Data Controller breaches several provisions in its processing of Sensitive Personal Data [2007] IEDPC 2
B. H. breached the Data Protection Acts by processing and disclosing sensitive personal data for purposes incompatible with those for which it was obtained, without the data subject's consent, and failed to comply with the access request.
- Citation
- [2007] IEDPC 2
- Parties
- Respondent: B. H.; Applicant: Data subject (former employee)
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Complaint / Decision by Data Protection Commissioner
- Outcome
- Complaint upheld; breaches found
- Legal Topics
- Processing of Sensitive Personal Data, Compatibility of Data Processing Purposes, Access Requests, Legal Proceedings Exemption
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
B. H.
Respondent
Data subject (former employee)
Applicant
Procedural Posture
Data Protection Complaint / Decision by Data Protection Commissioner
Legal Issues
- 1 Whether B. H. breached data protection laws by processing and disclosing sensitive personal data for purposes other than those for which it was obtained
- 2 Whether B. H. failed to comply with the data subject's access request
Ratio Decidendi
B. H. breached the Data Protection Acts by processing and disclosing sensitive personal data for purposes incompatible with those for which it was obtained, without the data subject's consent, and failed to comply with the access request.
Court Disposition
Complaint upheld; breaches found
Orders
- B. H. found in breach of Data Protection Acts for improper processing and disclosure of sensitive personal data
- B. H. found in breach for failure to comply with access request
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment