Spain Spain

HM Hospitales

48,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2020-02-25.

Rank · Sector
#71
of 270 in Health Care
Rank · Spain
#241
of 1,075
Rank · All fines
#753
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2020-02-25
Controller / Processor
HM Hospitales
Sector
Health Care
Quoted Articles
Art. 5 GDPR, Art. 6 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The data subject stated that at the time of his admission to hospital he had to fill in a form containing a checkbox indicating that, if he did not tick it, he agreed to the transfer of his data to third parties. This form, provided by HM, was not compatible with the GDPR, since consent was to be obtained through the inactivity of the data subject.

Open original source Links to the regulator's original publication or another source.

Related fines