DPA imposes fine on hospital for data breach violations
Original title: Επιβολή προστίμου σε Νοσοκομείο για μη τήρηση τεχνικών και οργανωτικών μέτρων, πλημμελή διαχείριση περιστατικού παραβίασης και παράλειψη δημοσιοποίησης στοιχείων επικοινωνίας του ΥΠΔ
The DPA (Hellenic Data Protection Authority) imposed a fine on a hospital for breaches of data protection rules. The violations include failure to implement adequate technical and organizational measures, inadequate handling of a data breach incident, and failure to disclose the contact details of the data protection officer. The hospital must immediately take measures to comply with data protection obligations and strengthen security measures.
What changed
- The hospital is required to implement adequate technical and organizational measures to protect personal data in accordance with GDPR
- Obligation for proper and timely management of data breach incidents with notification of interested parties
- Obligation to disclose and maintain accessible contact details of the data protection officer (DPO)
Who is affected
Hospitals and other public and private healthcare facilities that process patient personal data in Greece
Summary generated by a language model; the official text prevails. Not legal advice.