Skip to content
Content type · 475 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–475 of 475 sort newestlargest fineoldest
€4,000 Comune di Urago: Insufficient legal basis for data processing The local council has published on its website information containing a person's personal data, including health information. ITALY ·Garante ·Art. 5, 6 Healthcare Personal Data Education Feb 13, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Jan 23, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Garante ·Art. 5, 6 Healthcare Health Data Personal Data Jan 15, 2020
€10,000 Asociación de Médicos Demócratas: Insufficient legal basis for data processing The Asociación de Médicos Demócratas has processed personal data of its members, despite having been warned by the AEPD that it carried out the processing without the consent of… SPAIN ·aepd ·Art. 6 Healthcare Consent Personal Data Jan 7, 2020
Healthcare provider: Insufficient fulfilment of information obligations Czech Data Protection Auhtority (UOOU) CZECH REPUBLIC ·UOOU ·Art. 5, 12, 28 Health Data Healthcare Healthcare Jan 1, 2020
€387 Private healthcare provider: Insufficient technical and organisational measures to ensure information security The Czech DPA (UOOU) conducted an investigation against the operator of a non-governmental medical facility following a security breach. The operator offers a range of diagnostic… CZECH REPUBLIC ·UOOU ·Art. 24, 32 Healthcare Health Data Security Jan 1, 2020
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Healthcare Healthcare Security Dec 17, 2019
€105,000 Hospital: Insufficient technical and organisational measures to ensure information security The fine is based on several breaches of the GDPR in connection with a patient mix-up at the admission of the patient. This resulted in incorrect invoicing and revealed structural… GERMANY ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2019
€2,000 Nicola Medical Team 17 SRL: Insufficient cooperation with supervisory authority The company did not comply with measures ordered by the National Supervisory Authority. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Healthcare Dec 2, 2019
€500,000 Futura Internationale: Insufficient fulfilment of data subjects rights Futura Internationale was fined for cold calls after several complainants obtained cold calls, despite having declared directly to the caller and by post that this was not wanted.… FRANCE ·CNIL ·Art. 5, 6, 13 +4 Personal Data Healthcare Processing Nov 21, 2019
€60,000 Corporación radiotelevisión espanola: Insufficient technical and organisational measures to ensure information security CORPORACIÓN RADIOTELEVISIÓN ESPAÑOLA and the trade union have reported a security breach to the AEPD after six unencrypted USB sticks containing personal data were lost. The… SPAIN ·aepd ·Art. 32 Encryption Criminal Data Healthcare Nov 19, 2019
€900,000 UWV (Dutch employee insurance service provider): Insufficient technical and organisational measures to ensure information security As the UWV (the Dutch employee insurance service provider - 'Uitvoeringsinstituut Werknemersverzekeringen') did not use multi-factor authentication when accessing the online… THE NETHERLANDS ·AP ·Art. 32 Access Controls Health Data Security Oct 31, 2019
€50,000 Menzis (Health Insurance Company): Non-compliance with general data processing principles Marketing staff had access to patient data. Among other things, this violated the purpose limitation principle. THE NETHERLANDS ·AP ·Art. 5 Insurance Health Data Healthcare Oct 31, 2019
€7,400 Military Hospital: Insufficient fulfilment of data breach notification obligations A military hospital did not meet the reporting deadline for data breaches. Another part of the fine relates to a lack of technical and organisational measures. HUNGARY ·NAIH ·Art. 32, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 24, 2019
€511 B.D.: Insufficient cooperation with supervisory authority The fine of EUR 511 was imposed on B.D. for failure to provide access to information which the Commission for Personal Data Protection needed for performance of its tasks and… BULGARIA ·KZLD ·Art. 31 Supervisory Authorities Supervision Personal Data Oct 7, 2019
€2,000 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 2,000 on a legal person. The accused circumvented the law when, instead of providing social services with proper authorization, it did so… CZECH REPUBLIC ·UOOU ·Art. 5, 12, 30 Healthcare Personal Data Processing Oct 4, 2019
€25,000 Company in the medical sector: Insufficient fulfilment of information obligations The (none-final) fine was imposed on a company in the medical sector for non-compliance with information obligations and for not appointing a data protection officer. Update: The… AUSTRIA ·dsb ·Art. 13, 35, 37 Healthcare Healthcare Supervisory Authorities Aug 1, 2019
€350,000 Haga Hospital: Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Haga Hospital does not have a proper internal security of patient records in place. This is the conclusion of an investigation by the Dutch Data… THE NETHERLANDS ·AP ·Art. 32 Healthcare Health Data Healthcare Jun 18, 2019
€400,000 SERGIC (Real Estate): Insufficient technical and organisational measures to ensure information security The CNIL based the penalty on two grounds: Lack of basic security measures and excessive data storage. As to the first, sensitive user documents uploaded by rental candidates… FRANCE ·CNIL ·Art. 5 Security Access Controls Healthcare May 28, 2019
€510 Medical centers: Insufficient legal basis for data processing The sanction of 510 EUR was imposed on each medical center for unlawful processing of the personal data of data subject G.B. by a medical centre for the purpose of changing his… BULGARIA ·KZLD ·Art. 5, 6, 9 Healthcare Healthcare Integrity and Confidentiality Principle Apr 8, 2019
€80,000 GERMANY DPA: Insufficient technical and organisational measures to ensure information security In a digital publication, health data was accidentally published due to inadequate internal control mechanisms. Art. 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Security Jan 1, 2019
€294,000 GERMANY DPA: Non-compliance with general data processing principles A company was fined EUR 294 000 for 'unnecessarily long' storage and retention of personnel files and for 'excessive' data collection in the personnel selection process, during… Art. 5 ·Non-compliance with general data processing principles Health Data Healthcare IP Address Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 15 ·Insufficient fulfilment of data subjects rights Healthcare Healthcare Personal Data Jan 1, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… CYPRUS ·Art. 5, 6 ·Insufficient legal basis for data processing Healthcare Healthcare Controllers Jan 1, 2019
€400,000 Public Hospital: Insufficient technical and organisational measures to ensure information security Investigation revealed that the hospital’s staff, psychologists, dietitians and other professionals had access to patient data through false profiles. The profile management… PORTUGAL ·CNPD ·Art. 5, 32 Healthcare Health Data Healthcare Jul 17, 2018