Clinic owner
€10,000
Insufficient legal basis for data processing
Decision Date
July 5, 2024
Authority
Spanish Data Protection Authority (aepd)
ES
Sector
Health Care
Country
ES
Law
GDPRStatus
FINALDescription
The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the clinic on social media (Facebook and Instagram) without obtaining the individual’s consent.
Legal Citations
Art. 6 (1)Art. 9
Issues & Violations
Insufficient legal basis for data processing