The Norwegian Data Protection Authority has decided to impose a sanction of 400.000 NOK to the Høylandet municipality. Files that include images with personal health information without a connection with the municipality were available to employees of the health center.
Sanction to the Høylandet municipality
The Norwegian Data Protection Authority has underlined that the municipality has not adopted any relevant measure after having discovered the gap.
For this reason, the Authority has decided to impose a sanction against the municipality for serious deficiencies into the inner access controls. This makes a breach of security requirements for personal data pursuant to the privacy ordinance.
The error has been corrected and the municipality has also introduced a new system of inner control.
The municipality has a period of appellation of three weeks since the reception of the decision at the end of September.