Enforcement · Deputy Data Protection Ombudsman EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Yliopiston Apteekin: Non-compliance with general data processing principles
The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin.
Full text
The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These tools were implemented in a way that allowed the providers, who are based outside the EU, to access personal data. The controller also failed to ensure that the tools complied with the principle of data minimization.
Industry: Health Care
How it connects
References
Related across sources
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Jan 30, 2020 Personal Data Processing Material scope (GDPR)
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data