French Data Protection Authority (CNIL) · 15 April 2022
DEDALUS BIOLOGIE
Insufficient technical and organisational measures to ensure information security
Fine€1,500,000Fine issued
- Regulator
- French Data Protection Authority (CNIL)
- Decided
- 15 April 2022
- Country
- France
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/FR/009
What happened
The French DPA issued a fine of €1,500,000 against a software solutions provider acting as a processor for medical analysis laboratories, due to a data breach concerning the data of almost 500,000 data subjects in violation of Articles 28, 29, and 32 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 28ProcessorRead →
- Art. 29Processing under the authority of the controller or processorRead →
- Art. 32Security of processingRead →
- Data security
- Processor obligations
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/FR/009.