Danish Cancer Society

€107,000

Insufficient technical and organisational measures to ensure information security

Ngày ra quyết định

29 tháng 9, 2021

Thẩm quyền

Danish Data Protection Authority (Datatilsynet)

DK

Ngành

Health Care

Quốc gia

DK

Luật

GDPR

Trạng thái

FINAL

Mô tả

The Danish DPA has fined the Danish Cancer Society EUR 107,000 for failing to comply with the requirements of the GDPR regarding appropriate security measures. The Danish Cancer Society had reported four data breaches according to Art. 33 GDPR to the DPA. Two of these involved computer thefts, two phishing attacks - and all four were due to the Danish Cancer Foundation's failure to implement technical and organizational measures to ensure a level of security appropriate to the risk to data subjects. A similar personal data breach already occurred in August 2018, when the Foundation fell victim to phishing and spoofing hacking attacks. In this context, the Danish Cancer Society stated that it should increase protection through multifactor authentication, however, this was not implemented. The data of at least 1,448 individuals was compromised, and in several cases it involved sensitive personal health data, including medical history.

Trích dẫn pháp lý

Art. 32

Vấn đề & Vi phạm

Insufficient technical and organisational measures to ensure information security

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.