DEDALUS BIOLOGIE – €1,500,000 Fine (France, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
DEDALUS BIOLOGIE was fined EUR 1.5 million by the French data protection authority for a massive data leak affecting nearly 500,000 people. The company failed to secure sensitive medical data, leading to unauthorized access. This case highlights the importance of strong data security measures for companies handling personal information.
What happened
DEDALUS BIOLOGIE leaked sensitive personal data of nearly 500,000 individuals due to inadequate security measures.
Who was affected
Individuals whose medical data, including names and social security numbers, were exposed in the leak.
What the authority found
The French authority found DEDALUS violated GDPR by not securing personal data and extracting more data than necessary.
Why this matters
This case underscores the critical need for companies to implement robust security measures and comply with data protection agreements, especially when handling sensitive medical information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press revealed a data leak at DEDALUS that resulted in the leak of nearly 500,000 individuals' data. The leaked data included information on the surnames, first names, social security number, name of the treating physician, data on medical examinations and illnesses of the data subjects. During its investigation, the CNIL found several violations of the GDPR. Namely, DEDALUS had violated Art. 29 GDPR by extracting more data than required in the course of processing on behalf of two laboratories. In addition, the DPA found that DEDALUS had failed to implement appropriate technical and organizational measures to ensure the security of personal data. This constitutes a violation of Art. 32 GDPR. For example, no specific procedure for data migration operations had been implemented. Also, the leaked data had not been stored in encrypted form on the server. In addition, the DPA found that DEDALUS lacked authentication for access to the public area of the server. The absence of such security measures was one of the main causes of the data leak. Further, the DPA found that the contractual documents between DEDALUS and its customers did not comply with the requirements set forth in Art. 28 GDPR. The DPA took into aggravating consideration the seriousness of the violations committed, in particular the security breaches, as well as the large number of individuals affected, when imposing the fine.
Related Enforcement Actions (0)
No other enforcement actions found for DEDALUS BIOLOGIE in FR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 April 2022
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€1,500,000
Enforcement Tracker ID
ETid-1136
About this data
Cite as: Cookie Fines. DEDALUS BIOLOGIE - France (2022). Retrieved from cookiefines.eu
Last updated: