Region Stockholm – €50,000 Fine (Sweden, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Region Stockholm was fined EUR 50,000 for not properly informing people about how their call data was being used. Recorded calls to a health hotline were left unsecured online, exposing sensitive information. This incident underscores the need for strong data protection measures and transparency.
What happened
Region Stockholm collected call data without properly informing individuals about its processing.
Who was affected
People calling the 1177 health advice hotline in Stockholm, Sörmland, and Värmland regions.
What the authority found
The Swedish DPA found Region Stockholm failed to inform individuals about the processing of their call data, violating GDPR's transparency requirements.
Why this matters
This case emphasizes the importance of transparency and security in handling personal data, especially in healthcare. Organizations should ensure clear communication about data use and robust security measures.
GDPR Articles Cited
The Swedish DPA has imposed a fine of EUR 50,000 on Region Stockholm. The fine is related to an investigation against three companies and three Swedish regions. In all 21 regions of Sweden, a telephone hotline that offers advice on various health-related topics can be reached by dialing 1177. Each region operates its own health advice service, either internally or through contracted subcontractors, but together they form a national network. In 2019, the media reported that recorded calls to the 1177 helpline were available on a web server without password protection or other security measures. All calls to the 1177 number initially went to the company Inera, which managed and developed the shared systems. Calls to the number 1177 from people living in the Stockholm, Sörmland and Värmland regions were put through by Inera to Medhelp AB, which took the calls. Medhelp had in turn contracted the Thai company Medicall Co Ltd. to take calls on weekends and at night. Both Medhelp and Medicall had a contract with the technology company Voice Integrate Nordic AB for, among other things, call recordings. A data breach had then occurred in which recordings of calls to the number 1177 were available on the Internet on a storage server belonging to Voice Integrate. The incident resulted from the misconfiguration of a network-attached storage device that was publicly accessible over the Internet and did not use encrypted communications. A large number of calls were accessed due to the vulnerability. The DPA imposed the fine on Region Stockholm for collecting call data from data subjects without first properly informing them of its processing.
Related Enforcement Actions (0)
No other enforcement actions found for Region Stockholm in SE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
7 June 2021
Authority
Integritetsskyddsmyndigheten
Fine Amount
€50,000
Enforcement Tracker ID
ETid-717
About this data
Cite as: Cookie Fines. Region Stockholm - Sweden (2021). Retrieved from cookiefines.eu
Last updated: