Description

Issued Interim Ruling by Data Protection Agency on Netcompany's Alleged Failure to Implement Security Measures

On 12 January 2024, Datatilsynet, the Data Protection Agency reported Netcompany to the police and recommended a fine of at least DKK 15 million. The agency found that Netcompany, as the data controller, failed to implement adequate security measures during the development of mit.dk, a digital mail solution for citizens and businesses. An error in the coding allowed users unauthorised access to other users' digital mail, including confidential and sensitive information. Further, Netcompany failed to conduct an impact analysis before the launch of the solution. As a result, Datatilsynet recommendad its largest fine so far.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
software provider: other software
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-01-12
under investigation

On 12 January 2024, Datatilsynet, the Data Protection Agency reported Netcompany to the police and …

2024-05-23
concluded

On 23 May 2024, the Norwegian Data Protection Authority (Datatilsynet) concluded its investigation …