Company

€122,000

Insufficient legal basis for data processing

Ημερομηνία απόφασης

27 Δεκεμβρίου 2022

Αρχή

Deputy Data Protection Ombudsman

FI

Τομέας

Industry and Commerce

Χώρα

HU

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Finnish DPA has imposed a fine of EUR 122,000 on a company with products that process health data, such as heart rate, etc. The DPA had received several complaints regarding the processing of health data from data subjects. During its investigation, the DPA found that the company did not have a sufficient legal basis to process various types of health data. While the company had informed users of the products about the processing of personal health data in general, it had failed to provide information for each of the different types of health data (e.g., body mass index or oxygen capacity), such as the purpose of the processing. Accordingly, the DPA found that the users' consent could not be valid since it was not given on an individual basis and with full knowledge of the facts.

Νομικές παραπομπές

Art. 9

Θέματα & Παραβάσεις

Insufficient legal basis for data processing

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.