Enforcement · Spanish Data Protection Authority (aepd) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Owner of a Pharmacy Office: Non-compliance with general data processing principles
The Spanish DPA has imposed a fine on the owner of a pharmacy office.
Full text
The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The controller also failed to inform the data subjects about the fact, that the controller processed their data and that they obtained the data from a third party. Lastly, the controller failed to use encrypted email services. The original fine of EUR 11,000 was reduced to EUR 6,600 due to immediate payment and admission of responsibility by the controller.
Industry: Health Care
How it connects
Related across sources
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) CJEU Dec 14, 2023 Integrity and Confidentiality Principle Data Breaches Notification Obligation
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Jan 30, 2020 Personal Data Processing Material scope (GDPR)
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data