# Dentist: Insufficient legal basis for data processing

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2023-01-31
- Original: https://www.enforcementtracker.com/ETid-1601
- Canonical: https://overview.legal/posts/47716
- Topics: Healthcare, Health Data, Healthcare, Consent, Controllers, Personal Data, Processing, Processing Agreement, Data Controller, Supervisory Authorities

## Summary

The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However, it had failed to obtain the patient's consent before publishing the medical data. Therefore, the DPA found that the controller had unlawfully processed the data.

## Full text

The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However, it had failed to obtain the patient's consent before publishing the medical data. Therefore, the DPA found that the controller had unlawfully processed the data.

GDPR Articles: Art. 6 (1) a) GDPR, Art. 9 (2) a) GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/47716 · 2026-08-22
