Tietosuojavaltuutetun toimisto (Finland) · 8 June 2022
Insurance company
Name not published.
About: Accountability, Consent, Data principles, Special categories
FineNo fineViolation found
- Regulator
- Tietosuojavaltuutetun toimisto (Finland)
- Decided
- 8 June 2022
- Country
- Finland
- Sector
- Not given
- Regulator’s reference
- 7285/183/18
- Fino case number
- 2022/FI/019
What happened
The Finnish DPA held that an insurance company violated the fairness, data minimisation and data protection by default principles, among others, by requesting the entire medical record of the data subject from their healthcare provider to determine the insurance company's liability.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a) · 5(1)(b) · 5(1)(c)Read →
- Art. 7Conditions for consentRead →
- Art. 9Processing of special categories of personal dataRead →
- Art. 25Data protection by design and by default25(2)Read →
- Accountability
- Consent
- Data principles
- Special categories
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/FI/019.