Fino

AEPD (Spain) · 30 September 2024

HM HOSPITALES 1989

About: Data security

Fine€200,000Violation found
Regulator
AEPD (Spain)
Decided
30 September 2024
Country
Spain
Sector
Not given
Regulator’s reference
EXP202209677
Fino case number
2024/ES/139
Export as PDF

What happened

The DPA fined a controller €200,000 for failing to ensure a level of security appropriate to the large-scale processing of sensitive medical data, therefore violating Article 32 GDPR.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/ES/139.