Physician

€3,000

Insufficient legal basis for data processing

Ngày ra quyết định

21 tháng 5, 2021

Thẩm quyền

Spanish Data Protection Authority (aepd)

ES

Ngành

Health Care

Quốc gia

IT

Luật

GDPR

Trạng thái

FINAL

Mô tả

The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the controller's former clinic. The purchase agreement explicitly stated that the selling party (the controller) was not allowed to make a copy of the patient's files under any circumstances. Nevertheless, the controller had informed his/her former patients that his/her services could be obtained at his/her new clinic in the future. The AEPD found that the controller had acted not only in breach of contract but also in breach of data protection legislation by contacting the former patients.

Trích dẫn pháp lý

Art. 6

Vấn đề & Vi phạm

Insufficient legal basis for data processing

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.