Datatilsynet (Denmark) · 18 February 2022
Capital Region of Denmark
About: Data breach, Data security
FineNo fineViolation found
- Regulator
- Datatilsynet (Denmark)
- Decided
- 18 February 2022
- Country
- Denmark
- Sector
- Not given
- Regulator’s reference
- 2020-442-8862
- Fino case number
- 2022/DK/009
What happened
The Danish DPA (Datatilsynet) held that the Capital Region of Denmark violated Article 32(1) GDPR for negligence related to its health platform's software updates, which led to two separate data breaches involving 4,459 data subjects' health data.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 32Security of processing32(1)Read →
- Art. 33Notification of a personal data breach to the supervisory authority33(3)Read →
- Art. 34Communication of a personal data breach to the data subject34(2)Read →
- Art. 58Powers58(2)(a) · 58(2)(d)Read →
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/DK/009.