AZOP (Croatia) - AZOP (Croatia)

From GDPRhub
AZOP - AZOP (Croatia)
Authority: AZOP (Croatia)
Jurisdiction: Croatia
Relevant Law: Article 13 GDPR
Article 32 GDPR
Article 33 GDPR
Article 34(1) GDPR
Type: Investigation
Outcome: Violation Found
Started: 11.02.2026
Decided:
Published: 17.02.2026
Fine: 3,000 EUR
Parties: n/a
National Case Number/Name: AZOP (Croatia)
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Croatian
Original Source: AZOP (in HR)
Initial Contributor: RP

The DPA fined a hospital €3,000 for a failure to report a data breach in time and for an insufficient incident response plan. The DPA opened its investigation after an employee unlawfully photographed a screen showing medical data and disclosed it externally.

English Summary

Facts

The Croatian Personal Data Protection Agency (AZOP) initiated supervisory proceedings against a hospital acting as controller after media outlets published a photograph of a computer screen showing a patient’s medical report. An employee had taken the photograph inside the hospital and disclosed it externally. The controller became aware of the incident on 16 November 2023, when the publication appeared and the police opened criminal proceedings.

On 11 September 2024, AZOP carried out an on-site inspection to assess compliance with the GDPR. AZOP examined the controller’s transparency practices, its technical and organisational measures, and its handling of the incident.

The hospital’s website contained contact details of the data protection officer and a form for exercising rights, but it did not explain the purposes of processing, the legal basis, the retention period, or other mandatory information. The controller only published more detailed information after the inspection.

AZOP also reviewed the controller’s internal data protection and IT security rules. These documents did not clearly define a personal data breach, did not establish a structured breach assessment procedure, and did not demonstrate regular review or testing of security measures.

The controller did not notify AZOP within 72 hours of becoming aware of the disclosure. It considered the incident primarily a criminal offence by an employee and not a personal data breach under the GDPR. The controller also did not proactively inform the affected data subject. The data subject received information only after their representative contacted the controller.

Holding

AZOP found that the controller infringed Article 13 GDPR, Article 32 GDPR, Article 33 GDPR and Article 34(1) GDPR. It imposed an administrative fine of €3,000.

AZOP held that the controller breached Article 13 GDPR because it failed for several years to provide data subjects with the mandatory information on the processing of their personal data. The authority stressed that transparency enables data subjects to understand and exercise their rights. Publishing only contact details of the data protection officer did not satisfy this obligation.

AZOP found a breach of Article 32 GDPR because the controller had not implemented appropriate technical and organisational measures for the processing of health data, which fall under Article 9 GDPR and require enhanced protection. The internal rules were incomplete and outdated. They did not ensure proper breach management, risk assessment, or regular evaluation of safeguards. AZOP clarified that the unauthorised disclosure met the definition of a personal data breach under Article 4(12) GDPR. The controller remained responsible for preventive measures, even if an employee committed a criminal offence.

AZOP held that the controller infringed Article 33 GDPR because it did not notify the supervisory authority within 72 hours after becoming aware of the breach. The disclosure of medical data to the media clearly posed a risk to the rights and freedoms of the data subject. The controller’s internal assessment of the incident as purely criminal did not remove its notification duty.

Finally, AZOP found a breach of Article 34(1) GDPR because the controller did not inform the data subject without undue delay. The public disclosure of health data created a high risk, which required direct communication. Police involvement did not replace this obligation.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.

(567-UP/I-034-01/24-01/31-1DV)

P/

REPUBLIC OF CROATIA
AGENCY FOR THE PROTECTION

OF PERSONAL DATA

CLASS:

NUMBER:
Zagreb,

Personal Data Protection Agency (OIB: 28454963989), pursuant to Article 57, paragraph 1,
Article 58, paragraph 1 and 2, item (i) and Article 83 of Regulation (EU) 2016/679 of the European Parliament and of the
Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the
free movement of such data, and repealing Directive 95/46/EC (General

Data Protection Regulation) OJ EU L119, Articles 44, 45 and 46 of the Act on the Implementation of the General
Data Protection Regulation (Official Gazette No. 42/18) and Article 42, paragraphs 1 and 2, and Article 96 of the General Administrative Procedure Act (Official Gazette No. 47/09, 110/21) in the proceedings initiated ex officio, issues the following:

DECISION

1. It is established that the institution Hospital X from __, as the controller, in the period from May 2018
to September 2024, did not provide the respondents with information on the processing of personal data, in accordance with
the obligation under Article 13 of the General Data Protection Regulation.

2. It is established that the institution Hospital X from __, as the controller, did not adequately
implement and test organizational protection measures aimed at ensuring the security of the processing of
health data, in accordance with the obligation under Article 32 of the General Data Protection Regulation.

3. It is established that the institution Hospital X from __, as the controller, did not notify the Personal Data Protection Agency of the personal data breach within 72 hours of becoming aware of it, in accordance with the obligation under Article 33 of the General Data Protection Regulation.

4. It is established that the institution Hospital X from __, as the controller, did not notify the data subjects whose data was the subject of the personal data breach of the personal data breach, in accordance with the obligation under
Article 34, paragraph 1 of the General Data Protection Regulation.

5. For violations of the obligations under Articles 13, 32, 33 and 34, paragraph 1 of the General Data Protection Regulation,
described in points 1 - 4 of the operative part of this decision, in accordance with the provisions of Article 83 of the General Data Protection Regulation, an administrative fine in the amount of:

3,000.00 Euros
(in words: three thousand euros)

6. The institution Hospital X from __ is obliged to pay the imposed administrative fine to the state
budget within 15 days from the date of entry into force of this decision to the account number:

1 HR1210010051863000160, model HR64 and reference to the approval number: __ with the indication – “administrative
fines imposed by the AZOP”.

7. If the institution Hospital X from __, within 15 days from the entry into force of this decision, does not pay the imposed administrative fine, the Personal Data Protection Agency will, in accordance with Article 46, paragraph 2 of the Act on the Implementation of the General Data Protection Regulation, notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the seat of the said company is located, in order to collect the administrative fine by force in accordance with the regulations on forced tax collection.

8. The institution Hospital X from __ is obliged to submit proof of payment to the Personal Data Protection Agency within 15 days from the payment.

R e a s s i n g s i n g

I. DETERMINATION OF VIOLATION

On 11.09.2024. in the proceedings CLASS: __ initiated against Hospital X (hereinafter: the controller

), upon a request for determination of a violation of the rights of the data subject whose personal data were the subject
of a personal data breach, the Personal Data Protection Agency (hereinafter: the Agency) conducted
a supervisory proceeding regarding the controller's compliance with the provisions of the General Data Protection Regulation regarding the transparency and security of the processing of personal data. By decision
CLASS: __, NUMBER: __ of __, it was determined that the personal data breach (hereinafter:
the personal data breach in question) occurred as a result of a security breach that led
to the unauthorized disclosure to the media of medical documentation stored in the hospital

information system of the controller in question. It is important to point out that in the situation in question
an unknown employee of the controller took a photograph of the computer screen on which was
a display of a medical report containing patient data. During the implementation of the supervisory procedure, irregularities were identified that were not the subject of the request of the respondent based on whose request the procedure was initiated, and as a result, an ex officio procedure was initiated in order to harmonise the personal data processing procedures with the provisions of the General Data Protection Regulation.

During the procedure, the Agency carried out direct supervisory activities on 11.09.2024 at the data controller of Hospital X, and a Report on the supervision carried out on 11.09.2024 was drawn up (CLASS:__; NUMBER: __, which is attached to the case file).

The supervisory procedure in question established that the data controller did not provide the respondents with information on the processing of personal data in a transparent manner. Namely, until the day of the supervision, the data subjects were provided with information on the controller's website in the form of a decision on the appointment of the Personal Data Protection Officer, contact details and a template form for exercising rights, and a separate document relating to information on the processing of personal data was not drawn up, this was determined during the supervisory procedure in accordance with the statement of the Personal Data Protection Officer appointed by the controller (hereinafter: Personal Data Protection Officer). After the supervision, the Agency, by document CLASS: __, NUMBER: __ dated 17.09.2024, once again requested the controller to provide a statement on the manner in which the data subjects were informed about the processing of personal data. On 01.10.2024, the Agency received the requested statement from the controller, stating that the controller, after the supervision, published information on the processing of personal data in a separate document on the website. In relation to the Agency officer's inquiry, made during the supervision on 11.09.2024, whether amendments and supplements to the internal act entitled "Rules on the Collection, Processing and Protection of Personal Data of Hospital X" dated 27.09.2018 had been adopted and whether there were other acts relating to the protection of personal data and the application of organizational and technical protection measures, the personal data protection officer stated that the said Ordinance was current and that an internal act entitled "Security Procedures" and its supplements had also been adopted. Also, the personal data protection officer attached a document entitled "Personal Data Protection - Instructions" during the supervision. Upon reviewing the internal act of the processing manager entitled "Rules on the Collection, Processing and Protection of Personal Data of Hospital X" dated 27.09.2018 (hereinafter: the Ordinance), it was determined that it does not define the concept of personal data breach. Furthermore, Art. 13. of the Regulations stipulates that heads of organizational units are obliged to notify the Personal Data Protection Officer of a personal data breach. Article 20. of the Regulations, among other things, stipulates that the controller shall implement personal data protection measures in such a way that the persons authorized to process personal data are responsible for protecting personal data from accidental or unlawful destruction, loss, alteration and unauthorized access, without defining the persons authorized to process personal data or the manner in which they should do the same. 

