Physician

€3,000

Insufficient legal basis for data processing

Otsuse kuupäev

21. mai 2021

Ametiasutus

Spanish Data Protection Authority (aepd)

ES

Sektor

Health Care

Riik

IT

Seadus

GDPR

Staatus

FINAL

Kirjeldus

The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the controller's former clinic. The purchase agreement explicitly stated that the selling party (the controller) was not allowed to make a copy of the patient's files under any circumstances. Nevertheless, the controller had informed his/her former patients that his/her services could be obtained at his/her new clinic in the future. The AEPD found that the controller had acted not only in breach of contract but also in breach of data protection legislation by contacting the former patients.

Õiguslikud viited

Art. 6

Probleemid ja rikkumised

Insufficient legal basis for data processing

Privaatsuse jõustamise kohta ajakohastatud teave

Me austame teie privaatsust. Üks e-kiri kuus, ei ole rämpsposti, loobuda tellimusest igal ajal.