Västerbotten Region – €243,800 Fine (Sweden, 2020)

€243,800Integritetsskyddsmyndigheten3 December 2020Sweden
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Swedish data protection authority fined Västerbotten Region EUR 243,800 for not securing patient data properly. They failed to limit access to sensitive medical records, which could lead to unauthorized data exposure. Healthcare providers should ensure strict access controls to protect patient privacy.

What happened

Västerbotten Region did not implement adequate security measures, allowing unnecessary access to patient data.

Who was affected

Patients whose medical records were accessible to unauthorized users in the Västerbotten Region's system.

What the authority found

The Swedish authority found that Västerbotten Region violated GDPR by not performing a risk analysis and failing to restrict access to patient data.

Why this matters

This case highlights the need for robust data security measures in healthcare, emphasizing the principle of minimum access to sensitive information.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
articles corrected
Full Legal Summary
Detailed

The Swedish DPA (Integritetsskyddsmyndigheten) fined Västerbotten Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to ensure information security. It was found that there was no risk analysis regarding the access to patient data. Authorizations for users of the medical record system NCS Cross were not assigned according to the principle of minimum access. This gave users full access to confidential patient data that they did not need for work purposes.

Related Enforcement Actions (0)

No other enforcement actions found for Västerbotten Region in SE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 December 2020

Authority

Integritetsskyddsmyndigheten

Fine Amount

€243,800

Enforcement Tracker ID

ETid-470

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Västerbotten Region - Sweden (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: