Region Värmland – €25,000 Fine (Sweden, 2021)

€25,000Integritetsskyddsmyndigheten7 June 2021Sweden
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Region Värmland was fined EUR 25,000 by the Swedish DPA for not informing people about how their call data to a health hotline was being used. This case emphasizes the importance of transparency in data processing. Businesses should clearly communicate how they handle personal data to avoid penalties.

What happened

Region Värmland collected call data from individuals without properly informing them about its processing.

Who was affected

Callers to the 1177 health hotline in the Värmland region of Sweden were affected as their call data was collected without proper notice.

What the authority found

The Swedish DPA ruled that Region Värmland failed to inform individuals about the processing of their personal data, violating GDPR Articles 5(1)(a) and 13.

Why this matters

This case highlights the importance of transparency in data processing. Companies must ensure they provide clear information to individuals about how their data is used to comply with GDPR and avoid fines.

GDPR Articles Cited

Art. 13 GDPR
Art. 5(1)(a) GDPR
Full Legal Summary
Detailed

The Swedish DPA has imposed a fine of EUR 25,000 on Region Värmland. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of Sweden, a telephone hotline that offers advice on various health-related topics can be reached by dialing 1177. Each region operates its own health advice service, either internally or through contracted subcontractors, but together they form a national network. In 2019, the media reported that recorded calls to the 1177 helpline were available on a web server without password protection or other security measures. All calls to the 1177 number initially went to the company Inera, which managed and developed the shared systems. Calls to the number 1177 from people living in the Stockholm, Sörmland and Värmland regions were put through by Inera to Medhelp AB, which took the calls. Medhelp had in turn contracted the Thai company Medicall Co Ltd. to take calls on weekends and at night. Both Medhelp and Medicall had a contract with the technology company Voice Integrate Nordic AB for, among other things, call recordings. A data breach had then occurred in which recordings of calls to the number 1177 were available on the Internet on a storage server belonging to Voice Integrate. The incident resulted from the misconfiguration of a network-attached storage device that was publicly accessible over the Internet and did not use encrypted communications. A large number of calls were accessed due to the vulnerability. The DPA imposed the fine on Region Värmland for collecting call data from data subjects without first properly informing them of its processing.

Related Enforcement Actions (0)

No other enforcement actions found for Region Värmland in SE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

7 June 2021

Authority

Integritetsskyddsmyndigheten

Fine Amount

€25,000

Enforcement Tracker ID

ETid-716

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Region Värmland - Sweden (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: