Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
SWEDISH SUPERVISORY AUTHORITY: the wrong online post about sensitive personal data in Örebro

SWEDISH SUPERVISORY AUTHORITY: the wrong online post about sensitive personal data in Örebro

The data inspection reveals that the Örebro Health Medical Body committed a big fault during a data publication on the website about a patient who was hospitalized in a mental institution.

The data Inspectorate got a claim against the Örebro health committee and the doctor about the data publication on a website about a patient who was hospitalized in a mental forensic institution.

Elin HallStröm, the Data Inspectorate’s lawyer, underlines that their report shows that sensitive personal data were published in a wrong way in the Örebro Public website.

The Data Inspectorate review shows that there are no written procedures related to the publication of personal data and documents on web sites.

The procedures for the online publication are only in an oral form. In this case, the oral procedures were not observed and the document was published accidentally, this means that The Council does not adopt enough organizational measures to guarantee that personal data are protected from the online wrong publication.

We delegate the Council for the production of written procedures that will guarantee the compliance with the legislation when someone is posting something online.

The Data Inspectorate confirms that the Council does not have an aim, a legal base or any other exception of prohibition from the personal data processing Regulation.

The Data Inspectorate submits to the Board of Directors to remedy the deficiencies and also issues an administrative commission of 120,000 Swedish kronor to the Board of Directors.

The document was deleted from the web site.

SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DELLA SVEZIA

Recommended to you

Advanced Research