Search
Contact
26.10.2018 | KPMG Law Insights

DSGVO fine imposed

GDPR: Portuguese supervisory authority imposes fine of EUR 400,000 on hospital

The Portuguese data protection supervisory authority has imposed a fine of EUR 400,000 on a hospital. This is – at least as far as is known – the first significant fine across Europe following the entry into force of the General Data Protection Regulation (GDPR) on May 25, 2018.

Background

The Portuguese data protection authority CNPD (Comissão Nacional de Protecção de Dados) has announced that a large part of the fine was based on the fact that too many people had access to patient data at the hospital concerned. For example, data that was supposed to be accessible only to physicians could also be accessed by technicians. In addition, nearly 1,000 users were registered in the system as “doctors,” although the hospital actually employed just under 300 physicians.

Legal classification

Personal data must be protected – and not just since the DSGVO came into force – in such a way that only those employees have access who actually have to work with precisely this data and therefore need access. This principle is now also explicitly enshrined in law under the heading “privacy by design” (or “data protection through technology design”).

This principle applies in particular to the hospital sector, since this involves especially sensitive data that is also protected by criminal law in Germany. An incident like the one in Portugal could therefore also bring the law enforcement authorities on the scene in Germany.

Evaluation

The hospital reportedly plans to take legal action against the fine. In this respect, it remains to be seen whether the competent courts share the legal assessment of the data protection authority and, in particular, consider the amount of the fine to be appropriate.

Basically, according to the known facts, this is a serious case, which, moreover, concerns particularly sensitive data. However, it also shows that the authorities are prepared not only to look for very obvious violations, but also to delve deeper into the systems of those responsible.

Recommendation

The German data protection supervisory authorities issued guidance on the use of hospital information systems years ago. One focus of this guidance is on the design of access rights. It can be assumed that the recommendations contained in the guidance will largely remain valid after the GDPR comes into force.

Those responsible – not only from the healthcare sector – are therefore well advised to put their authorization concepts to the test. In the case of official controls, the responsible party must demonstrate an authorization concept in which access is limited to what is actually required. The controller must also be able to use it to justify why a person needs access to certain data. Even the lack of proof (under the keyword “accountability”) can trigger a fine.

Explore #more

12.12.2025 | KPMG Law Insights

Focus offshore: NRW buys extensive tax data on international tax havens

According to recent press reports from December 11, 2025, the state of North Rhine-Westphalia has purchased an extensive data set with tax-relevant information from international…

12.12.2025 | Deal Notifications

KPMG Law advises The Chemours Company on the implementation and closing of a large-volume factoring financing

KPMG Law Rechtsanwaltsgesellschaft GmbH (KPMG Law) advised the US-American Chemours Company on the implementation of a cross-border factoring financing. The legal implementation was managed by…

11.12.2025 | KPMG Law Insights

First omnibus package to relax CSDDD, CSRD and EU taxonomy obligations

Negotiators from the EU Parliament and the Council have now reached an agreement on the outstanding points of the first omnibus package. The content of…

11.12.2025 | KPMG Law Insights

IPCEI-AI: Requirements for funding and evaluation criteria

On December 5, 2025, the Federal Ministry for Economic Affairs and Energy launched the expression of interest procedure for the “IPCEI Artificial Intelligence” (IPCEI-AI) funding…

11.12.2025 | In the media

Interview in TextilWirtschaft – What the relaxed EU supply chain law means for the industry

After weeks of debate, the weakened form of the CSDDD has now been adopted in Brussels. This brings new, complex legal uncertainties for companies, says…

02.12.2025 | KPMG Law Insights

Implementation of the Pay Transparency Directive: what the expert commission recommends

The EU Pay Transparency Directive has been in force since June 2023 and must now be transposed into German law. In the coalition agreement,…

28.11.2025 | In the media

KPMG Law Guest article Expert forum on employment law: Between theory and practice: The EU Blue Card and the right to short-term mobility within the EU

Nowadays, not only employees but also employers want to create more attractive working conditions. For some time now, so-called workstations / work-from-anywhere programs or other…

26.11.2025 | KPMG Law Insights

EU deforestation regulation forces companies to act

Anyone who trades in or uses the raw materials soy, oil palm, cattle, coffee, cocoa, rubber and wood and certain products made from them should…

25.11.2025 | KPMG Law Insights

Special infrastructure assets: how the administration manages to implement projects quickly

The special infrastructure fund creates the opportunity to catch up on years of investment backlog. There is a need for urgency. Defence capability, economic growth…

21.11.2025 | In the media

KPMG Law Interview in Real Estate I Haufe: Substitute building materials: “Secondary is not second class”

The Substitute Building Materials Ordinance is intended to harmonize the circular economy in construction, but legal uncertainty and bureaucracy are holding it back. How can…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll