Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 3 December 2020
Aleris Sjukvård AB
Insufficient technical and organisational measures to ensure information security
- Regulator
- Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
- Decided
- 3 December 2020
- Country
- Sweden
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/SE/009
What happened
The Swedish DPA (Datainspektionen) imposed a €1.466 million (approximately) fine on the healthcare provider "Aleris Sjukvård AB" for not carrying out the risk assessments required by the Patient Data Act and for granting their employees access to all personal data in the patients' journal system in breach of Article 32 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f) · 5(2)Read →
- Art. 32Security of processing32(1) · 32(2)Read →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/SE/009.