Medicals Nordic – €80,400 Fine (Denmark, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Denmark's Datatilsynet fined Medicals Nordic EUR 80,400 for using WhatsApp to share sensitive health data without proper security measures. Employees, including those without a need to know, had access to confidential information, and ex-employees were not removed from group chats. This case underscores the importance of secure data handling and access management.
What happened
Medicals Nordic used WhatsApp to share confidential health data among employees, including those who didn't need access, and failed to remove ex-employees from group chats.
Who was affected
Citizens tested at Medicals Nordic's centers had their health and personal identity information shared improperly.
What the authority found
The Danish DPA found that Medicals Nordic processed sensitive data unsafely and shared it with unauthorized individuals, including ex-employees.
Why this matters
This case highlights the critical need for companies to implement secure communication methods and manage access rights effectively. It serves as a cautionary tale for businesses handling sensitive information to conduct thorough risk assessments and ensure data protection compliance.
GDPR Articles Cited
In January 2021, the Danish DPA discovered that Medicals Nordic used WhatsApp to transmit "confidential information and health information" about citizens tested in the company's test centres. The DPA initiated an own-volition inquiry to assess whether Medicals Nordic had implemented appropriate organisational and technical security measures to safeguard the transmission of citizens' information. It found that employees at the company used their private phones to communicate confidential patient information to the central administration in charge of the four test centres it operated. It did so via WhatsApp group chats, to which all employees at these centres were added. As such, even employees who did not have a work-related need to process information about patients could access it. It included, among other things, the social security number and health data of citizens. Further, ex-employees who no longer worked at the company were not removed from the group chat due to "inadequate access management", meaning they still had access to this data. The Danish DPA held that "confidential information and health information about a large number of citizens has been processed unsafely and passed on to unauthorized persons, including employees who did not have a work-related need to receive the information [and ex-employees]". It emphasised that in several cases the violations were intentional as Medicals Nordic did not carry out necessary data-related risk assessments. Thus, it fined the company DDK 600,000 or approximately €80,500.
Related Enforcement Actions (0)
No other enforcement actions found for Medicals Nordic in DK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
9 July 2021
Authority
Datatilsynet (Denmark)
Fine Amount
€80,400
600,000 DKK
GDPRhub ID
gdprhub-4039About this data
Cite as: Cookie Fines. Medicals Nordic - Denmark (2021). Retrieved from cookiefines.eu
Last updated: