[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faRKgCycCA1FM_SR4jYII1qy78TCmHeeGPD9Wqs4fMjo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"7e77aea6-5b7a-46ad-964f-ac89f9acc347","unlawful-disclosure-of-medical-data-to-employer-triggers-gdpr-fine","4dc7f10e-b5cd-4cf9-bc74-88f7fd981090","Unlawful Disclosure of Medical Data to Employer Triggers GDPR Fine","An individual unlawfully shared another person's sensitive medical data with their employer without a valid legal basis under GDPR, resulting in a €600 fine from the Austrian Data Protection Authority. Article 9 of GDPR establishes strict conditions for processing special category data such as health information, and the exception for legal claims under Article 9(2)(f) was inapplicable because the relevant claim was time-barred and no proceedings were active. This case highlights that individuals — not just organizations — bear personal responsibility for how they handle others' personal data. Even well-intentioned disclosures can constitute serious GDPR violations when no lawful basis exists, underscoring the need for broad data protection awareness beyond IT teams.","**Immediate actions:**\n- Train all staff and individuals handling personal data on GDPR lawful bases, particularly the strict conditions governing special category data under Article 9.\n- Establish a clear internal review process requiring legal sign-off before any health or sensitive personal data is disclosed to third parties.\n\n**Long-term improvements:**\n- Implement a data classification policy that flags health and special category data for heightened handling controls and mandatory justification logs.\n- Develop and regularly update a data-sharing policy that explicitly maps permissible disclosures to their GDPR lawful bases.\n- Conduct annual GDPR awareness refreshers for all personnel, including case studies on individual liability for unlawful data sharing.\n\n**Detection & accountability measures:**\n- Maintain an audit log of all instances where personal data — especially health data — is shared externally, including the stated lawful basis.\n- Designate a Data Protection Officer (DPO) or privacy contact point to advise on borderline disclosure decisions before action is taken.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 9 – Processing of special categories of personal data","GDPR Article 9(2)(f) – Legal claims exception","GDPR Article 5(1)(a) – Lawfulness, fairness and transparency principle","GDPR Article 83 – General conditions for imposing administrative fines","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 AC-3 (Access Enforcement)","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27001 Annex A.8.2 – Information Classification","ISO\u002FIEC 27701 – Privacy Information Management","published","2026-07-25T10:20:35.431089+00:00","2026-07-25T10:20:35.145+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2021-0.518.795&diff=52496&oldid=24492","dsb-austria-2021-0-518-795-e020b0","DSB (Austria) - 2021-0.518.795",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"3beba6d1-c744-400a-b584-183f0c66f5c4","2026-07-25","afternoon","ThreatNoir Weekend Brief — July 25","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-25\u002Fthreatnoir-afternoon-brief-2026-07-25.mp3"]