[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftPm3HzwrJnaDI4WMWZy9m4gFaQJq9-Ox1KQGV3WaqPE":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"37d09451-817b-4272-9fbe-aa2163d814b5","Persónuvernd (Island) - 2025051308","personuvernd-island-2025051308-46ccaf","Created page with \"{{DPAdecisionBOX |Jurisdiction=Iceland |DPA-BG-Color= |DPAlogo=LogoIS.png |DPA_Abbrevation=Persónuvernd |DPA_With_Country=Persónuvernd (Island) |Case_Number_Name=2025051308 |ECLI= |Original_Source_Name_1=Persónuvernd |Original_Source_Link_1=https:\u002F\u002Fisland.is\u002Fs\u002Fpersonuvernd\u002Furskurdir-akvardanir-og-alit\u002Foheimilar-uppflettingar-starfsmanns-landspitala-i-sjukraskra-5-10-2026 |Original_Source_Language_1=Icelandic |Original_Source_Language__Code_1=IS |Original_Source_...\" New page {{DPAdecisionBOX |Jurisdiction=Iceland |DPA-BG-Color= |DPAlogo=LogoIS.png |DPA_Abbrevation=Persónuvernd |DPA_With_Country=Persónuvernd (Island) |Case_Number_Name=2025051308 |ECLI= |Original_Source_Name_1=Persónuvernd |Original_Source_Link_1=https:\u002F\u002Fisland.is\u002Fs\u002Fpersonuvernd\u002Furskurdir-akvardanir-og-alit\u002Foheimilar-uppflettingar-starfsmanns-landspitala-i-sjukraskra-5-10-2026 |Original_Source_Language_1=Icelandic |Original_Source_Language__Code_1=IS |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint |Outcome=Upheld |Date_Started=12.05.2025 |Date_Decided= |Date_Published=05.10.2026 |Year=2026 |Fine= |Currency= |GDPR_Article_1=Article 6(1) GDPR |GDPR_Article_Link_1=Article 6 GDPR#1 |GDPR_Article_2=Article 9 GDPR |GDPR_Article_Link_2=Article 9 GDPR |GDPR_Article_3= |GDPR_Article_Link_3= |GDPR_Article_4= |GDPR_Article_Link_4= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1= |Party_Link_1= |Party_Name_2= |Party_Link_2= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor=sf | }} The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. == English Summary == === Facts === The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The controller had confirmed that the employee had searched for the data subject’s patient record nine times. The controller’s supervisory board investigated the searches of the data subject’s records and clarified that the employee did not have a legitimate reason to access the medical records. Therefore, they found that the employee exceeded her access rights and thus was in violation of the national law on medical records. === Holding === The DPA held that despite the controller being in charge of its employees’ searches of medical records, if an employee exceeds their access rights they bear personal responsibility. The DPA found that the employee was responsible for the processing of personal data which consisted of searches of the data subject’s medical records. In this regard, the DPA held that the employee did not provide evidence of an appropriate legal basis, in accordance with Articles 6(1) and 9 GDPR. In light of the foregoing, the DPA issued a reprimand against the employee for a violation of Articles 6(1) and 9 GDPR. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Icelandic original. Please refer to the Icelandic original for more details. The Data Protection Authority has ruled in a case where a complaint was filed over a Landspítali employee's access to the complainant's medical record. The finding of the Oversight Board for the Landspítali Electronic Patient Record was available, which determined that the employee had not demonstrated a legitimate reason for accessing the complainant's medical record on the occasions in question during the board's investigation of the matter. The Supervisory Board therefore concluded that the employee had violated the provisions of the Act No. 55\u002F2009 on Medical Records and Article 21 of the Act No. 70\u002F1996 on the Rights and Duties of Civil Servants. The supervision of the Personal Data Protection Authority was limited to examining whether the processing of personal data involved in the said searches had been in accordance with the requirements of Act No. 90\u002F2018 on Personal Data Protection and Processing of Personal Data, including whether the searches were necessary for a clearly specified purpose. The Data Protection Authority concluded that the employee's processing of the complainant's personal data was not in compliance with Law No. 90\u002F2018. Since the employee in question exceeded her access rights under Act No. 55\u002F2009, she was herself considered responsible for the processing of personal data involved in the aforementioned searches. The Data Protection Authority issued a reprimand to the employee for violations of the data protection law. Decision on the complaint regarding [B]'s searches in the medical record, in case no. 2025051308: Procedural matters 1. On May 12, 2025, the Personal Data Protection Authority received a complaint from [A] (hereinafter the complainant) regarding unauthorized searches of her medical record by [B], an employee of Landspítali. The grounds for the complaint state that the hospital's supervisory board confirmed that [B] had looked up the complainant's name in her medical record a specified number of times.2. By letter from the Personal Data Authority to Landspítali, dated On April 21, 2026, the agency requested specific information and invited the hospital to comment on the complaint. Responses from Landspítali were received in a letter dated July of that year. The complainant was given the opportunity to submit comments on Landspítali's responses in a letter dated July 10 of that year, and these were received by email on August 5 of that year. In a letter from the Personal Data Authority to [B], dated On July 10, 2018, the Data Protection Authority requested specific information and offered it the opportunity to comment on the complaint. No response was received from [B] within the specified response period. In a letter from the Data Protection Authority to Landspítali, dated On August 21 of that year, the Authority requested a copy of the decision of the Electronic Patient Record Supervisory Board and an overview of [B]'s viewings of the complainant's medical record, which had been referenced in the hospital's response letter. The requested documents were received on September 1, 2021.3. All of the above-mentioned documents have been taken into account in the resolution of the case, although not all are specifically detailed in the following ruling. Dispute4. The dispute concerns the legality of the searches [B] conducted in the complainant's medical record on December 23, 2021, April 22, and December 6, 2022, July 31, 2023, and July 23, 2024, in Landspítali's electronic health record systems. Events of the Case and Available Evidence 5. A summary of the searches in the complainant's medical record shows nine searches performed by [B] in the Saga medical record system of Landspítali. Two searches were conducted on December 23, 2021, April 22, 2022, December 6, 2022, and July 31, 2023, and one search on July 23, 2024.6. The Oversight Committee for the Electronic Patient Record at Landspítali reviewed the aforementioned queries following a complaint from the complainant in the fall of 2024. According to the committee's conclusion, dated December 30 of that year, [B] failed to demonstrate during the investigation that she had a legitimate reason to access the complainant's medical record on the occasions in question, and therefore [B] was found to have violated the provisions of Act No. 55\u002F2009 on Medical Records and Article 21. para. of the Civil Service Act No. 70\u002F1996. [B]'s conduct was reported to the Office of the National Superintendent of Health and the Data Protection Authority, in accordance with paragraphs 2 and 3 of Article 22 of the Act No. 55\u002F2009.The Parties' Positions. The Complainant's Position7. The complainant's position is that [B] had no legitimate reason to access and review her medical record, as [B] was not involved in her treatment in any way. [...]. Position of Landspítali8. Landspítali refers to the conclusion of the Supervisory Board for Electronic Patient Records, see discussion in paragraph 6. Since [B] exceeded her access privileges under the Act on Medical Records No. 55\u002F2009 and the hospital's regulations, she herself is responsible for the searches in the complainant's medical record. In this regard, Landspítalinn refers to a decision by the Data Protection Authority in case no. 2025020534, which concerned similar searches by the same employee and were deemed illegal. The hospital refers to its previous responses in that matter regarding the alleged legal basis for [B]'s inquiries, as that case is, in the hospital's opinion, comparable to this one. [B]'s Views9. As previously stated, see discussion in paragraph 2, [B] was invited to comment on the complaint and was also asked to provide specific information. She was informed that if no response was received within the specified deadline, the case would be taken up for resolution, without further notice, based on the available information, including the decision of the Electronic Patient Record Oversight Committee at Landspítali, cf. discussion in paragraph 6. No response was received from [B]. Facts and Conclusion Legal Framework 10. This case concerns inquiries by a Landspítali employee, [B], into the complainant's medical record. It therefore concerns the processing of personal data that falls within the scope of Law No. 90\u002F2018 on Personal Data Protection and Processing of Personal Data, and thus within the authority of the Data Protection Authority, see Article 4(1), Article 1(2), and Article 39(1) of the Act. 11. The person responsible for ensuring that the processing of personal data complies with Law No. 90\u002F2018 is called the controller. According to item 6 of Article 3 of the Act, this refers to a natural person, legal entity, public authority, or other body which alone or jointly with others determines the purposes and means of the processing of personal data, in accordance with item 7. Article 4 of Regulation (EU) 2016\u002F679. Generally, the controller is considered to be the relevant institution or company, not individual employees, whether they are managers or general staff. However, if an employee of an organization or company has used personal data for their own purposes, or for a task that falls outside the controller's scope of responsibility, they themselves are responsible for that action.12. All processing of personal data must fall under one of the legal bases in Article 9 of the Act No. 90\u002F2018, pursuant to Article 6(1) of Regulation (EU) 2016\u002F679. For example, it is permitted to process personal data if the processing is necessary to fulfill a legal obligation to which the controller is subject, see item 3 of the statutory provision and Article 6(1)(c) of the Regulation. The basis for such processing must be provided for by law, pursuant to Article 6(3) of the Regulation.13. Processing of sensitive personal data, including health data, pursuant to point (b) of paragraph 3. Article 3 of the Act and Article 9(1) of the Regulation must also comply with one of the additional conditions in Article 11(1) of the Act, pursuant to Article 9(2) of the Regulation. As is the case here, provision 8 of the statutory provision and Article 9(h) of the regulation come into play, regarding processing being necessary to prevent diseases or for occupational medicine, to assess an employee's work capacity, diagnose illnesses, and provide care or treatment in the field of health or social services, and for which there is a specific legal authorization, provided it is carried out by a staff member of such a service who is bound by confidentiality.14. The processing of personal data must also comply with all the principles in Article 8(1) of the Act, see Article 5(1) of the Regulation. It provides, among other things, that personal data shall be processed in a lawful, fair, and transparent manner in relation to the data subject, see point 1. of the statutory provision and Article 6(a) of the Regulation, and that they must be obtained for specified, lawful, and legitimate purposes and not be further processed in a manner incompatible with those purposes, see item 2 of the statutory provision. of the legal provision and paragraph b of the regulatory provision. The controller is responsible for ensuring that the processing of personal data always complies with the fundamental principles of data protection law and must be able to demonstrate this, pursuant to paragraph 2 of the legal and regulatory provision.15. In assessing whether the provisions of the law cited above are complied with, the provisions of any other applicable laws must be taken into account. In the present case, the Act No. 55\u002F2009 on Medical Records is at issue.16. In Act No. 55\u002F2009, section 2 states: Article that in the recording and maintenance of medical records and access to them, the human dignity and self-determination of patients shall be respected and it shall be taken into account that medical records contain sensitive personal data and that the information in them is confidential. According to Section 12 of the Act, access to medical records is not permitted unless there is a legal authorization for it under the provisions of this Act or other laws. Section 13. of the Act provides that health care professionals involved in a patient's treatment who need their medical record information for the purpose of that treatment shall have access to the patient's medical record, subject to the limitations set forth in the Act and regulations issued pursuant to it. According to item 3 of Article 3 of the same law, the concept of treatment includes: an examination, procedure, or other healthcare service provided by a physician or other healthcare professional to diagnose, treat, rehabilitate, nurse, or care for a patient.Conclusion17. The Personal Data Authority has generally considered that Landspítali is considered the data controller for its employees' searches in patient records, when they are performed by the healthcare professionals involved in the patient's treatment and who need their medical record information for the purpose of that treatment, see Article 13 of the Act No. 55\u002F2009 on Medical Records. However, if an employee exceeds their access privileges under the aforementioned law, they are personally responsible for it, see also the discussion in paragraph 11. In this regard, reference is also made to the institution's rulings of April 29, 2021, in case no. 2020010658 and of November 3, 2025, in case no. 2025020534. In the case at hand, it is therefore necessary to determine whether [B] was authorized to process the personal data that is the subject of the complaint.18. [B] has not taken a position on the matter, and her position on the subject of the complaint is therefore not before the Court, see discussion in paragraph 9. It is established that [B] accessed the complainant's medical record on December 23, 2021; April 22 and December 6, 2022; July 31, 2023; and July 23, 2024. As noted in paragraph 6, the supervisory board for Landspítali's electronic patient records concluded that [B] had not demonstrated during the investigation of the case that she had a legitimate reason to access the complainant's medical record on the dates in question. Persónuvernd is not in a position to re-examine the assessment of when access to health record information is necessary for the purpose of treatment, and the agency's supervision is therefore limited to examining whether that processing of personal data, which consists of a search in the medical record, has been in accordance with the requirements of the Personal Data Act, including whether the search can be considered to have been necessary for a clearly specified purpose in light of the data controller's explanations.19. In light of the foregoing, [B] is considered to be responsible for the processing of personal data that consisted of the searches in the complainant's medical record on the occasions in question, pursuant to item 6 of Article 3 of Law No. 90\u002F2018 and item 7. Article 4 of Regulation (EU) 2016\u002F679. In the opinion of the Personal Data Authority, [B] has not demonstrated that the searches in the complainant's medical record were based on an appropriate legal basis for processing, in accordance with Articles 9 and 11 of Law No. 90\u002F2018, cf. Article 6(1) and Article 9(2) of Regulation (EU) 2016\u002F679, cf. also Article 8(2) of the Act and Article 5(2) of the Regulation.20. For that reason, it is the conclusion of the Icelandic Data Protection Authority that the processing [B] of the complainant's personal data, which consisted of inquiries into her medical record on December 23, 2021, April 22, and December 6, 2022, July 31, 2023, and July 23, 2024, was not in compliance with the Personal Data Processing Act No. 90\u002F2018. Decision on the exercise of authority21. The Data Protection Authority may issue a reprimand to a controller or processor if processing operations have violated Regulation (EU) 2016\u002F679, see item 2. Article 42 of Act No. 90\u002F2018, and impose administrative fines on those who, intentionally or negligently, violate any of the provisions of the Regulation listed in paragraphs 2 and 3 of Article 46 of Act No. 90\u002F2018, pursuant to paragraphs 1 and 5 of that article. According to items 1 and 2 of paragraph 3 of Article 46, these include provisions on the basic principles of processing, specifically pursuant to paragraph 1 of Article 5, paragraph 1 of Article 6, and paragraph 2 of Article 9 of the Regulation.22. In determining whether to apply the above-mentioned provisions authorizing a fine, as well as the amount of the fine, regard shall be had to Article 1. subsection 47 of the Act No. 90\u002F2018, which provides for the factors that may be considered either in mitigation or in aggravation. Having regard to the considerations set out in the aforementioned provision, and having regard to other legitimate considerations and the facts of the case as a whole, as well as taking into account the principle of proportionality, see Article 83(1) of the Regulation (EU) 2016\u002F679 and Article 12 of the Administrative Procedure Act No. 37\u002F1993, there is no basis to impose an administrative fine on [B] for the violations described in paragraphs 19 and 20. However, it is deemed appropriate to issue a reprimand to [B], pursuant to item 2. Article 42 of the Act, for the aforementioned violations. Order: [B]'s processing of [A]'s personal data, which consisted of inquiries in her medical record on December 23, 2021, April 22 and December 6, 2022, July 31, 2023, and July 23, 2024, did not comply with the Personal Data Processing Act No. 90\u002F2018.[B] is issued a reprimand, pursuant to item 2 of Article 42 of Act No. 90\u002F2018, for the aforementioned violations. Personal Data Protection, October 5, 2026 Edda Þuríður Hauksdóttir Ósk Óskarsdóttir","Iceland's Data Protection Authority (Persónuvernd) has issued a reprimand to a Landspítali Hospital employee for conducting unauthorized searches of a patient's medical records. The employee accessed the records nine times without a legitimate medical treatment basis, violating Articles 6(1) and 9 of the GDPR. The DPA emphasized that while the hospital is the data controller, individual employees are personally responsible for exceeding their access rights.","Icelandic DPA reprimands hospital employee for unauthorized medical record access.","Help Persónuvernd (Island) - 2025051308: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 09:41, 9 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators113 edits Tag: Decisions [1.0] (No difference) Latest revision as of 09:41, 9 October 2026 Persónuvernd - 2025051308 Authority: Persónuvernd (Island) Jurisdiction: Iceland Relevant Law: Article 6(1) GDPR Article 9 GDPR Type: Complaint Outcome: Upheld Started: 12.05.2025 Decided: Published: 05.10.2026 Fine: n\u002Fa Parties: n\u002Fa National Case Number\u002FName: 2025051308 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Icelandic Original Source: Persónuvernd (in IS) Initial Contributor: sf The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The controller had confirmed that the employee had searched for the data subject’s patient record nine times. The controller’s supervisory board investigated the searches of the data subject’s records and clarified that the employee did not have a legitimate reason to access the medical records. Therefore, they found that the employee exceeded her access rights and thus was in violation of the national law on medical records. Holding The DPA held that despite the controller being in charge of its employees’ searches of medical records, if an employee exceeds their access rights they bear personal responsibility. The DPA found that the employee was responsible for the processing of personal data which consisted of searches of the data subject’s medical records. In this regard, the DPA held that the employee did not provide evidence of an appropriate legal basis, in accordance with Articles 6(1) and 9 GDPR. In light of the foregoing, the DPA issued a reprimand against the employee for a violation of Articles 6(1) and 9 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Icelandic original. Please refer to the Icelandic original for more details. The Data Protection Authority has ruled in a case where a complaint was filed over a Landspítali employee's access to the complainant's medical record. The finding of the Oversight Board for the Landspítali Electronic Patient Record was available, which determined that the employee had not demonstrated a legitimate reason for accessing the