[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffcSDiQbHuhtBbbQNao1AB4XgD4GxYITjqUd0x93OeV0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"68e85402-3c39-4ccd-8383-576ddda8bdeb","medical-employee-fined-for-photographing-and-sharing-patient-data-without-consent","2caed4ce-c315-43fc-ae2f-69788e1ff344","Medical Employee Fined for Photographing and Sharing Patient Data Without Consent","A medical services employee violated GDPR by photographing two patients and sharing those images with unauthorized third parties, acting as an independent data controller outside the scope of his employment duties. The root failure was a lack of security awareness and disregard for data protection obligations, compounded by insufficient workplace policies around personal device use in sensitive environments. Because the data involved constituted special category health data under GDPR Article 9, the breach carried heightened legal consequences. This case illustrates that individual employees can bear personal legal liability for mishandling patient data, not just their organizations.","**Immediate actions:**\n- Enforce a strict no-photography policy in all clinical and patient-facing areas, backed by visible signage and employment agreements.\n- Revoke or restrict personal device use in areas where sensitive patient data is accessible.\n\n**Long-term improvements:**\n- Deliver mandatory, role-specific GDPR and data protection training for all staff handling health or personal data at least annually.\n- Embed data protection clauses and disciplinary consequences into employment contracts to clarify individual accountability.\n- Establish a clear acceptable use policy (AUP) covering personal devices, photography, and sharing of any patient-related information.\n\n**Detection & Response measures:**\n- Implement a reportable incident procedure so staff can quickly escalate suspected unauthorized data sharing.\n- Conduct periodic audits and spot-checks of data handling practices in clinical environments to identify policy violations early.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 4 (Controller definition)","GDPR Article 5 (Principles of data processing)","GDPR Article 6 (Lawfulness of processing)","GDPR Article 9 (Special category data)","NIST SP 800-53 AT-2 (Security Awareness Training)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 MP-1 (Media Protection Policy)","CIS Control 14 (Data Protection)","CIS Control 17 (Security Awareness and Skills Training)","ISO 27001 A.7.2.2 (Information Security Awareness, Education and Training)","ISO 27001 A.8.2.3 (Handling of Assets)","published","2026-10-06T16:20:39.496812+00:00","2026-10-06T16:20:39.204+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2026-0.483.002&diff=53314&oldid=0","dsb-austria-2026-0-483-002-605e58","DSB (Austria) - 2026-0.483.002",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]