Midtjylland Region – €53,800 Fine (Denmark, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Midtjylland Region in Denmark was fined for poor security measures that exposed sensitive patient records. Patients and staff could access areas with these records without proper restrictions. This case emphasizes the need for strong data security practices, especially for sensitive health information.
What happened
Midtjylland Region failed to secure access to buildings containing sensitive patient records, allowing unauthorized access.
Who was affected
Patients and staff at a lifestyle center who had unauthorized access to sensitive health records.
What the authority found
The Danish DPA fined Midtjylland Region for inadequate security measures, violating GDPR's requirements for protecting personal data.
Why this matters
This case serves as a reminder for organizations to implement robust security measures to protect sensitive data. Regular assessments and proper access controls are crucial to prevent unauthorized data exposure.
GDPR Articles Cited
The Danish DPA has imposed a fine of EUR 53,800 on Midtjylland Region. On June 12, 2020, the DPA received a notification from the region regarding a personal data security breach pursuant to Art. 33 GDPR. According to the notification, all patients and staff at a lifestyle center were able to access a building where up to 100,000 physical patient records were stored, including health information and personal identity number details. The reason for this was that both staff and patients had been given key cards that allowed them to access all three buildings of the lifestyle center, regardless of whether the user was required to access them. In addition, passersby were able to take a look at the covers of some of the records -which showed personal data such as identity numbers and names - through a window in the building. In this context, the DPA found that the Midtjylland Region had not taken adequate security measures for the storage of personal data. In addition, the region had not established sufficient guidelines for access restrictions when creating key cards, and had not conducted adequate periodic testing, assessment, and evaluation of the security measures taken. In evaluating the question of whether a fine should be imposed, the Danish DPA took into account, as an aggravating factor, that the region processed large amounts of sensitive data, such as health data.
Related Enforcement Actions (0)
No other enforcement actions found for Midtjylland Region in DK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
8 September 2021
Authority
Datatilsynet (Denmark)
Fine Amount
€53,800
Enforcement Tracker ID
ETid-824
About this data
Cite as: Cookie Fines. Midtjylland Region - Denmark (2021). Retrieved from cookiefines.eu
Last updated: