Skip to content
Enforcement · Icelandic data protection authority ('Persónuvernd') EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

HEI – Medical Travel: Insufficient fulfilment of data subjects rights

€10,600 Fine
HEI – Medical Travel
ICELAND
Art. 15 GDPR Art. 9 GDPR Art. 17 GDPR

How it connects

Full text

The Icelandic DPA has imposed a fine of EUR 10,600 on HEI - Medical Travel. A data subject had filed a complaint with the DPA against the controller. The controller had gained access to the data subject's email via the Icelandic Medical Association's internal website and had then sent them unsolicited emails. The DPA found that such access was unlawful due to the lack of a valid legal basis. In addition, the data subject had asked the controller for information about the processing of their personal data, such as the origin of the e-mail address. The controller did not properly comply with this request.

Industry: Health Care

Similar Content