Datatilsynet (Norway) · 22 October 2020
Sykehuset Østfold HF
About: Accountability, Data principles, Data security
FineNOK750,000≈ €68,600Violation found
- Regulator
- Datatilsynet (Norway)
- Decided
- 22 October 2020
- Country
- Norway
- Sector
- Not given
- Regulator’s reference
- 20/02291
- Fino case number
- 2020/NO/015
What happened
The Norwegian DPA fined Østfold Hospital €64,400 (NOK 750,000) for insufficiently protecting patient data cf. Article 32 GDPR and Article 5(1)(f) GDPR and inadequate internal controls cf. Article 24 GDPR and Article 5(2) GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f) · 5(2)Read →
- Art. 24Responsibility of the controllerRead →
- Art. 32Security of processingRead →
- Accountability
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/NO/015.