Skip to content
Enforcement · French Data Protection Authority (CNIL) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security

The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE.

€1,500,000 Fine
DEDALUS BIOLOGIE
FRANCE
Art. 28 GDPR Art. 29 GDPR Art. 32 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press revealed a data leak at DEDALUS that resulted in the leak of nearly 500,000 individuals' data. The leaked data included information on the surnames, first names, social security number, name of the treating physician, data on medical examinations and illnesses of the data subjects. During its investigation, the CNIL found several violations of the GDPR. Namely, DEDALUS had violated Art. 29 GDPR by extracting more data than required in the course of processing on behalf of two laboratories. In addition, the DPA found that DEDALUS had failed to implement appropriate technical and organizational measures to ensure the security of personal data. This constitutes a violation of Art. 32 GDPR. For example, no specific procedure for data migration operations had been implemented.

§

Also, the leaked data had not been stored in encrypted form on the server. In addition, the DPA found that DEDALUS lacked authentication for access to the public area of the server. The absence of such security measures was one of the main causes of the data leak. Further, the DPA found that the contractual documents between DEDALUS and its customers did not comply with the requirements set forth in Art. 28 GDPR. The DPA took into aggravating consideration the seriousness of the violations committed, in particular the security breaches, as well as the large number of individuals affected, when imposing the fine. GDPR Articles: Art. 28 GDPR, Art. 29 GDPR, Art. 32 GDPR Industry: Health Care

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Feb 24, 2023 Certification International Transfer Processing Agreement