Romania Romania

Medstar S.R.L.

2,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2025-02-20.

Rank · Sector
#229
of 270 in Health Care
Rank · Romania
#205
of 283
Rank · All fines
#2,372
of 3,050

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2025-02-20
Controller / Processor
Medstar S.R.L.
Sector
Health Care
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found that the controller had failed to implement appropriate technical and organizational measures to protect personal data and prevent such an incident.

Open original source Links to the regulator's original publication or another source.

Related fines