Dalarna Region

€17,900

Insufficient technical and organisational measures to ensure information security

決定日期

2023年1月17日

權限

Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)

SE

部門

Health Care

國家

SE

法律

GDPR

狀態

FINAL

說明

The Swedish DPA has imposed a fine of EUR 17,900 on Dalarna Region. The region had sent out invitations for patient visits where the respective healthcare facility, such as a children's hospital, was visible on the envelope window. The DPA found that this visibility allowed unauthorized persons to gain access to patients' personal data. The DPA concluded that the region had failed to implement adequate technical and organizational measures to protect personal data.

法律引文

Art. 32 (1)

問題與違規

Insufficient technical and organisational measures to ensure information security

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。