Spanish Society of Medical Oncology – €42,000 Fine (Spain, 2025)

€42,000Agencia Española de Protección de Datos15 January 2025Spain
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Spanish Society of Medical Oncology was fined €42,000 for not protecting patient data properly. This matters because it shows that organizations must ensure strong security measures to protect personal information, especially in health-related fields. Companies should prioritize data security to avoid similar penalties.

What happened

The organization failed to secure patient data, leading to a data breach affecting over 2,600 individuals.

Who was affected

Cancer patients whose personal data was accessed without authorization.

What the authority found

The Spanish DPA found that the organization did not implement adequate security measures, violating GDPR's requirement for data protection.

Why this matters

This case highlights the need for robust data security practices, especially for organizations handling sensitive health information. Other companies should review their security protocols to prevent breaches and potential fines.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(f) GDPR

Original data from scraper before AI verification against source document.

Source verified 12 March 2026
national law identified
Full Legal Summary
Detailed

The Spanish Society of Medical Oncology (controller) promoted the participation by cancer patients in a study being conducted by a data processor. The patients downloaded a mobile app and, using a code given to them by their oncologist, inputted data about their well-being. In June 2023, the controller notified the AEPD (Spanish DPA) that the processor had suffered a breach of security which resulted in the unauthorised access to 2,622 patients' personal data by an intentional bad-actor. The personal data consisted of the participants' email addresses, their phone number and their health-related data. The DPA’s investigation revealed that the processor had failed to properly implement cryptographic controls to allow for the encryption of the data. Based on evidence from the National Cybersecurity and Technology Expertise Association, the DPA found that the failure to implement such controls facilitated the occurrence of the breach. The DPA found that the controller had infringed Article 5(1)(f) GDPR for failing to ensure appropriate security of processing. The DPA initially levied a fine of €70,000 for the infringement but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may acknowledge its responsibility for the alleged violations and/or make a voluntary payment of the proposed fine. Each of these actions reduces the imposed fine by 20%. The controller opted to reduce the fine by 40%, both acknowledging its responsibility for the violations and paying the reduced sanction amount of €42,000.

Related Enforcement Actions (0)

No other enforcement actions found for Spanish Society of Medical Oncology in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

15 January 2025

Authority

Agencia Española de Protección de Datos

Fine Amount

€42,000

GDPRhub ID

gdprhub-9071

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Spanish Society of Medical Oncology - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: