Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

Sweden: IMY fines Board of Education of Östersund Municipality SEK 300,000 for failure to conduct impact assessment

On November 30, 2023, the Swedish Authority for Privacy Protection (IMY) published its Decision No. 00070-2023, as issued on November 28, 2023, in which it imposed a fine of SEK 300,000 (approx. $28,728) on the Children and Education Board of Östersund Municipality for violation of the General Data Protection Regulation (GDPR) following use of Google Workspace for education services.

Background to the decision

In particular, IMY highlighted that Google Workspace has been used in 24 schools in Östersund Municipality and that the Board of Education is responsible for the processing of personal data when using such services in the schools. Specifically, IMY clarified that Google Workspace was used for teaching and communication during the COVID-19 pandemic. Personal data processed includes name, email address, class affiliation, and group affiliation of 5,945 students and 1,303 employees.

Findings of IMY

Following its investigation, IMY held that the Board of Education of Östersund Municipality violated Article 35(1) of the GDPR for the failure to conduct a data protection impact assessment (DPIA) prior to the use of Google Workspace. Specifically, IMY determined that pursuant to Article 35(1), which requires a DPIA for processing that is likely to lead to a high risk for the rights and freedoms of natural persons. Further, IMY held that DPIAs must be carried out in the public sector before the processing of children's personal data if there is a large number of users as the children are in a vulnerable position in relation to the data controller.

Outcomes

Therefore, IMY imposed the abovementioned fine on the Board of Education of Östersund Municipality for violating the GDPR.

You can read the press release here and the decision here, both only available in Swedish.

Feedback