Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance EDPB Annual Report 2021 Guidance EDPB Annual Report 2019 Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Literature If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Guidance EDPB Annual Report 2023 Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement
Full text
The Romanian DPA has imposed a fine of EUR 5,000 on MED LIFE S.A.. The company had disposed of documents containing sensitive patient data in a publicly accessible garbage can. An individual had found these documents and filed a complaint with the DPA. During its investigation, the DPA found that MED Life had not taken adequate technical and organizational measures to protect personal data and avoid such incidents.
Industry: Health Care
Original document at the source www.dataprotection.ro