# Covid-19 test center: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Data Protection Authority of Hamburg
- Date: 2022-01-01
- Original: https://www.enforcementtracker.com/ETid-1745
- Canonical: https://overview.legal/posts/47860
- Topics: Encryption, Healthcare, Security, Personal Data, Processing Agreement, Law Enforcement, Supervisory Authorities

## Summary

The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them to access the test result without taking any further security measures. In some cases, the download link was structured in a way that led to the download of a PDF file with the file name corresponding to the last name of the person tested. With knowledge of the directory path, it was therefore possible to view third-part

## Full text

The DPA of Hamburg has imposed a fine of EUR 2,700 on a Covid-19 test center. The test center had send the data subjects an unencrypted e-mail containing a URL that allowed them to access the test result without taking any further security measures. In some cases, the download link was structured in a way that led to the download of a PDF file with the file name corresponding to the last name of the person tested. With knowledge of the directory path, it was therefore possible to view third-party test results.

GDPR Articles: Art. 32 (1) GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/47860 · 2026-08-22
