HEI – Medical Travel

€10,600

Insufficient fulfilment of data subjects rights

Datum för beslut

3 maj 2022

Myndighet

Icelandic data protection authority ('Persónuvernd')

IS

Sektor

Health Care

Land

IS

Lag

GDPR

Status

FINAL

Beskrivning

The Icelandic DPA has imposed a fine of EUR 10,600 on HEI - Medical Travel. A data subject had filed a complaint with the DPA against the controller. The controller had gained access to the data subject's email via the Icelandic Medical Association's internal website and had then sent them unsolicited emails. The DPA found that such access was unlawful due to the lack of a valid legal basis. In addition, the data subject had asked the controller for information about the processing of their personal data, such as the origin of the e-mail address. The controller did not properly comply with this request.

Rättsliga hänvisningar

Art. 15 (1)Art. 9 (1)Art. 17 (2)

Frågor och överträdelser

Insufficient fulfilment of data subjects rights

Håll dig uppdaterad om efterlevnaden av sekretessreglerna

Vi respekterar din integritet. Ett e-postmeddelande per månad, ingen skräppost, avsluta prenumerationen när som helst.