Hotel Online AS
c/o Oslo Exempt from public
International Hub disclosure:
Oscars gate 27
Offl. § 20 første ledd B
0352 OSLO
IMI Case Rep. reference Our reference Date
293985 20/02292-8 03.05.2021
Closure of case
We refer to our latest request for information dated 4 January 2021 and your letter dated 23
January 2021.
A complaint has been lodged with the Norwegian SA against you, Hotel Online AS (formerly
Global Travel Technology AS/European Travel Group AS). We are the leading supervisory
authority as Cityhotels.no/com is a hotel portal owned by you as a Norwegian registered
company with your main establishment in Norway.
The subject matter of the complaint is an alleged breach of security of processing. The
complainant booked a hotel through cityhotels.no. Upon completion of the transaction, an
order confirmation was given in the form of a web-page. The complainant discovered that
basic manipulation of the URL of the web-page revealed order confirmations of other
customers. Order confirmations include information such as the name and home address of
the data subject, the hotel booked, dates of stay and price.
You acknowledge the lack of security of processing when processing personal data through
your booking website www.cityhotels.no. After we made you aware of the security issue
connected to the booking website, you have closed down www.cityhotels.no. You are also in
the process of establishing a new booking system on cityhotels.com, with a brand new
solution that you have stated will satisfy the requirements of the GDPR.
We refer to your full response to our order to provide information regarding all measures you
have taken.
Postadresse: Kontoradresse: Telefon: Org.nr: Hjemmeside: 1
Postboks 458 Sentrum Trelastgata 3 22 39 69 00 974 761 467 www.datatilsynet.no
0105 OSLO 0191 OSLO
Generally, this type of lack of security of processing could have adverse personal data
consequences. However, in the view of the Norwegian SA, you has taken adequate and
appropriate measures to address the issue by closing down the website and getting data
protection expertise when setting up a new booking website. In addition, we have no
information that personal data of costumers has been abused by manipulating the URL.
Taking into account the above, the Norwegian SA not see a need to pursue this matter
further. We therefore close the case.
Kind regards
Tobias Judin
Head of Section
Tanja Czelusniak
Legal advisor
This letter has electronic approval and is therefore not signed
Copy: Complainant
2