Syddanmark Region – €67,200 Fine (Denmark, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Syddanmark Region in Denmark was fined EUR 67,200 for not properly protecting patient data on its website. A PowerPoint file with sensitive health information was publicly accessible for years, showing the need for better data security measures.
What happened
Syddanmark Region left a PowerPoint file with sensitive patient data publicly accessible on its website.
Who was affected
The breach affected 3,915 patients whose health information and ID numbers were exposed.
What the authority found
The Danish data protection authority fined the region for failing to implement adequate security measures to protect sensitive data.
Why this matters
This case underscores the need for robust data security practices, especially when handling sensitive health information. Organizations should regularly review and update their security measures to prevent similar breaches.
GDPR Articles Cited
The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach according to Art. 33 GDPR. The Syddanmark Region states that since May 2011, a PowerPoint presentation was available on its website that had been created at Odense University Hospital for training purposes and contained charts with personal data - including health information and ID card number details - of 3,915 patients. The region used a screening tool to periodically check for inadvertent postings of personal identity numbers on its website. However, the screening tool was unable to scan the underlying data in PowerPoint presentations. In this context, the DPA found that the region had not implemented appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. In assessing whether a fine should be imposed, the DPA took into aggravating consideration the fact that Syddanmark Region processes large amounts of personal data, including health data - which is of a sensitive nature.
Related Enforcement Actions (0)
No other enforcement actions found for Syddanmark Region in DK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
17 September 2021
Authority
Datatilsynet (Denmark)
Fine Amount
€67,200
Enforcement Tracker ID
ETid-839
About this data
Cite as: Cookie Fines. Syddanmark Region - Denmark (2021). Retrieved from cookiefines.eu
Last updated: