Syddanmark Region – €67,200 Fine (Denmark, 2021)

€67,200Datatilsynet (Denmark)17 September 2021Denmark
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Syddanmark Region in Denmark was fined EUR 67,200 for not properly protecting patient data on its website. A PowerPoint file with sensitive health information was publicly accessible for years, showing the need for better data security measures.

What happened

Syddanmark Region left a PowerPoint file with sensitive patient data publicly accessible on its website.

Who was affected

The breach affected 3,915 patients whose health information and ID numbers were exposed.

What the authority found

The Danish data protection authority fined the region for failing to implement adequate security measures to protect sensitive data.

Why this matters

This case underscores the need for robust data security practices, especially when handling sensitive health information. Organizations should regularly review and update their security measures to prevent similar breaches.

GDPR Articles Cited

Art. 32 GDPR
Full Legal Summary
Detailed

The Danish DPA imposed a fine of EUR 67,200 on Syddanmark Region. On March 9, 2020, the DPA received a notification from Syddanmark Region regarding a personal data breach according to Art. 33 GDPR. The Syddanmark Region states that since May 2011, a PowerPoint presentation was available on its website that had been created at Odense University Hospital for training purposes and contained charts with personal data - including health information and ID card number details - of 3,915 patients. The region used a screening tool to periodically check for inadvertent postings of personal identity numbers on its website. However, the screening tool was unable to scan the underlying data in PowerPoint presentations. In this context, the DPA found that the region had not implemented appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. In assessing whether a fine should be imposed, the DPA took into aggravating consideration the fact that Syddanmark Region processes large amounts of personal data, including health data - which is of a sensitive nature.

Related Enforcement Actions (0)

No other enforcement actions found for Syddanmark Region in DK

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

17 September 2021

Authority

Datatilsynet (Denmark)

Fine Amount

€67,200

Enforcement Tracker ID

ETid-839

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Syddanmark Region - Denmark (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: