Medical clinic

€5,000

Insufficient fulfilment of information obligations

Decision Date

26 de dezembro de 2021

Authority

Deputy Data Protection Ombudsman

FI

Sector

Health Care

Country

FI

Law

GDPR

Status

FINAL

Description

The Finnish DPA has fined a medical clinic EUR 5,000. A customer of the clinic had complained to the DPA that he had not received access to his medical records from the clinic following a request for information. In addition, the clinic failed to adequately inform its clients about the processing of personal data. Specifically, the DPA points out that the clinic did not inform its clients about the extent to which it was acting as a data controller for patient data generated by its activities.

Legal Citations

Art. 5 (1)Art. 12 (1)Art. 13 (1)Art. 15 (1)Art. 25

Issues & Violations

Insufficient fulfilment of information obligations

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.