Covid 19 Test Lab
Insufficient technical and organisational measures to ensure information security
Fecha de la decisión
6 de junio de 2024
Autoridad
Austrian Data Protection Authority (dsb)
AT
Sector
Health Care
País
AT
Ley
GDPREstado
FINALDescripción
The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data breach. Furthermore, the controller refused to inform the data subjects of the breach. The DPA also found that the controller processed certain data without a sufficient legal basis, used a processor without the necessary contract, failed to designate a suitable DPO, and failed to report the designation to the DPA.