information security

Håll dig uppdaterad om efterlevnaden av sekretessreglerna

Vi respekterar din integritet. Ett e-postmeddelande per månad, ingen skräppost, avsluta prenumerationen när som helst.