FineME
Run assessment
Back to Cases
technologyhealth · 2020

1177 Vårdguiden

IMY imposed sanctions after sensitive call recordings from the healthcare service 1177 were exposed online due to inadequate processor oversight and security controls, raising issues under GDPR Articles 5, 24, 28 and 32.

Fine Imposed€3M
Authority

Integritetsskyddsmyndigheten

Styleaggressive
Avg. investigation15 mo
View authority profile
Regulation

Key Takeaways
  • Healthcare controllers remain accountable for processor security and access governance.