Fino

French Data Protection Authority (CNIL) · 21 July 2026

Hôpital privé de la Loire

Insufficient technical and organisational measures to ensure information security

Fine€500,000Fine issued
Regulator
French Data Protection Authority (CNIL)
Decided
21 July 2026
Country
France
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2026/FR/005
Export as PDF

What happened

The DPA found that a hospital, victim of a data breach, lacked sufficient measures to protect the patients data pre breach and that its reaction to the breach - assigning a shared password and failing to inform 202,246 affected third parties of the breach - was in violation of Articles 32 and 34 GDPR. The DPA fined the hospital €500,000.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data breach
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/FR/005.