Sanction RGPD Norwegian Supervisory Authority (Datatilsynet) — Moss municipality : 49 k€ (2021)

Autorité de contrôle
Norwegian Supervisory Authority (Datatilsynet)
Pays
Norvège
Entreprise / secteur
Moss municipality
Montant de l'amende
49 k€
Date de la décision
4 juin 2021
Fondement juridique
Art. 32 (1) b), d)
Manquement
Mesures techniques et organisationnelles insuffisantes

Résumé des faits

The Norwegian DPA (Datatilsynet) has fined the municipality of Moss EUR 49,200 for inadequately securing personal data. In January, the municipality of Rygge was annexed to the municipality of Moss. For this reason, several IT systems from both municipalities were combined. Due to inadequate security measures, a data breach occurred in a productive system used in the municipality's health service. This system processed personal and health data and affected people who live in the municipality and use the health center. The system is used for services related to immunization programs in the municipality, as well as for other health checks and follow-ups of pregnant women. About 2000 people were potentially affected by the breach. Due to the data breach, errors had occurred in vaccine registration. As a result, the data subjects were at risk of receiving the wrong vaccines. There was also a potential for their immunization data to be misfiled in the national immunization registry. Furthermore, errors occurred in follow-ups for pregnant women, including information on the week of pregnancy or the mother's drug use. Also, patient information was provided to health workers in a health service ward without being required and without access being documented.

Décision officielle

Norwegian Supervisory Authority (Datatilsynet)

Évaluer votre conformité RGPD avec Data Comply One