NAIH (Hungary) · 14 March 2021
Budapest Főváros Kormányhivatala XI. kerületi Hivatala
About: Data breach, Data security
- Regulator
- NAIH (Hungary)
- Decided
- 14 March 2021
- Country
- Hungary
- Sector
- Not given
- Regulator’s reference
- NAIH-2894-3/2021
- Fino case number
- 2021/HU/009
What happened
The Hungarian DPA (NAIH) held that transferring health data without password protection to general practitioners not authorised to access such data constitutes a personal data breach resulting in a high risk to the rights and freedoms of natural persons. The emergency situation caused by the Covid-19 pandemic does not exempt public authorities from taking appropriate data security measures and from lawfully processing personal data.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 32Security of processing32(1)(a) · 32(1)(b) · 32(2)Read →
- Art. 33Notification of a personal data breach to the supervisory authority33(1)Read →
- Art. 34Communication of a personal data breach to the data subject34(1)Read →
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/HU/009.