APD/GBA (Belgium) · 1 April 2025
Hospital managerPrivate person
About: Accountability, Data breach, Data principles, Data security
FineNo fineRejected
- Regulator
- APD/GBA (Belgium)
- Decided
- 1 April 2025
- Country
- Belgium
- Sector
- Not given
- Regulator’s reference
- 64/2025
- Fino case number
- 2025/BE/010
What happened
The DPA held that a hospital manager who consults their subordinate's medical file in excess of its internal competences acts as controller for this processing and not the hospital. However, the hospital failed to notify the data breach to the DPA.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 4Definitions4(7)Read →
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 24Responsibility of the controllerRead →
- Art. 32Security of processing32(1)Read →
- Art. 33Notification of a personal data breach to the supervisory authority33(1)Read →
- Accountability
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/BE/010.