The Spanish authority imposes an €18,000 fine on ECG MÉDICA for a GDPR violation related to a health data breach

The Spanish data protection authority sanctioned a medical diagnostic center for insufficient security measures, including the absence of an early detection system, which led to the exfiltration and online publication of health data of 1,352 patients.

Facts and context

The Spanish data protection authority (AEPD) today published a sanction decision against ECG MÉDICA, S.L. including the imposition of a fine of €18,000 for failures related to the security of personal data.

The procedure was initiated following the company's notification of a personal data breach, which led to the exfiltration and online publication of medical reports.

Reasons for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that the company had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The breach, which occurred between June and July 2024, resulted in the exfiltration of data of 1,352 patients, including identification and health data. The investigation revealed deficiencies in proactive security measures, notably the absence of early warning systems that would have allowed quicker detection of the intrusion. The company only became aware of the incident in July 2024 following a third-party alert and discovered the online publication of 25 medical reports in April 2025. Although the authority did not find particular negligence, referring to the European Data Protection Board Guidelines 04/2022, it considered that the reactive measures taken after the discovery of the incident were insufficient to demonstrate prior compliance with the security obligation.

Authority's decision

Consequently, the authority imposed a fine of €18,000 on ECG MÉDICA, S.L.. This amount results from a 40% reduction on the initial fine of €30,000, granted following the recognition of responsibility and voluntary payment by the company.

Lessons learned

This decision reminds that:

  • Implementing reactive security measures after a data breach is not sufficient to meet the requirements of Article 32 of the GDPR; proactive measures, such as early intrusion detection systems, are essential.
  • The absence of internal detection of an intrusion over a prolonged period is an indicator of a failure of technical and organizational security measures.
  • The responsibility of an entity is increased when its main activity involves large-scale processing of special categories of data, such as health data, which is considered an aggravating factor.
  • Recognition of responsibility and voluntary payment of the fine can lead to a substantial reduction in its amount, illustrating the benefit for entities to cooperate with the supervisory authority.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire