Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) · 24 August 2021
Actamedica SRL
Insufficient technical and organisational measures to ensure information security
- Regulator
- Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Decided
- 24 August 2021
- Country
- Romania
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/RO/008
What happened
The Romanian DPA fined a controller approximately €3000 (RON 9836.60) for failing to implement appropriate technical and organisational measures which lead to the disclosure of the complainant's biological samples. The controller also failed to notify the DPA of the incident and answer the complainant's request regarding details on the disclosure.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 28Processor28(1)Read →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data security
- Processor obligations
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/RO/008.