CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 18 (2013)

CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 18 (2013)

The data controller had basic security measures and backup systems in place but failed to ensure the backup system was functioning, resulting in the loss of five months of patient data. The Commission emphasised the necessity of regular system checks and targeted patient notification.

Citation
[2013] IEDPC 18
Parties
Data Controller: Medical Practitioner (Data Controller); Regulator: Irish Data Protection Commission
Jurisdiction
Ireland
Procedural Posture
Data Protection Complaint / Investigation and Resolution
Outcome
recommendations issued
Legal Topics
Ransomware, Data Breach, Patient Data, Backup Failure, Security Measures

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 2 Authorities cited 1 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Parties

Medical Practitioner (Data Controller)

Data Controller

Irish Data Protection Commission

Regulator

Procedural Posture

Data Protection Complaint / Investigation and Resolution

  1. 1 Whether the data controller took appropriate technical and organisational measures to protect personal data
  2. 2 Whether the data controller responded appropriately to a ransomware attack and subsequent data loss

Ratio Decidendi

The data controller had basic security measures and backup systems in place but failed to ensure the backup system was functioning, resulting in the loss of five months of patient data. The Commission emphasised the necessity of regular system checks and targeted patient notification.

Court Disposition

recommendations issued

Orders

  • Notify affected patients whose records were compromised
  • Implement regular checks of backup and security systems