Psykoterapiakeskus Vastaamo – €608,000 Fine (Finland, 2021)

€608,000Tietosuojavaltuutetun toimisto7 December 2021Finland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Finnish Data Protection Authority fined Vastaamo psychotherapy center €608,000 for failing to protect patient data. Hackers accessed their database due to weak security, and the center delayed reporting the breach. This case emphasizes the importance of strong data security and timely breach reporting.

What happened

Vastaamo was fined for not securing patient data and delaying breach notifications after hackers accessed their database.

Who was affected

Patients of Vastaamo psychotherapy center were affected, as their sensitive medical data was compromised.

What the authority found

The authority found that Vastaamo failed to protect personal data and did not report the breach promptly, violating GDPR requirements.

Why this matters

This case highlights the critical need for businesses to implement robust security measures and promptly report data breaches. It serves as a warning to other companies handling sensitive information.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 33(1) GDPR
Art. 34(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 33(1) GDPR
Art. 34(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary
Detailed

The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An unauthorized third party had gained access to Vastaamo's medical database on at least two occasions, in December 2018 and March 2019. The attacker had also siphoned off data and left a ransom note on the servers. Due to insufficient logging, neither the exact date of the breach nor the network addresses used by the attacker could be identified. The most likely cause of the medical database leak was an unprotected port on the database where the root user account of the database was not password protected. The patient database server was open to the Internet without firewall protection during the period between November 26, 2017, and March 13, 2019. For this reason, the DPA determined that the personal data were not adequately protected against unauthorized and unlawful processing or accidental loss, destruction, or damage, and that the controller had not implemented basic measures for the secure processing of personal data. As part of its investigation, the DPA also determined that the controller must have known as early as March 2019 that data in the patient information system had been lost and could have been compromised by an external attacker. Vastaamo should have immediately reported the security breach to both the DPA and its patients. However, Vastaamo was significantly late in meeting this obligation. The fine is composed proportionately of EUR 145, 600 for the breach of Art. 33 (1) GDPR, EUR 145, 600 for the breach of Art. 34 (1) GDPR and EUR 316, 800 for the breach of Art. 5 (1) f) GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for Psykoterapiakeskus Vastaamo in FI

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

7 December 2021

Authority

Tietosuojavaltuutetun toimisto

Fine Amount

€608,000

Enforcement Tracker ID

ETid-952

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Psykoterapiakeskus Vastaamo - Finland (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: