French Data Protection Authority (CNIL) · 17 December 2020
Doctor
Insufficient technical and organisational measures to ensure information security
Fine€6,000Fine issued
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 17 December 2020
- Country
- France
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/FR/002
What happened
The French DPA (CNIL) imposed a €6,000 fine on a private doctor for violating Article 32 GDPR by making his patients' health data freely accessible on the web, and Article 33 GDPR by not notifying the DPA of said breach.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/FR/002.