Enforcement
EN Clinic owner: Insufficient legal basis for data processing
€10,000 fine - Spanish Data Protection Authority (aepd)
Content
The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the clinic on social media (Facebook and Instagram) without obtaining the individual’s consent.
GDPR Articles: Art. 6 (1) GDPR, Art. 9 GDPR
Industry: Health Care