[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fE1Kpg9EJJFcgm-B7zu8m1OTGjCWOmIMwCIqv-SX1cnA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"6e335b2a-6733-4a36-a345-b3fdfb880d94","employee-fined-for-photographing-and-sharing-patients-sensitive-health-data","1a1f753b-eec4-4078-ad0f-ba207e5c485d","Employee Fined for Photographing and Sharing Patients' Sensitive Health Data","An employee at a specialized care facility unlawfully photographed patients — revealing their physical impairments and care details — and shared those images, violating GDPR rules governing special categories of sensitive personal data. Austria's DPA determined the employee acted as an independent data controller, meaning individual staff members can bear direct legal and financial liability, not just their organizations. This case highlights that GDPR obligations extend to individuals, not solely to institutions, making personal accountability a very real risk. The incident underscores that insufficient staff training on data privacy — particularly around sensitive health information — can result in serious legal consequences for both the individual and the organization's reputation.","**Immediate actions:**\n- Establish and enforce a clear, written policy prohibiting the photography or recording of patients and service users without explicit documented consent.\n- Remove or restrict personal device camera access in sensitive care areas through technical controls or device management policies.\n\n**Long-term improvements:**\n- Deliver mandatory, role-specific GDPR and data protection training to all staff who interact with sensitive personal data, with annual refreshers and competency assessments.\n- Implement a formal data protection awareness programme that explicitly covers special category data (health, disability) and the personal legal consequences of misuse.\n- Embed data protection impact assessments (DPIAs) into onboarding processes for roles with access to vulnerable populations.\n\n**Detection & governance measures:**\n- Establish a confidential reporting mechanism (whistleblower line) so staff and patients can report suspected unlawful data processing.\n- Conduct periodic audits of staff understanding of data handling obligations, particularly for employees working with vulnerable individuals.\n- Appoint or consult a Data Protection Officer (DPO) to review policies and provide ongoing guidance on lawful processing of health-related data.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 9 – Processing of special categories of personal data","GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 6 – Lawfulness of processing","GDPR Article 83 – General conditions for imposing administrative fines","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 MP-1 – Media Protection Policy","CIS Control 14 – Security Awareness and Skills Training","CIS Control 3 – Data Protection","ISO\u002FIEC 27001 Annex A 6.3 – Information Security Awareness, Education and Training","ISO\u002FIEC 27001 Annex A 5.34 – Privacy and Protection of Personal Identifiable Information","ITIL – Service Transition: Knowledge Management (staff competency)","published","2026-10-06T16:20:25.215725+00:00","2026-10-06T16:20:25.103+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2026-0.483.002&diff=53315&oldid=53314","dsb-austria-2026-0-483-002-758fe0","DSB (Austria) - 2026-0.483.002",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]