Non-Public Health Care Institution

€7,700

Insufficient technical and organisational measures to ensure information security

Ημερομηνία απόφασης

4 Αυγούστου 2025

Αρχή

Polish National Personal Data Protection Office (UODO)

PL

Τομέας

Health Care

Χώρα

PL

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose, doctors used their private cars and carried patients' health records in them. However, in its risk analysis, the controller failed to take into account the possibility of car theft, resulting in a fine being issued.

Νομικές παραπομπές

Art. 5 (1)Art. 25 (1)Art. 32 (1)

Θέματα & Παραβάσεις

Insufficient technical and organisational measures to ensure information security

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.