AN ADMISNISTRATIVE FINE WAS IMPOSED ON THE MUNICIPALITY OF OSLO, THE EDUCATION AGENCY
13 February 2020
The Norwegian Data Protection Authority (the “Authority”) fined the Municipality of Oslo, the Education Agency €120.000 because that the municipality had not implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk in ‘Skolemelding’ mobile app used for communication between school employees, parents and pupils.
In the assessment of the Authority, it is found that the app enables communication of special category personal data, such as health data, regarding the children and there are no technical measures to avoid such transmission. Moreover, it is possible for unauthorised persons to access and alter personal due to poor app login security.
The municipality implemented measures to limit the damages as soon as it was made aware of the security flaws, and it has shown willingness to resolve the issues so that
The municipality did not appeal the decision.
You can find the text of the news here.
Should you have any queries and/or remarks, please do not hesitate to contact us.