AEPD (Spain) · 30 September 2022
Consejeria de Sanidad de la Comunidad de Madrid
About: Accountability, Data principles, Data security, Special categories
FineNo fineViolation found
- Regulator
- AEPD (Spain)
- Decided
- 30 September 2022
- Country
- Spain
- Sector
- Not given
- Regulator’s reference
- PS-00587-2021
- Fino case number
- 2022/ES/234
What happened
Spanish DPA held a controller responsible for a data breach since they did not have sufficient measures in place to avoid data breaches. Although some measures were applied, they did not provide an adequate level of protection for sensitive data.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 4DefinitionsRead →
- Art. 5Principles relating to processing of personal data5(1)(f) · 5(2)Read →
- Art. 9Processing of special categories of personal data9(1)Read →
- Art. 24Responsibility of the controllerRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Art. 57Tasks57(1)Read →
- Art. 58Powers58(2)Read →
- Art. 83General conditions for imposing administrative fines83(4) · 83(5) · 83(7)Read →
- Accountability
- Data principles
- Data security
- Special categories
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/ES/234.