Back to Cases
technologyhealth · 2020
1177 Vårdguiden
IMY imposed sanctions after sensitive call recordings from the healthcare service 1177 were exposed online due to inadequate processor oversight and security controls, raising issues under GDPR Articles 5, 24, 28 and 32.
Fine Imposed€3M
Regulation
Key Takeaways
- Healthcare controllers remain accountable for processor security and access governance.