Dentist

€1,000

Insufficient legal basis for data processing

Data deciziei

31 ianuarie 2023

Autoritatea

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)

RO

Sector

Health Care

Țara

IT

Legea

GDPR

Statut

FINAL

Descriere

The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However, it had failed to obtain the patient's consent before publishing the medical data. Therefore, the DPA found that the controller had unlawfully processed the data.

Citări juridice

Art. 6 (1)Art. 9 (2)

Probleme și încălcări

Insufficient legal basis for data processing

Rămâneți la curent cu aplicarea normelor de confidențialitate

Îți respectăm confidențialitatea. Un e-mail pe lună, fără spam, dezabonare oricând.