Spain Spain

DENTALCUADROS BCN S.L.P.

12,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2024-05-08.

Rank · Sector
#125
of 270 in Health Care
Rank · Spain
#376
of 1,075
Rank · All fines
#1,276
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2024-05-08
Controller / Processor
DENTALCUADROS BCN S.L.P.
Sector
Health Care
Quoted Articles
Art. 32 GDPR, Art. 33 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation, the DPA found that the controller had failed to take appropriate technical and organizational measures to protect personal data. In addition, the controller failed to report the data breach to the DPA in a timely manner. The original fine of EUR 20,000 was reduced to EUR 12,000 due to voluntary payment and acknowledgement of responsibility.

Open original source Links to the regulator's original publication or another source.

Related fines