Motor insurance center – €52,000 Fine (Finland, 2021)

€52,000Tietosuojavaltuutetun toimisto16 December 2021Finland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Finnish motor insurance center was fined EUR 52,000 for collecting more patient data than necessary for processing insurance claims. The company accessed data that was not needed, violating principles of data minimization and transparency. This case emphasizes the need to only collect data that is essential for the task at hand.

What happened

The motor insurance center collected excessive patient data beyond what was necessary for processing claims.

Who was affected

Patients whose data was unnecessarily accessed by the motor insurance center.

What the authority found

The Finnish authority found the insurance center violated GDPR by not adhering to data minimization and transparency principles.

Why this matters

This case serves as a reminder for companies to limit data collection to what is strictly necessary. It highlights the importance of adhering to data protection principles to avoid regulatory penalties.

GDPR Articles Cited

Art. 5(1)(a) GDPR
Art. 25(2) GDPR
Full Legal Summary
Detailed

The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of processing claims. However, much of the data was not necessary to process the claims. For example, the DPA found that the motor vehicle insurance center had also collected patient visit notes to determine whether the health care provider had billed for visits that were not related to the examination or treatment of injuries caused by the accident. The DPA notes that the Finnish Motor Insurance Act does not justify direct access to all patient data, but that the information requested must be necessary for the processing of the claim. For this reason, the authority recognized a violation of the principles of legality and transparency as well as data minimization in practice.

Related Enforcement Actions (0)

No other enforcement actions found for Motor insurance center in FI

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 December 2021

Authority

Tietosuojavaltuutetun toimisto

Fine Amount

€52,000

Enforcement Tracker ID

ETid-1012

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Motor insurance center - Finland (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: