Finland Finland

Yliopiston Apteekin

1,100,000 €

GDPR enforcement action by Deputy Data Protection Ombudsman on 2025-05-27.

Rank · Sector
#11
of 270 in Health Care
Rank · Finland
#3
of 27
Rank · All fines
#163
of 3,050

Case details

Authority
Deputy Data Protection Ombudsman
Date
2025-05-27
Controller / Processor
Yliopiston Apteekin
Sector
Health Care
Quoted Articles
Art. 5 (1) c), f) GDPR, Art. 32 (1), (2) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These tools were implemented in a way that allowed the providers, who are based outside the EU, to access personal data. The controller also failed to ensure that the tools complied with the principle of data minimization.

Open original source Links to the regulator's original publication or another source.

Related fines