Physician

€3,000

Insufficient legal basis for data processing

Datum för beslut

21 maj 2021

Myndighet

Spanish Data Protection Authority (aepd)

ES

Sektor

Health Care

Land

IT

Lag

GDPR

Status

FINAL

Beskrivning

The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the controller's former clinic. The purchase agreement explicitly stated that the selling party (the controller) was not allowed to make a copy of the patient's files under any circumstances. Nevertheless, the controller had informed his/her former patients that his/her services could be obtained at his/her new clinic in the future. The AEPD found that the controller had acted not only in breach of contract but also in breach of data protection legislation by contacting the former patients.

Rättsliga hänvisningar

Art. 6

Frågor och överträdelser

Insufficient legal basis for data processing

Håll dig uppdaterad om efterlevnaden av sekretessreglerna

Vi respekterar din integritet. Ett e-postmeddelande per månad, ingen skräppost, avsluta prenumerationen när som helst.