complainant's medical record on the occasions in question during the board's investigation of the matter. The Supervisory Board therefore concluded that the employee had violated the provisions of the Act No. 55\u002F2009 on Medical Records and Article 21 of the Act No. 70\u002F1996 on the Rights and Duties of Civil Servants. The supervision of the Personal Data Protection Authority was limited to examining whether the processing of personal data involved in the said searches had been in accordance with the requirements of Act No. 90\u002F2018 on Personal Data Protection and Processing of Personal Data, including whether the searches were necessary for a clearly specified purpose. The Data Protection Authority concluded that the employee's processing of the complainant's personal data was not in compliance with Law No. 90\u002F2018. Since the employee in question exceeded her access rights under Act No. 55\u002F2009, she was herself considered responsible for the processing of personal data involved in the aforementioned searches. The Data Protection Authority issued a reprimand to the employee for violations of the data protection law. Decision on the complaint regarding [B]'s searches in the medical record, in case no. 2025051308: Procedural matters 1. On May 12, 2025, the Personal Data Protection Authority received a complaint from [A] (hereinafter the complainant) regarding unauthorized searches of her medical record by [B], an employee of Landspítali. The grounds for the complaint state that the hospital's supervisory board confirmed that [B] had looked up the complainant's name in her medical record a specified number of times.2. By letter from the Personal Data Authority to Landspítali, dated On April 21, 2026, the agency requested specific information and invited the hospital to comment on the complaint. Responses from Landspítali were received in a letter dated July of that year. The complainant was given the opportunity to submit comments on Landspítali's responses in a letter dated July 10 of that year, and these were received by email on August 5 of that year. In a letter from the Personal Data Authority to [B], dated On July 10, 2018, the Data Protection Authority requested specific information and offered it the opportunity to comment on the complaint. No response was received from [B] within the specified response period. In a letter from the Data Protection Authority to Landspítali, dated On August 21 of that year, the Authority requested a copy of the decision of the Electronic Patient Record Supervisory Board and an overview of [B]'s viewings of the complainant's medical record, which had been referenced in the hospital's response letter. The requested documents were received on September 1, 2021.3. All of the above-mentioned documents have been taken into account in the resolution of the case, although not all are specifically detailed in the following ruling. Dispute4. The dispute concerns the legality of the searches [B] conducted in the complainant's medical record on December 23, 2021, April 22, and December 6, 2022, July 31, 2023, and July 23, 2024, in Landspítali's electronic health record systems. Events of the Case and Available Evidence 5. A summary of the searches in the complainant's medical record shows nine searches performed by [B] in the Saga medical record system of Landspítali. Two searches were conducted on December 23, 2021, April 22, 2022, December 6, 2022, and July 31, 2023, and one search on July 23, 2024.6. The Oversight Committee for the Electronic Patient Record at Landspítali reviewed the aforementioned queries following a complaint from the complainant in the fall of 2024. According to the committee's conclusion, dated December 30 of that year, [B] failed to demonstrate during the investigation that she had a legitimate reason to access the complainant's medical record on the occasions in question, and therefore [B] was found to have violated the provisions of Act No. 55\u002F2009 on Medical Records and Article 21. para. of the Civil Service Act No. 70\u002F1996. [B]'s conduct was reported to the Office of the National Superintendent of Health and the Data Protection Authority, in accordance with paragraphs 2 and 3 of Article 22 of the Act No. 55\u002F2009.The Parties' Positions. The Complainant's Position7. The complainant's position is that [B] had no legitimate reason to access and review her medical record, as [B] was not involved in her treatment in any way. [...]. Position of Landspítali8. Landspítali refers to the conclusion of the Supervisory Board for Electronic Patient Records, see discussion in paragraph 6. Since [B] exceeded her access privileges under the Act on Medical Records No. 55\u002F2009 and the hospital's regulations, she herself is responsible for the searches in the complainant's medical record. In this regard, Landspítalinn refers to a decision by the Data Protection Authority in case no. 2025020534, which concerned similar searches by the same emplo","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Pers%C3%B3nuvernd_(Island)_-_2025051308&diff=53352&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fthumb\u002F7\u002F7d\u002FLogoIS.png\u002F1200px-LogoIS.png","2026-10-09T09:41:33+00:00","2026-10-09T10:00:11.994384+00:00",7,[18,21],{"name":19,"type":20},"Landspítali Hospital","vendor",{"name":22,"type":23},"Saga medical record system","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]