University of Bordeaux – Violation Found (France, 2023)

Violation Found
Commission Nationale de l'Informatique et des Libertés7 September 2023France
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The French data protection authority found that the University of Bordeaux could proceed with a study on health data after it met several legal requirements. The study aims to compare health trajectories related to diseases and is part of a European initiative. This case shows how research can be conducted while still respecting privacy laws.

What happened

The University of Bordeaux received authorization to process personal health data for a study on cardio-metabolic diseases.

Who was affected

Individuals whose health data will be used in the study conducted by the University of Bordeaux.

What the authority found

The authority determined that the university's project met the necessary legal obligations under GDPR for processing health data.

Why this matters

This finding highlights the balance between advancing scientific research and protecting personal data. It encourages other organizations to explore similar studies while ensuring compliance with privacy regulations.

GDPR Articles Cited

Art. 28 GDPR
Art. 36 GDPR
Art. 5(1)(b) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(e) GDPR
Art. 6(1)(e) GDPR
Art. 9(2)(j) GDPR
Art. 14(5)(b) GDPR
Full Legal Summary
Detailed

The University of Bordeaux, the data controller, applied for authorisation to undertake automated processing of personal data from the French DPA under Article 36 GDPR. The controller aimed to carry out the processing for a study comparing health trajectories leading to cardio-metabolic diseases on a national scale in order to evaluate the interoperability of European health data. The project was selected by the European Commission as part of a 'European Health Data Area' pilot. Hence, the DPAs from Denmark, Finland, Norway and Hungary will also need to authorise similar studies to compare the aggregated results. The French DPA authorised the project by the data controller on the basis that it met a number of obligations imposed by the GDPR. Firstly, that the purpose of processing was determined, explicit and legitimate in accordance with Article 5(1)(b) GDPR when considering the project's objectives. Secondly, the processing of health data was lawful as it was necessary for the execution of a task carried out in the public interest, per Article 6(1)(e) GDPR, and was also necessary for scientific research purposes under Article 9(2)(j) GDPR. Thirdly, that the data was adequate, relevant and limited to what was necessary for the purposes of processing under Article 5(1)(c) GDPR, as the data was scientifically justified in the data controller's application and further filtering would be carried out before being transmitted to the hosting [https://www.health-data-hub.fr/page/faq-english Health Data Platform;] a French public structure whose objective is to enable project coordinators to access non-nominative data hosted on a secure platform. Fourthly, since the data would only be accessible for a period of 5 years (after which it would be deleted or anonymised), the data controller would not be exceeding the period necessary for the collection and processing purposes of the data pursuant to Article 5(1)(e) GDPR. The data controller was also not required to individua

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for University of Bordeaux in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

7 September 2023

Authority

Commission Nationale de l'Informatique et des Libertés

GDPRhub ID

gdprhub-6376

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. University of Bordeaux - France (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: