City of Hafnarfjörður

€18,600

Non-compliance with general data processing principles

Ngày ra quyết định

6 tháng 12, 2023

Thẩm quyền

Icelandic data protection authority ('Persónuvernd')

IS

Ngành

Public Sector and Education

Quốc gia

IS

Luật

GDPR

Trạng thái

FINAL

Mô tả

The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection regulations. In particular, the city did not fulfill its obligations when selecting Google as a processor and the processing agreement with Google did not comply with data protection requirements. Furthermore, the city did not ensure that the student data was not processed for purposes other than those specified by the city. Furthermore, the retention period was not considered appropriate but rather too extensive. In imposing the fine, particular consideration was given to the protection of sensitive children's data. Although no demonstrable damage had occurred, it was criticized that the city had not sufficiently ensured the secure transfer of data to the US in the past. However, the city cooperated transparently with the data protection authority and revised its data protection practices.

Trích dẫn pháp lý

Art. 5 (1)Art. 24 (1)Art. 28

Vấn đề & Vi phạm

Non-compliance with general data processing principles

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.