Fino

French Data Protection Authority (CNIL) · 17 December 2020

Doctor

Insufficient technical and organisational measures to ensure information security

Fine€6,000Fine issued
Regulator
French Data Protection Authority (CNIL)
Decided
17 December 2020
Country
France
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2020/FR/002
Export as PDF

What happened

The French DPA (CNIL) imposed a €6,000 fine on a private doctor for violating Article 32 GDPR by making his patients' health data freely accessible on the web, and Article 33 GDPR by not notifying the DPA of said breach.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/002.