Spanish Society of Medical Oncology – €42,000 Fine (Spain, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Spanish Society of Medical Oncology was fined €42,000 for not protecting patient data properly. This matters because it shows that organizations must ensure strong security measures to protect personal information, especially in health-related fields. Companies should prioritize data security to avoid similar penalties.
What happened
The organization failed to secure patient data, leading to a data breach affecting over 2,600 individuals.
Who was affected
Cancer patients whose personal data was accessed without authorization.
What the authority found
The Spanish DPA found that the organization did not implement adequate security measures, violating GDPR's requirement for data protection.
Why this matters
This case highlights the need for robust data security practices, especially for organizations handling sensitive health information. Other companies should review their security protocols to prevent breaches and potential fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Spanish Society of Medical Oncology (controller) promoted the participation by cancer patients in a study being conducted by a data processor. The patients downloaded a mobile app and, using a code given to them by their oncologist, inputted data about their well-being. In June 2023, the controller notified the AEPD (Spanish DPA) that the processor had suffered a breach of security which resulted in the unauthorised access to 2,622 patients' personal data by an intentional bad-actor. The personal data consisted of the participants' email addresses, their phone number and their health-related data. The DPA’s investigation revealed that the processor had failed to properly implement cryptographic controls to allow for the encryption of the data. Based on evidence from the National Cybersecurity and Technology Expertise Association, the DPA found that the failure to implement such controls facilitated the occurrence of the breach. The DPA found that the controller had infringed Article 5(1)(f) GDPR for failing to ensure appropriate security of processing. The DPA initially levied a fine of €70,000 for the infringement but pursuant to Law 39/2015, a Spanish law concerning administrative proceedings, the DPA informed the controller that it may acknowledge its responsibility for the alleged violations and/or make a voluntary payment of the proposed fine. Each of these actions reduces the imposed fine by 20%. The controller opted to reduce the fine by 40%, both acknowledging its responsibility for the violations and paying the reduced sanction amount of €42,000.
Related Enforcement Actions (0)
No other enforcement actions found for Spanish Society of Medical Oncology in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 January 2025
Authority
Agencia Española de Protección de Datos
Fine Amount
€42,000
GDPRhub ID
gdprhub-9071About this data
Cite as: Cookie Fines. Spanish Society of Medical Oncology - Spain (2025). Retrieved from cookiefines.eu
Last updated: