GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Public Roads Administration of Norway

Country
Norway
Fine
367,000 EUR
Date
Norwegian Data Protection Authority (Datatilsynet)(Norwegian Data Protection Authority (Datatilsynet))
Articles
Art 17 GDPRArt 25 GDPR

The public roads administration had failed to comply with its obligations under the GDPR Article 17 (Right to erasure)

The public roads administration of Norway is the controller for a system processing and storing personal data from the toll road systems of Norway, i.e. data collected when different identifiable vehicles pass the different public toll stations. This information is then used for billing the owners of the vehicles. Under the Norwegian accounting rules, personal data pertaining to customer invoicing must be stored for 5 years after the end of the accounting year, however the public roads administration had not deleted any personal data from its system upon expiry of the 5 year term, as the data system used for the processing did not have functionality for deletion. The public roads administration had therefore failed to comply with its obligations under the GDPR Article 17 (Right to erasure), as well as having failed to implement functionality in the data solution that would allow such deletion, in violation of the GDPR Article 25 (Data protection by design and by default). The DPA have has been threatened with a fine of NOK 4,000,000. The public roads administration has been given a deadline until 23 March 2020 to give its account, after which the DPA will make a final decision in the case.

Reported by: Gjessing Reimers