Deputy Data Protection Ombudsman · 7 December 2021
Psykoterapiakeskus Vastaamo
Non-compliance with general data processing principles
- Regulator
- Deputy Data Protection Ombudsman
- Decided
- 7 December 2021
- Country
- Finland
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/FI/004
What happened
The Finnish DPA fined a psychotherapy firm €608,000 for not reporting two personal data breaches in due time, which led to the disclosure of patient records to the attackers responsible for the breaches, and for failing to ensure the security of personal data. Both the firm and the patients were blackmailed following these data breaches.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 33Notification of a personal data breach to the supervisory authority33(1)Read →
- Art. 34Communication of a personal data breach to the data subject34(1)Read →
- Data breach
- Data principles
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/FI/004.