Icelandic data protection authority ('Persónuvernd') · 10 March 2020
National Center of Addiction Medicine ('SAA')
Insufficient technical and organisational measures to ensure information security
- Regulator
- Icelandic data protection authority ('Persónuvernd')
- Decided
- 10 March 2020
- Country
- Iceland
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/IS/002
What happened
Persónuvernd imposed a fine of ISK 3,000,000 (approx. 20,000 euro) on the organisation S.Á.Á for a security breach pursuant to Article 5(1)(f) and Article 32 GDPR. The security breach resulted in the disclosure of the names of 3,000 patients and detailed medical records of 252 individuals.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IS/002.