City of Kópavogur

€20,000

Non-compliance with general data processing principles

決定日期

2023年12月6日

權限

Icelandic data protection authority ('Persónuvernd')

IS

部門

Public Sector and Education

國家

IS

法律

GDPR

狀態

FINAL

說明

The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur. The city had used the Google Education system without sufficiently complying with data protection regulations. In particular, the city did not fulfill its obligations when selecting Google as a processor and the processing agreement with Google did not comply with data protection requirements. Furthermore, the city did not ensure that the student data was not processed for purposes other than those specified by the city. Furthermore, the retention period was not considered appropriate but rather too extensive. In imposing the fine, particular consideration was given to the protection of sensitive children's data. Although no demonstrable damage had occurred, it was criticized that the city had not sufficiently ensured the secure transfer of data to the US in the past. However, the city cooperated transparently with the data protection authority and revised its data protection practices.

法律引文

Art. 5 (1)Art. 24 (1)Art. 28

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。