Skip to content
Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Doctor: Insufficient technical and organisational measures to ensure information security

The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art.

€6,000 Fine
Doctor
FRANCE
Art. 32 GDPR Art. 33 GDPR

Full text

The French DPA (CNIL) fined a doctor EUR 6,000 for violations of Art. 32 GDPR and Art. 33 GDPR. The controller had stored medical image data such as MRI and X-ray images as well as personal data such as names, dates of birth and treatment data of his patients on a server in order to be able to access them from his home computer. A review of the controller's systems had revealed that access to the server was not properly secured. This would have allowed anyone to access his patients' data. Furthermore, the data leak had existed for about five years. The data protection authority therefore found that the doctor had failed to take adequate technical and organisational measures to ensure data security.

Industry: Health Care

How it connects

C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
W292 2292202-1 The data subject is in the military The unit he is employed at (controller) and the data subject are involved in a multitude of legal disputes concerning his employment, disciplinary proceedings, data protection… BVwG - W292 2292202-1 ·Federal Administrative Court Jun 30, 2026 Health Data Legitimate Interest Healthcare