Spain Spain

Physician

3,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2021-05-21.

Rank · Sector
#205
of 270 in Health Care
Rank · Spain
#614
of 1,075
Rank · All fines
#2,035
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2021-05-21
Controller / Processor
Physician
Sector
Health Care
Quoted Articles
Art. 6 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Spanish DPA (AEPD) has fined a physician EUR 3,000. The controller had left his/her former clinic and started working in a new clinic. The complainant had taken over the controller's former clinic. The purchase agreement explicitly stated that the selling party (the controller) was not allowed to make a copy of the patient's files under any circumstances. Nevertheless, the controller had informed his/her former patients that his/her services could be obtained at his/her new clinic in the future. The AEPD found that the controller had acted not only in breach of contract but also in breach of data protection legislation by contacting the former patients.

Open original source Links to the regulator's original publication or another source.

Related fines