National Center of Addiction Medicine ('SAA')

€20,600

Insufficient technical and organisational measures to ensure information security

Decision Date

10 de março de 2020

Authority

Icelandic data protection authority ('Persónuvernd')

IS

Sector

Health Care

Country

IS

Law

GDPR

Status

FINAL

Description

Persónuvernd noted that a former employee of the SAA received boxes of allegedly personal belongings that he had left there, but which also contained patient data, including the health records of 252 former patients and documents with the names of about 3,000 people who had participated in rehabilitation for alcohol and drug abuse.

Legal Citations

Art. 5 (1)Art. 32

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.