CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 18 (2013)
The data controller had basic security measures and backup systems in place but failed to ensure the backup system was functioning, resulting in the loss of five months of patient data. The Commission emphasised the necessity of regular system checks and targeted patient notification.
- Citation
- [2013] IEDPC 18
- Parties
- Data Controller: Medical Practitioner (Data Controller); Regulator: Irish Data Protection Commission
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Complaint / Investigation and Resolution
- Outcome
- recommendations issued
- Legal Topics
- Ransomware, Data Breach, Patient Data, Backup Failure, Security Measures
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Medical Practitioner (Data Controller)
Data Controller
Irish Data Protection Commission
Regulator
Procedural Posture
Data Protection Complaint / Investigation and Resolution
Legal Issues
- 1 Whether the data controller took appropriate technical and organisational measures to protect personal data
- 2 Whether the data controller responded appropriately to a ransomware attack and subsequent data loss
Ratio Decidendi
The data controller had basic security measures and backup systems in place but failed to ensure the backup system was functioning, resulting in the loss of five months of patient data. The Commission emphasised the necessity of regular system checks and targeted patient notification.
Court Disposition
recommendations issued
Orders
- Notify affected patients whose records were compromised
- Implement regular checks of backup and security systems
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment