Spain Spain

Physician

5,600 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2022-04-22.

Rank · Sector
#176
of 270 in Health Care
Rank · Spain
#489
of 1,075
Rank · All fines
#1,670
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2022-04-22
Controller / Processor
Physician
Sector
Health Care
Quoted Articles
Art. 6 (1) GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA (AEPD) has fined a physician. The physician had used recordings of a patient's treatment for advertising purposes. However, the patient had not consented to this. For this reason, the DPA found that the doctor had processed the data without a valid legal basis. The original fine of EUR 7,000 was reduced to EUR 5,600 due to immediate payment.

Open original source Links to the regulator's original publication or another source.

Related fines