AXIOYU PYLIS CENTRE I.A – €30,000 Fine (Greece, 2022)

€30,000Hellenic Data Protection Authority3 August 2022Greece
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Greek diagnostic center was fined 30,000 euros for losing access to a patient's mammogram images. This matters because it shows the importance of securely storing and managing personal health data.

What happened

AXIOYU PYLIS CENTRE I.A lost access to a patient's mammogram images, violating data protection rules.

Who was affected

A patient who could not access her mammogram images due to the center's data management failures.

What the authority found

The authority found that the center violated GDPR by failing to maintain the integrity and confidentiality of the patient's data.

Why this matters

This case highlights the critical need for healthcare providers to implement strong data management practices. It serves as a reminder that losing access to important health data can lead to significant penalties.

GDPR Articles Cited

Art. 15 GDPR
Art. 32 GDPR
Art. 33 GDPR
Art. 34 GDPR
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

A patient (data subject) of diagnostic centre Pyle Axiou I.A.E. (controller) requested copies of her medical records in relation to a mammogram carried out in the past. The controller replied that it could not provide her with the images from the mammogram, as the machine can only store them for 3 months. The data subject then submitted a complaint with the DPA for violation of her right of access. She stressed that in particular the images of the mammogram were important in view of her age and state of health. After a letter of the DPA, the controller suddenly remembered that it also stored the images on a hard drive in it's storage. However, it could not recover the images. During a hearing, the controller argued: # it exhausted all possibilities to recover the images (but without success); # the most important medical record was provided to the data subject: the report on the images. # it informed the data subject in good time of the unavailability of the images; # it submitted his views on the issues of his compliance with his obligations under Articles 32-34 GDPR. The data subject argued during the hearing that, in addition to the violation of the right of access, the controller also violated her right to information. She was never informed by the controller of the definitive loss of the images. The DPA found that the retention period for the images was ten years from the data subject's last visit. The DPA further noted that the images were unavailable at the time the right was exercised. The DPA therefore held that the data subject's right of access (Article 15 GDPR) was not violated as it was impossible to provide the images, even though they were unlawfully deleted. However, the DPA, found that the loss of availability of the images constituted a violation of the principle of integrity and confidentiality pursuant to Article 5(1)(f) GDPR. The DPA followed that the above-mentioned violation was a result of insufficient technical and organizational

Related Enforcement Actions (0)

No other enforcement actions found for AXIOYU PYLIS CENTRE I.A in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 August 2022

Authority

Hellenic Data Protection Authority

Fine Amount

€30,000

GDPRhub ID

gdprhub-5211

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. AXIOYU PYLIS CENTRE I.A - Greece (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: