Region Nordjylland โ Violation Found (Denmark, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A security flaw in a Danish healthcare IT system allowed users to access and delete other people's personal data by changing a URL number. This breach exposed sensitive information like names and health data of nearly half a million patients. The Danish DPA found that the system lacked proper security measures, violating GDPR rules.
What happened
A security flaw in a healthcare IT system let users access and delete others' personal data by altering a URL.
Who was affected
Patients whose personal data, including names and health information, were exposed due to the system flaw.
What the authority found
The Danish DPA ruled that the healthcare system failed to implement adequate security measures, violating GDPR's Article 32.
Why this matters
This case highlights the importance of robust security testing in IT systems, especially those handling sensitive data. Businesses must ensure their systems are secure to protect user data and comply with GDPR.
GDPR Articles Cited
A security flaw in a health care IT system used by a Danish region had made it possible to access other individuals' personal data and to delete their bookings. After logging in to their own account, users were able to access personal data related to other users by changing a number in the URL of the website. From may 2018 and until april 2021, users could take advantage of this security flaw, and thus access all correspondence between health care personnel and their patients, including personal data such as names, social security numbers, cell phone numbers, addresses and health data. 498 599 patients were registered in the system in April 2021. The region reported the personal data breach to the Danish DPA, and stated that there were no signs that the personal data has been accessed without authorisation or otherwise misused. The DPA held that the controller acted in violation of the security requirements of article 32 GDPR. The controller had entered into a technical development contract with the developer of the IT system without including sufficient obligations related to testing. The contract framework included an obligation to perform user tests, however it did not contain clear obligations to perform security tests. The DPA therefore reprimanded the controller for not implementing appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Region Nordjylland in DK
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Region Nordjylland - Denmark (2021). Retrieved from cookiefines.eu
Last updated: