CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 17 (2013)

CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 17 (2013)

As the patient file could not be accessed by the unintended recipient due to software restrictions, the incident was recorded as a non-breach.

Citation
[2013] IEDPC 17
Parties
Data Controller: G.P. (General Practitioner); Regulator: Irish Data Protection Commission; Third Party: Software Supplier
Jurisdiction
Ireland
Procedural Posture
Data Protection Complaint / Investigation
Outcome
non-breach recorded
Legal Topics
Data Breach, Email Misdirection, Data Security, Patient Confidentiality

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 1 Authorities cited 1 Party arguments 2
Sign in to unlock

Parties

G.P. (General Practitioner)

Data Controller

Irish Data Protection Commission

Regulator

Software Supplier

Third Party

Procedural Posture

Data Protection Complaint / Investigation

  1. 1 Whether the sending of a patient file to an incorrect email address constituted a data breach under Irish data protection law.

Ratio Decidendi

As the patient file could not be accessed by the unintended recipient due to software restrictions, the incident was recorded as a non-breach.

Court Disposition

non-breach recorded

Orders

  • No further action required.
  • Data controller advised to implement measures to prevent recurrence.