Clinic owner

€10,000

Insufficient legal basis for data processing

Decision Date

5 de julho de 2024

Authority

Spanish Data Protection Authority (aepd)

ES

Sector

Health Care

Country

ES

Law

GDPR

Status

FINAL

Description

The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the clinic on social media (Facebook and Instagram) without obtaining the individual’s consent.

Legal Citations

Art. 6 (1)Art. 9

Issues & Violations

Insufficient legal basis for data processing

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.