Skip to content
News · European Data Protection Board EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Health data breach: the CNIL fined Hôpital Privé de la Loire EUR 500 000

Full text

Background informationDate of final decision: 3 September 2026National caseController: Hôpital Privé de la LoireLegal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fineKeywords: Cybersecurity, Personal data breaches, Health and researchSummary of the DecisionOrigin of the caseIn summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).Key findingsFailure to en

How it connects

€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Jul 21, 2026 Data Breaches Notification Obligation Healthcare
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026 Data Breaches Notification Obligation Controllers
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Sep 3, 2026 Integrity and Confidentiality Principle Data Breaches Right of Access
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer