1(2)
Decision concerning a complaint
has lodged a complaint to the The Danish Data Protection Agency
(Datatilsynet) against Nordic Entertainment Group Sweden AB’s (NENT) for their
handling of his request to access his data. Since NENT, who is the controller1, has it’s
National Reference nr:
DI-2021-2067
main establishment in Sweden, The Danish Data Protection Agency has handed over
the complaint to the Swedish Authority for Privacy Protection (Integritetsskydds-
IMI number: myndigheten, IMY), in accordance with article 56.1 of the GDPR.2
184280
IMY shall handle complaints and investigate, to the extent appropriate, the subject
Date:
2021-08-31
matter of the complaint (article 57.1 f of the GDPR).
has requested that NENT should be ordered to provide the data by e-
mail. NENT has refused to send the data by e-mail and stated that the data has been
made available on account. NENT has stated that they cannot ensure
the proper protection of the personal data when sending it by e-mail.
Under article 5 of the GDPR, the controller shall be responsible for, and be able to
demonstrate that the personal data is being processed in a manner that ensures
appropriate security of the personal data, including protection against unauthorised or
unlawful processing and against accidental loss, destruction or damage, using
appropriate technical or organisational measures.
In accordance with article 32 of the GDPR, the controller shall implement appropriate
technical and organisational measures to ensure a level of security appropriate to the
risk.
IMY has no reason to doubt NENT’s statement regarding that they cannot ensure the
proper protection of the personal data when sending it by e-mail. For this reason IMY
does not concider NENT to have acted in violation of the GDPR and thus finds no
reason to order NENT to respond to the request by e-mail.
has also stated in his complaint that NENT has failed to act on his
request for access on time. NENT has admitted to being 8 days late to answer his
request. has now been offered acces to his personal data, albeit not in
the way he requested. NENT has stated that this breach has been remedied and that
new rutines have been put in place in order to prevent future delays. For this reason
IMY sees no need to take any action on account of the delay.
The case is hereby closed.
Postadress:
Box 8114 1 Controller means the organisation (for example a corporation, foundation, association or authority) which determines
104 20 Stockholm the purposes and means of the processing of personal data. Thus, the controller is not the supervisor of a workplace
or an employee. Natural persons can however sometimes be controllers, as in the case of sole traders. If two or more
Webbplats:
entities jointly determines the purposes and means of the processing, they have to decide between themselves who is
www.imy.se responsible for the different obligations imposed by the GDPR. The controller can outsource the actual processing of
E-post: personal data, but never transfer his or her responsibilities as controller.
2 REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the
[email protected]
protection of natural persons with regard to the processing of personal data and on the free movement of such data,
Telefon: and repealing Directive 95/46/EC (General Data Protection Regulation).
08-657 61 00
Integritetsskyddsmyndigheten Diarienummer: DI-2021-2067 2(2)
Datum: 2021-08-31
Decision Maker for IMY: Legal Advisor
, 2021-08-31 (Det här är en elektronisk signatur)