
Summary The Danish DPA has fined the municipality of Frederiksberg EUR 13,450. On March 1, 2021, the municipality reported a data breach under Art. 33 GDPR.

The municipality’s dental care service had operated a system through which parents could access their children’s dental care letters online. The municipality then extended this access to parents with joint custody. As a result, in several cases, parents gained access to information about the other parent and the child’s address, even though the affected parent and child were registered with name and address protection.
The DPA considered this to be a breach of the municipality’s duty to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk to the data subjects.

Link: link
Related articles:  Art. 32 GDPR
Type: Insufficient technical and organisational measures to ensure information security
Fine: EUR 13,450
Sector Public Sector and Education


All data is based on The CMS’s Law GDPR Enforcement Tracker Source:

Tags: case law