Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 7 June 2021
MedHelp AB
Non-compliance with general data processing principles
- Regulator
- Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
- Decided
- 7 June 2021
- Country
- Sweden
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/SE/004
What happened
The Swedish DPA fined the company Medhelp AB €1,179,459 (SEK 12 million). Medhelp was contracted by three Swedish regions to answer calls from the medical advice hotline 1177. Medhelp violated the GDPR by exposing an unprotected server with patient data to the internet, failing to provide enough information about the transfer of data to a third country, and failing to continuously back up patient data. In addition, Medhelp employed a subcontractor to process data in Thailand contrary to Swedish healthcare law.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 6Lawfulness of processingRead →
- Art. 9Processing of special categories of personal data9(1)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Special categories
- Transparency
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/SE/004.