Upon reviewing the internal act of the controller entitled "Procedure of the Information System of Hospital X" dated 28.02.2022 (hereinafter: the Procedure), it was determined that in point IX. of the Procedure it is stipulated that the introduction of private computer and communication equipment and its connection to the institution's IT system is not allowed. Furthermore, the same point stipulates that the user is obliged to report the loss of computer and communication devices to the Department of Information Technology. 

Upon inspection of the document entitled "Personal Data Protection - Instructions" (hereinafter: Instructions), it was determined that
it, among other things, contains the following instruction: "In the event of a personal data breach, which
is related to our data processing system, we are obliged to notify all relevant persons and the competent authority
within 72 hours of becoming aware of the breach, if it is likely that the personal data breach
will cause a risk to the rights and freedoms of individuals."

During the supervision carried out on 11.09.2024. at the request of an authorized officer of the Agency,
when and how the controller learned about the personal data breach in question in the form of,
the publication of a photograph of the computer screen showing the medical findings of the respondent in the media,
the representative of the controller stated that the information about the aforementioned event was visible to everyone from the publication in the media and that he did not know the exact date and that immediately, on 16.11.2023., following

a report in the media about the disclosure of this data, the police also initiated proceedings. Furthermore, when asked about the reason for not reporting to the supervisory body (Agency) within the statutory 72-hour period, the representative of the controller stated that the initial check determined that there was no intrusion into the hospital storage system, but rather that it was the actions of an employee, which constitutes a criminal offense and is the responsibility of the police. Accordingly, the representative of the controller stated that they considered it unnecessary to report to the Agency as the supervisory body for the implementation of the General Data Protection Regulation. Furthermore, in relation to the question of why the heads of organizational units within which the personal data breach occurred did not report the breach to the personal data protection officer appointed by the controller, the representative of the controller stated that after the police initiated action, they did not involve a wider circle of people other than those directly responsible, given that police investigations are secret. During the supervision conducted on 11.09.2024. When asked by an authorized officer of the Agency whether, upon learning of the event in the form of the removal of health data from the storage system of the controller, any information was sent to the respondent whose data was not authorized to be delivered to the media, the personal data protection officer appointed by the controller stated that the respondent was provided with information related to the personal data breach only after the respondent's attorney-in-fact contacted the controller. When asked directly whether an analysis had been made regarding the possibility of a risk to the rights and freedoms of individuals in accordance with Article 34 of the General Data Protection Regulation, the personal data protection officer stated that this had not been done and that she, as the data protection officer, was involved in resolving the specific issue only after receiving a letter from the respondent's attorney-in-fact, given the circumstance of the police conducting an investigation due to the commission of a criminal offence, for which reason it was deemed that no other measures and actions were necessary.

In addition to the above, we would like to point out that since May 25, 2018, the General Data Protection Regulation has been directly and bindingly applied in all member states of the European Union, including the Republic of Croatia.

Article 4, point 12, stipulates: “‘personal data breach’ means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed;”

Article 13 of the General Data Protection Regulation stipulates:
“1. Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time of collection of the personal data, provide the data subject with all of the following information:

(a) the identity and contact details of the controller and, where applicable, of the controller’s representative
;
(b) the contact details of the data protection officer, where applicable;
(c) the purposes of the processing for which the personal data are used and the legal basis for the processing;
(d) where the processing is based on Article 6(1)(f), the legitimate interests pursued by the controller
or by a third party;
(e) the recipients or categories of recipients of the personal data, if any; and
(f) where applicable, the fact that the controller intends to transfer the personal data
to a third country or an international organisation and the existence or absence of an adequacy decision
by the Commission, or in the case of transfers referred to in Articles 46 or 47 or the second subparagraph of Article 49
paragraph 1 reference to the appropriate or adequate safeguards and
the means of obtaining a copy of them or the place where they are made available.
2. In addition to the information referred to in paragraph 1, the controller shall, at the time when the personal data are collected,
provide the data subject with the following additional information necessary to ensure fair and
transparent processing:
(a) the period for which the personal data will be stored or, where that is not possible, the criteria
which determined that period;
(b) the existence of the right to obtain from the controller access to the personal data and rectification
or erasure of personal data or restriction of processing concerning the data subject or
the right to object to processing of such data and the right to data portability;
(c) where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2),
the existence of the right to withdraw consent at any time, without affecting
the lawfulness of the processing based on consent before it was withdrawn;
(d) the right to lodge a complaint with a supervisory authority authority;

4 (e) information on whether the provision of personal data is a legal or contractual obligation or
a condition necessary for entering into a contract and whether the data subject is under an obligation to provide personal data
and what the possible consequences are of not providing such data;
(f) the existence of automated decision-making, including profiling referred to in Article 22
paragraphs 1 and 4 and, at least in such cases, meaningful information on the logic involved
as well as the significance and envisaged consequences of such processing for the data subject.

3. Where the controller intends to further process personal data for a purpose other
than that for which the personal data were collected, the controller shall, prior to such further processing, provide the data subject with information on that other purpose and any other relevant information referred to in paragraph 2.

4. Paragraphs 1, 2 and 3 shall not apply if and to the extent that the data subject already has
the information.

Article 32 of the General Data Protection Regulation stipulates:

“1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of individuals, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, where appropriate:
(a) pseudonymisation and encryption of personal data;
(b) the ability to ensure the permanent confidentiality, integrity, availability and resilience of the processing systems and services;
(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing and assessing the effectiveness of the technical and organisational measures to ensure the security of the processing.
2. When assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of personal data or unauthorised access to personal data that are
transmitted, stored or otherwise processed.
3. Adherence to an approved code of conduct referred to in Article 40 or an approved certification mechanism referred to in Article 42 may be used as an element of demonstrating compliance with the
requirements referred to in paragraph 1 of this Article.
4. The controller and the processor shall take measures to ensure that any individual

acting under the responsibility of the controller or the processor who has access to personal data does not process those data except on instructions from the controller, unless he is
obliged to do so by Union or Member State law.

Article 33 of the General Data Protection Regulation stipulates:
“1. In the event of a personal data breach, the controller shall, without undue delay and, where
feasible, not later than 72 hours after having become aware of the breach, notify the personal data breach to the supervisory authority competent
in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, it shall be accompanied by reasons for the delay.
2. The processor shall notify the controller without undue delay after having become aware of the personal data breach.
3. The notification referred to in paragraph 1 shall at least:
(a) describe the nature of the personal data breach, including, where possible, the categories and

the approximate number of data subjects concerned and the approximate number of personal data records concerned;
(b) indicate the name and contact details of the data protection officer or other contact point
from whom the personal data breach may be obtained. more information;

5 (c) describe the likely consequences of the personal data breach;
(d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse consequences.
4. If and to the extent that it is not possible to provide the information at once, the information shall be provided in stages without undue further delay.

5. The controller shall document all personal data breaches, including the facts relating to the personal data breach, its consequences and the measures taken to remedy the damage. That documentation shall enable the supervisory authority to verify compliance with this Article.

Article 34 of the General Data Protection Regulation stipulates:
“1. In the event of a personal data breach which is likely to result in a high risk to the rights and freedoms of individuals, the controller shall communicate the personal data breach to the data subject without undue delay.
2. The communication to the data subject referred to in paragraph 1 of this Article shall describe the nature of the personal data breach using clear and plain language and shall contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3).
3. The communication to the data subject referred to in paragraph 1 shall not be mandatory where any of the following
conditions is met:
(a) the controller has taken appropriate technical and organisational protection measures and those measures are applied to the personal data affected by the personal data breach, in particular
those which make the personal data unintelligible to any person not authorised to access them, such as encryption;
(b) the controller has taken subsequent measures ensuring that a high
risk is no longer likely to occur the risk to the rights and freedoms of the data subject referred to in paragraph 1;
(c) this would require a disproportionate effort. In such a case, there shall be a public notice or a similar measure informing the data subject in an equally effective manner.
4. If the controller has not by that time notified the data subject of the personal data breach,
after considering the level of likelihood that the personal data breach will result in a high risk,
the supervisory authority may require it to do so or may conclude that one of the
conditions referred to in paragraph 3 is met.

Accordingly, in this administrative case it was established that the controller, in the period from 25.05.2018 to September 2024, failed to provide the data subject with basic information on the processing of personal data in the form of information; on the purposes of the processing for which the personal data are used and the legal grounds for the processing; the legitimate interests of the controller or a third party; the recipients or categories of recipients of the personal data, as well as information on;
the period for which the personal data will be stored or, if that is not possible, the criteria by which that period was determined and information on whether the provision of personal data is a legal or

contractual obligation or a condition necessary for concluding a contract and whether the data subject is obliged to provide
personal data and what the possible consequences are if such data is not provided. Based on which, a violation of Article 13 of the General Data Protection Regulation was established.

During this administrative procedure, by reviewing the internal acts of the Rules, Procedures and Instructions
and the statements of the representatives of the data controller given during the supervision carried out on 11.09.2024.
it was established that the controller does not recognize situations and events that represent a possible

violation of personal data and that may negatively affect the devices and freedoms of individuals. Namely,
in the specific case, the controller did not recognize the event in the form of unauthorized disclosure of personal data of the respondents stored in the hospital information system as a violation of personal data, but defined the event in question only as a criminal offense of unauthorized

use of personal data under Article 146 of the Criminal Code. Furthermore, the same follows from the internal act
Procedure which stipulates that the user is obliged to report the loss of computer and communication devices to the Department of Information Technology, but not to the Data Protection Officer, who
must be informed of the violation of personal data in a timely manner. It is important to emphasize here that
the Criminal Code in Chapter Twenty-Five defines a series of criminal offenses against computer systems,
programs and data, for example; unauthorized access to computer systems or any of its

parts or computer data; unauthorized damage, modification, deletion, destruction or concealment of another's computer data or programs or disabling access to another's computer data or programs, which can very often result in a personal data breach in the form of destruction, loss, modification, unauthorized disclosure or access to personal data. In the above situations, criminal liability is borne by the perpetrator of the criminal offense, but also, in terms of the provisions of the General Data Protection Regulation, potentially by the controller if he has not implemented appropriate technical and organizational measures to minimize the risk of personal data breach.

Furthermore, in relation to the violation of the security of personal data processing, it was determined that the internal acts did not prescribe the manner in which the personal data protection officer will exercise control and supervision over personal data processing processes. It was also determined that the internal acts had not been revised since their adoption. Namely, the Ordinance has not been revised since 2018, while the Procedure has not been revised since 2022, despite the fact that one of the obligations of the controller is to regularly test and assess the effectiveness of technical and organizational measures to ensure the security of processing.

Also, the lack of understanding of the obligations of the controller under the General Data Protection Regulation is indicated by the provision of Article 20 of the Ordinance, which, among other things, prescribes that the controller implements personal data protection measures in such a way that persons authorized to process personal data are responsible for protecting personal data against accidental or unlawful destruction, loss, alteration and unauthorized access. Namely, it is the controller as an institution that is responsible for the security of the processing of personal data in the form of implementing appropriate technical and organizational measures aimed at preventing a security breach that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal data that are transmitted, stored or otherwise processed, and not the person authorized to process them. Namely, in accordance with the provisions of Article 32 of the General Data Protection Regulation, the controller is responsible for taking measures to ensure that any individual acting under his responsibility who has access to personal data does not process such data unless on the instructions of the controller. 

An overview of all the documents submitted by the controller shows that the controller does not distinguish between a violation of the rights of the data subject and a violation of personal data. Furthermore, the Ordinance, as well as other acts, does not prescribe how to assess whether a personal data breach will cause a high risk to the rights and freedoms of individuals. The Ordinance does not prescribe the manner in which the Data Protection Officer shall exercise control and supervision over the processing of personal data.

Therefore, the controller is obliged, in accordance with the General Data Protection Regulation, to prescribe in detail the manner in which personal data is processed in internal acts, in order to be able to prove that he has taken measures to ensure that each individual acting under his responsibility processes the data in accordance with the instructions. In this specific case, the controller submitted to the Agency internal acts that are not sufficiently elaborated, i.e. they do not contain clear instructions on the manner in which employees/persons under the responsibility of the controller should handle personal data.

7 Namely, the hospital, as the manager of high-risk processing of special categories of personal health data, is expected to elaborate in detail organizational measures in accordance with the high risk.
For example, it should have elaborated internal acts in the form of a rulebook that defines all aspects of the protection of personal data of patients and employees, including rules on the collection, processing, storage and access to personal data, regulates the rights of respondents (patients), such as the right to access, rectification and deletion of data, procedures for exercising patients' rights to access their data, rectification, transfer and deletion of data, as well as a procedure for managing complaints and objections related to the processing of their personal data, as well as the obligation to notify data breaches, which clearly define the responsible persons. Furthermore, considering that hospitals often store sensitive medical data, the controller should elaborate an internal rulebook on data retention that defines how long the data will be stored (based on legal deadlines) and the method of their secure deletion when the deadline expires or when the data is no longer needed for the purpose of processing, as well as the responsible persons for the above. Also, an information security regulation is necessary, which prescribes measures to protect information within the hospital, which includes IT system security, protection against cyber threats, data encryption, network security, antivirus protection and access management to sensitive data. Furthermore, an important regulation is one that prescribes technical measures for the security of computer systems and networks. This includes rules on firewalls, encryption of data in transmission, data backups, and protection against unauthorized access. It is also necessary to define access controls and supervision, including the use of access cards, video surveillance, and restricting access to certain areas. Internal regulations should also ensure that only authorized employees have access to sensitive patient data and other important information within the hospital. This includes defining access rights, creating and revoking passwords, and controlling access privileges based on employee position and responsibility. Internal
regulations should prescribe regular training and tests for staff, so that they are familiar with
best data protection practices, security threat recognition and responsibilities

related to data processing. Furthermore, internal regulations also regulate the procedure in the case
of a security incident, such as a cyber attack, unauthorized data access or loss
data. It prescribes protocols for reporting incidents, their analysis and notification to authorities
bodies.

The hospital as a processing manager must ensure that all employees, from medical staff to

administrative, to be familiar with organizational and technical measures and to apply them consistently
apply to ensure data security and protection of the rights of respondents/patients.

As a result of the above, and considering that during this procedure it was determined how they are
organizational measures contained in the submitted internal acts of the processing manager are not adequate,
not up-to-date, i.e. do not correspond to the risk of processing, a violation of Art. 32. General regulations on protection
data.


        A violation of Article 33 of the General Data Protection Regulation was established since the controller failed to notify the Personal Data Protection Agency, as the supervisory authority, of the personal data breach within the statutory period of 72 hours from becoming aware of the personal data breach in the form of a photograph in the media showing a screen showing the medical data of the respondent/patient contained within the hospital's BIS, although he had knowledge of the same on 16.11.2023. and the fact that the controller did not document any personal data breach, including the facts related to the personal data breach, its consequences and the measures taken to repair the damage over a period of 6 years.

8 In conclusion, a violation of Article 34, paragraph 1 of the General Data Protection Regulation was established since it was established that the controller in this specific case did not inform the respondent of the personal data breach even though he had knowledge that his health data had been unauthorizedly disclosed to the media.

II. IMPOSITION OF ADMINISTRATIVE FINES

Article 44 of the Act on the Implementation of the General Data Protection Regulation stipulates that the Agency shall impose administrative fines for violations of the provisions of this Act and the General Data Protection Regulation, in accordance with Article 83 of the General Data Protection Regulation.
Pursuant to Article 46 of the same Act, the administrative fine shall be paid within 15 days from the date of entry into force of the decision imposing it. If the party fails to pay the administrative fine within the prescribed period, or upon the maturity of the last installment if payment by installments has been approved, the Agency shall notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the party to whom the administrative fine has been imposed has its residence or registered office, in order to collect the administrative fine by force in accordance with the regulations on the forced collection of taxes.
Administrative fines shall be paid to the state budget. By way of derogation from paragraph 2 of this
Article, no interest shall be charged on a due but unpaid administrative fine.

Given the circumstances established in the specific case, the Agency, in accordance with its powers

under Article 58, paragraph 2, item (i) of the General Data Protection Regulation, imposed an administrative fine
instead of other corrective measures under the relevant Article, all in accordance with the conditions for its imposition under Article 83 of the General Data Protection Regulation and Articles 44 and 46 of the Act on the Implementation of the General Data Protection Regulation. After a detailed examination of the available remedies under Article 58(2) of the General Data Protection Regulation, which the supervisory authority is empowered to impose on the controller and/or processor in the event of an infringement of the provisions of the General Data Protection Regulation, and having regard to all the circumstances of the case, in particular that the chosen remedy must be effective, proportionate and dissuasive in each individual case, the Agency has decided to impose an administrative fine, paying due regard to the criteria laid down in Article 83(2) of the General Data Protection Regulation. Namely, Article 83(1) of the General Data Protection Regulation requires each supervisory authority to ensure that the imposition of administrative fines in accordance with this Article in respect of infringements of paragraphs 4, 5 and 6 of this Regulation is effective, proportionate and dissuasive in each individual case. The Agency considers that the amount of the imposed administrative fine cannot be effective if it does not have a significant impact on the controller's income, the principle of proportionality cannot be maintained if the violation is considered in the abstract, regardless of the impact on the controller or processor, and it should also be a deterrent against future violations. Therefore, the imposed administrative fine cannot be a deterrent if it does not have a financial impact on the controller in question. By imposing an administrative fine, the aim is to ensure that the rules on personal data protection are respected both by the controller itself and by all other controllers/processors regarding the security of personal data processing and the procedure in the event of a personal data breach. By imposing an administrative fine, general deterrence (to discourage others from repeating the same violation in the future) and specific deterrence (to discourage the addressee of this administrative fine from repeating the same violations).

Pursuant to Article 83(2) of the General Data Protection Regulation, administrative fines shall be imposed in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and Article 58(2)(j), depending on the circumstances of each case. When deciding whether to impose an administrative

fine and when deciding on the amount of that administrative fine in each case, due regard shall be paid to the following:

(a) the nature, gravity and duration of the infringement, taking into account the nature, scope and purposes of the processing concerned, as well as the number of data subjects and the level of harm suffered by them;

(b) whether the infringement was intentional or negligent;

(c) any action taken by the controller or processor to mitigate the harm suffered by data subjects;

(d) the level of responsibility of the controller or processor taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the level of cooperation with the supervisory authority to remedy the infringement and mitigate the potential adverse effects of that infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the supervisory authority became aware of the infringement, in particular whether and to what extent the controller or processor reported the infringement;
(i) where measures referred to in Article 58(2) have previously been imposed on the controller or processor concerned in relation to the same matter, compliance with those measures;
(j) compliance with approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42; and
(k) any other aggravating or mitigating factors applicable to the circumstances of the case,

such as the financial gain gained from the infringement or the losses avoided, directly or indirectly, by that infringement.

Furthermore, the provision of paragraph 3 of the same Article stipulates that if a controller or processor in respect of the same or related processing operations intentionally or negligently infringes several provisions of this Regulation, the total amount of the fine shall not exceed the administrative amount determined for the most serious infringement.

Article 83(4) of the General Data Protection Regulation stipulates that administrative fines of up to EUR 10 000 000 may be imposed for infringements of the obligations of controllers and processors laid down in Articles 32, 33 and 34 of the General Data Protection Regulation, or in the case of undertakings, up to 2% of the total worldwide annual turnover in the preceding financial year, whichever is the higher.

Article 83(5) of the General Data Protection Regulation provides that administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its worldwide annual turnover in the preceding financial year, whichever is the higher, may be imposed for infringements of the obligations of the controller and processor laid down in Article 13 of the General Data Protection Regulation. The Agency imposed an administrative fine of EUR 3,000.00 on the controller Hospital X for infringements of Articles 13, 32, 33 and 34 of the General Data Protection Regulation. Pursuant to Article 83(2) of the General Data Protection Regulation, when deciding on the imposition of an administrative fine and deciding on the amount of the administrative fine, the Agency in this case paid due attention to the following:

- The nature, gravity and duration of the infringement, taking into account the nature, scope and purpose of the processing in question, as well as the number of data subjects and the level of damage suffered by them (Article 83(2)(a);

In the case in question, it was established that the controller Hospital X, despite the high-risk and extensive processing of health data as its core activity, had not adequately implemented organisational protection measures in relation to the handling of personal data breaches, even 6 years after the entry into force of the General Data Protection Regulation. The protection of patients' personal data and the preservation of the confidentiality of health information are important not only for the sake of respecting the patient's privacy, but also for the sake of trust in the medical profession and the health services provided by doctors and other medical staff.

- Whether the infringement is intentional or negligent (Article 83(2)(b);
In the present case, no direct intention to infringe the provisions of the General Data Protection Regulation by the controller has been established, but rather the controller has acted negligently.

