Dentist
€1,000
Insufficient legal basis for data processing
Lēmuma datums
2023. gada 31. janvāris
Iestāde
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
RO
Nozare
Health Care
Valsts
IT
Likums
GDPRStatuss
FINALApraksts
The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However, it had failed to obtain the patient's consent before publishing the medical data. Therefore, the DPA found that the controller had unlawfully processed the data.
Juridiskās atsauces
Art. 6 (1)Art. 9 (2)
Jautājumi un pārkāpumi
Insufficient legal basis for data processing