Company
Insufficient legal basis for data processing
Datum för beslut
15 mars 2022
Myndighet
Norwegian Supervisory Authority (Datatilsynet)
NO
Sektor
Industry and Commerce
Land
HU
Lag
GDPRStatus
FINALBeskrivning
The Norwegian DPA has imposed a fine of EUR 9,700 on a company. The DPA had received a complaint from a former employee of the company. Background of the complaint is the fact that after the employee's termination, both professional and private e-mails from the employee's mailbox were automatically forwarded to an e-mail address administrated by the managing director. During its investigation, the DPA found that the controller had automatically forwarded the e-mails without a valid legal basis. Also, the controller did not inform the former employee about the processing of the data by forwarding the e-mails, contrary to its obligation under Art. 13 GDPR. Finally, the DPA found that the controller did not properly comply with a request of objection to the processing submitted by the former employee.