Spain Spain

Clinic owner

10,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2024-07-05.

Rank · Sector
#143
of 270 in Health Care
Rank · Spain
#417
of 1,071
Rank · All fines
#1,419
of 3,042

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2024-07-05
Controller / Processor
Clinic owner
Sector
Health Care
Quoted Articles
Art. 6 (1) GDPR, Art. 9 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA has fined the owner of a plastic surgery clinic EUR 10,000. The controller posted before-and-after pictures of an individual who had undergone surgery at the clinic on social media (Facebook and Instagram) without obtaining the individual’s consent.

Open original source Links to the regulator's original publication or another source.

Related fines