Midtjylland Region

€53,800

Insufficient technical and organisational measures to ensure information security

결정 날짜

2021년 9월 8일

권한

Danish Data Protection Authority (Datatilsynet)

DK

섹터

Public Sector and Education

국가

DK

법률

GDPR

상태

FINAL

설명

The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach pursuant to Art. 33 GDPR. According to the notification, all patients and staff at a lifestyle center were able to access a building where up to 100,000 physical patient records were stored, including health information and personal identity number details. The reason for this was that both staff and patients had been given key cards that allowed them to access all three buildings of the lifestyle center, regardless of whether the user was required to access them. In addition, passersby were able to take a look at the covers of some of the records -which showed personal data such as identity numbers and names - through a window in the building. In this context, the DPA found that the Midtjylland Region had not taken adequate security measures for the storage of personal data. In addition, the region had not established sufficient guidelines for access restrictions when creating key cards, and had not conducted adequate periodic testing, assessment, and evaluation of the security measures taken. In evaluating the question of whether a fine should be imposed, the Danish DPA took into account, as an aggravating factor, that the region processed large amounts of sensitive data, such as health data.

법적 인용

Art. 32

문제 및 위반 사항

Insufficient technical and organisational measures to ensure information security

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.