Skip to content
Enforcement · Danish Data Protection Authority (Datatilsynet) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Midtjylland Region: Insufficient technical and organisational measures to ensure information security

The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region.

€53,800 Fine
Midtjylland Region
DENMARK
Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach pursuant to Art. 33 GDPR. According to the notification, all patients and staff at a lifestyle center were able to access a building where up to 100,000 physical patient records were stored, including health information and personal identity number details. The reason for this was that both staff and patients had been given key cards that allowed them to access all three buildings of the lifestyle center, regardless of whether the user was required to access them. In addition, passersby were able to take a look at the covers of some of the records -which showed personal data such as identity numbers and names - through a window in the building. In this context, the DPA found that the Midtjylland Region had not taken adequate security measures for the storage of personal data.

§

In addition, the region had not established sufficient guidelines for access restrictions when creating key cards, and had not conducted adequate periodic testing, assessment, and evaluation of the security measures taken. In evaluating the question of whether a fine should be imposed, the Danish DPA took into account, as an aggravating factor, that the region processed large amounts of sensitive data, such as health data. GDPR Articles: Art. 32 GDPR Industry: Public Sector and Education

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der… CJEU ·Third Chamber Dec 21, 2023 Health Data Healthcare Integrity and Confidentiality Principle
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision