Skip to content
News · European Data Protection Board EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire

How it connects

C-667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der… CJEU ·Third Chamber Dec 21, 2023 Special Categories of Data Liability Controllers
DSB-D124.0850/25 Health data that is required for an expert opinion in a court proceeding can be processed under Article 9(2)(f) and (g) GDPR in conjunction with Austrian national law and, the… DSB-D124.0850/25 ·Austria ·Art. 9 Sep 8, 2026 Health Data Personal Data Special Categories of Data
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Liability
C‑474/24 NADA Austria and Others CJEU - C‑474/24 - NADA Austria and Others Several data subjects were subject to suspension proceedings by the Austrian Anti-Doping Legal Commission (ÖADR). Under Austrian law, the National Anti-Doping Agency (“NADA”)… Jul 24, 2026 Criminal Data Special Categories of Data Types of Special Categories of Personal Data
1 As 183/2023-62 Health insurer must disclose aggregated patient treatment data under Free Access to OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free… Supreme Administrative Court Aug 4, 2026 Personal Data Special Categories of Data Pseudonymization

Full text

Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).Key findingsFailure to en