Dentist

€1,000

Insufficient legal basis for data processing

Data della decisione

31 gennaio 2023

Autorità

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)

RO

Settore

Health Care

Paese

IT

Legge

GDPR

Stato

FINAL

Descrizione

The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However, it had failed to obtain the patient's consent before publishing the medical data. Therefore, the DPA found that the controller had unlawfully processed the data.

Citazioni legali

Art. 6 (1)Art. 9 (2)

Problemi e violazioni

Insufficient legal basis for data processing

Rimanete aggiornati sull'applicazione della privacy

Rispettiamo la vostra privacy. Un'email al mese, niente spam, cancellazione in qualsiasi momento.