France France

CEGEDIM SANTÉ

800,000 €

GDPR enforcement action by French Data Protection Authority (CNIL) on 2024-09-12.

Rank · Sector
#12
of 270 in Health Care
Rank · France
#27
of 74
Rank · All fines
#202
of 3,050

Case details

Authority
French Data Protection Authority (CNIL)
Date
2024-09-12
Controller / Processor
CEGEDIM SANTÉ
Sector
Health Care
Quoted Articles
Art. 5 (1) a) GDPR, Art. 66 Loi n° 78-17 du 6 janvier 1978
Type of violation
Non-compliance with general data processing principles

Summary

The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes. However, the DPA found that this data was not anonymous but only pseudonymized, making re-identification possible.

Open original source Links to the regulator's original publication or another source.

Related fines