Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 3 December 2020
Sahlgrenska University Hospital
Insufficient technical and organisational measures to ensure information security
Fine€341,300Fine issued
- Regulator
- Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
- Decided
- 3 December 2020
- Country
- Sweden
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/SE/005
What happened
The Swedish DPA (Datainspektionen) fined a university hospital approximately €34 000 for giving its staff wider access to medical records than they needed to do their jobs.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f) · 5(2)Read →
- Art. 32Security of processing32(1) · 32(2)Read →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/SE/005.