Spain Spain

IDCQ HOSPITALES Y SANIDAD, S.L.U.

1,200,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2025-11-21.

Rank · Sector
#9
of 270 in Health Care
Rank · Spain
#30
of 1,075
Rank · All fines
#158
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2025-11-21
Controller / Processor
IDCQ HOSPITALES Y SANIDAD, S.L.U.
Sector
Health Care
Quoted Articles
Art. 6 GDPR, Art. 9 GDPR, Art. 25 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies or originals of previous scans. However, the controller had established very strict return policies, resulting in data being deleted after a very short amount of time, and data subjects being unable to easily retrieve their data if they had brought it on physical data carriers. Furthermore, the controller only stored data that was necessary for comparison purposes, deleting the rest immediately upon receipt.

Open original source Links to the regulator's original publication or another source.

Related fines