Orthodontic Clinic

€12,000

Insufficient technical and organisational measures to ensure information security

決定日期

2021年2月4日

權限

Dutch Supervisory Authority for Data Protection (AP)

NL

部門

Health Care

國家

NL

法律

GDPR

狀態

FINAL

說明

The Dutch DPA (AP) has fined an orthodontic clinic EUR 12,000. The web form that new patients used to sign up contained mandatory fields for all sorts of patient personal data. The data that the patients (mostly children) entered into the form was then sent to the orthodontic clinic via an unencrypted - and thus unsecured - connection. This presented the risk of unauthorized third parties accessing the personal data of the data subjects.

法律引文

Art. 32 (1)

問題與違規

Insufficient technical and organisational measures to ensure information security

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。