- Any action taken by the controller or processor to mitigate the damage suffered by the data subjects (Article 83(2)(c);
Since in the present case it has not been established that the data subjects have suffered damage, the same circumstance is not assessed as either mitigating or aggravating.

- The degree of responsibility of the controller or processor, taking into account the technical and

organisational measures implemented by them in accordance with Articles 25 and 32 (Article 83(2)(d);
As an aggravating circumstance, the Agency, when imposing an administrative fine, particularly assessed
the degree of misunderstanding of its obligations related to the security of the processing of special categories of personal
data. By not complying with the obligations to record personal data breaches,
failing to analyze the risks and failing to notify the supervisory authority of personal data breaches,
the controller seriously endangers the rights and freedoms of the data subjects whose personal data it processes.

It should also be noted that personal data breaches serve as indicators of system weaknesses that need to be improved so that the same breaches do not occur repeatedly, so
this was taken into account when setting the amount of the fine.

- Relevant previous breaches by the controller or processor (Article 83, paragraph 2,
item e);

The Agency has no relevant previous breaches of data protection provisions recorded by the controller.

-The degree of cooperation with the supervisory authority in order to eliminate the breach and mitigate the possible harmful
effects of that breach (Article 83, paragraph 2,
item f);
The controller responded appropriately to the requests of the supervisory authority during this administrative procedure.

- The categories of personal data affected by the breach (Article 83(2)(g);

The circumstance in question was taken into account as aggravating, given that the controller's main activity is the processing of health data, as a special category of personal data under Article 9 of the General Data Protection Regulation.

- The manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor reported the breach (Article 83(2)(h);

The Agency became aware of the personal data breach from the data subject's request, but, given that the controller was imposed an administrative fine for breaching the obligation to notify the supervisory authority, the same circumstance was not taken into account when determining the administrative fine.

- If the controller or processor concerned has been previously subject to measures referred to in Article 58(2) in relation to the same matter

, compliance with those measures (Article 83(2)(i);

11Since the controller has not been previously subject to a measure referred to in Article 58(2) of the GDPR, this circumstance shall not be taken into account when determining the amount of the administrative fine.

- Compliance with approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j);

Not relevant.

- Any other aggravating or mitigating factors applicable to the circumstances of the case, such as the financial gain gained from the infringement or the losses avoided, directly or indirectly, by the infringement (Article 83(2)(k);

When determining the amount of the administrative fine, the Agency did not establish other relevant circumstances that should be considered aggravating or mitigating.

A fine can be considered effective if it achieves the objectives for which it was imposed. This can be the re-establishment of compliance with the rules, the punishment of illegal behavior, or both. The Agency decided to impose an administrative fine as a corrective measure because the controller, even after 6 years from the start of the application of the General Data Protection Regulation, despite the fact that it processes health data as a special category of personal data, does not recognize its obligations under the General Data Protection Regulation or personal data breaches. Namely, one of the basic principles of personal data processing is the controller's obligation to ensure that the processing of personal data is secure, i.e. to implement appropriate organizational measures to ensure an appropriate level of security, taking into account the risk to the rights and freedoms of individuals. The fact that personal data breaches in hospitals can cause a high risk to rights and freedoms, even in the form of fatal consequences, is of decisive importance. The controller in this case cannot ensure an adequate level of security if it does not identify personal data breaches, does not involve the data protection officer in matters related to the protection of personal data, and does not regularly test, evaluate and assess the effectiveness of organizational measures to ensure the security of processing. The Agency conducted an investigation in accordance with Articles 51 and 52 of the General Administrative Procedure Act and in accordance with all principles of administrative procedure prescribed by the Administrative Procedure Act, correctly established the facts, and based on the established facts, correctly applied the substantive law and drew a correct conclusion on the facts in the specific case. It bases its decision on all relevant evidence and facts at its disposal and submitted as evidence by the controller. Likewise, taking into account all of the above, the Agency believes that the corrective measure in the form of an administrative fine is effective, proportionate and dissuasive in this administrative matter, and that its amount is fully appropriate to the circumstances of the specific case.

Based on all of the above, it was decided as in the Operative Part of the Decision.

INSTRUCTION ON LEGAL REMEDY

No appeal is allowed against this decision, but an administrative dispute may be initiated before the Administrative Court in __ within 30 days from the date of delivery of the decision.
DIRECTOR
Zdravko Vukić, univ. mag. oec.

12 SUBMIT:
1. Hospital X,
2. Filing Cabinet, here

13