Belgian Data Protection Authority (APD) · 19 August 2022
Medical laboratory
Insufficient technical and organisational measures to ensure information security
Fine€20,000Fine issued
- Regulator
- Belgian Data Protection Authority (APD)
- Decided
- 19 August 2022
- Country
- Belgium
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/BE/002
What happened
The Belgian DPA fined a medical laboratory €20,000 for violating Articles 5(1)(f), 12, 13, 14, 24, 25, 32, 35(1), and 35(3) GDPR due to a lack of security and a privacy policy on its website as well as its nonexistent data protection impact assessment.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 14Information to be provided where personal data have not been obtained from the data subjectRead →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/BE/002.