Enforcement · Data Protection Authority of Hessen EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Covid-19 test center: Insufficient legal basis for data processing
How it connects
Related across sources
Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II) Literature GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection Literature GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR Literature GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR Case Law SG Nürnberg - S 5 SF 65/24 DS Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)
Full text
The DPA of Hessen has fined a Covid-19 test center EUR 16,400. The controller had sent an e-mail containing personal data to several recipients in an open distribution list. The DPA also found that the controller had failed to adequately document the data breach.
Industry: Health Care
Original document at the source www.zaftda.de