Search
Contact
26.10.2018 | KPMG Law Insights

DSGVO fine imposed

GDPR: Portuguese supervisory authority imposes fine of EUR 400,000 on hospital

The Portuguese data protection supervisory authority has imposed a fine of EUR 400,000 on a hospital. This is – at least as far as is known – the first significant fine across Europe following the entry into force of the General Data Protection Regulation (GDPR) on May 25, 2018.

Background

The Portuguese data protection authority CNPD (Comissão Nacional de Protecção de Dados) has announced that a large part of the fine was based on the fact that too many people had access to patient data at the hospital concerned. For example, data that was supposed to be accessible only to physicians could also be accessed by technicians. In addition, nearly 1,000 users were registered in the system as “doctors,” although the hospital actually employed just under 300 physicians.

Legal classification

Personal data must be protected – and not just since the DSGVO came into force – in such a way that only those employees have access who actually have to work with precisely this data and therefore need access. This principle is now also explicitly enshrined in law under the heading “privacy by design” (or “data protection through technology design”).

This principle applies in particular to the hospital sector, since this involves especially sensitive data that is also protected by criminal law in Germany. An incident like the one in Portugal could therefore also bring the law enforcement authorities on the scene in Germany.

Evaluation

The hospital reportedly plans to take legal action against the fine. In this respect, it remains to be seen whether the competent courts share the legal assessment of the data protection authority and, in particular, consider the amount of the fine to be appropriate.

Basically, according to the known facts, this is a serious case, which, moreover, concerns particularly sensitive data. However, it also shows that the authorities are prepared not only to look for very obvious violations, but also to delve deeper into the systems of those responsible.

Recommendation

The German data protection supervisory authorities issued guidance on the use of hospital information systems years ago. One focus of this guidance is on the design of access rights. It can be assumed that the recommendations contained in the guidance will largely remain valid after the GDPR comes into force.

Those responsible – not only from the healthcare sector – are therefore well advised to put their authorization concepts to the test. In the case of official controls, the responsible party must demonstrate an authorization concept in which access is limited to what is actually required. The controller must also be able to use it to justify why a person needs access to certain data. Even the lack of proof (under the keyword “accountability”) can trigger a fine.

Explore #more

23.07.2026 | In the media

Statement by KPMG Law experts on Südwestrundfunk (SWR) regarding the GKV Savings Act

On the TV program ” SWR Aktuell Rheinland-Pfalz,” KPMG Law hospital expert Harald Maas discusses the GKV Savings Act and the growing financial pressure…

21.07.2026 | In the media

KPMG Law Guest Article in SpringerProfessional: Strategically Managing Geopolitical Supply Chain Risks

Global supply chains and international business models are under pressure as never before: Geopolitical tensions, industrial policy initiatives, and stricter foreign trade regulations are rapidly…

17.07.2026 | KPMG Law Insights

New Packaging Implementation Act tightens obligations for companies

  Co-author: Séverine Sieprath, Director of Audit, KPMG AG Wirtschaftsprüfungsgesellschaft   The Packaging Implementation Act (VerpackDG),…

17.07.2026 | KPMG Law Insights

Action Plan Against Tax Crime: Voluntary Disclosure Allowing for Immunity from Prosecution to Be Abolished

Tax and financial crime will be prosecuted more rigorously in Germany going forward. On July 16, 2026, Federal Minister of Finance Lars Klingbeil and Federal…

15.07.2026 | In the media

KPMG Law Guest Post on the DVNW Procurement Blog: Section 97a of the German Act Against Restraints of Competition (GWB): Slight Relief for Lump-Sum Contracts

On July 1, 2026, the Act on Accelerating the Award of Public Contracts—the Public Procurement Acceleration Act, for short—entered into force. A key change is…

15.07.2026 | In the media

KPMG Law Statement on “tagesschau”: Recycled Building Materials Rarely Used Despite Shortages

Gravel, sand, and crushed stone are becoming scarce and more expensive. Recycled construction materials could help. But despite advanced technology, there are major hurdles, especially…

15.07.2026 | In the media

KPMG Law Statement in *Private Banking* Magazine: How the ECB Plans to Launch the Digital Euro

The banking industry is awaiting the ECB’s decision on which institutions will be selected for the digital euro pilot project. From Germany, Deutsche Bank, Helaba,…

09.07.2026 | In the media

Op-Ed in *Versicherungsmagazin*: D&O Insurance—A Legal Safety Net in Turbulent Times

Liability risks for executives are increasing significantly: New regulatory requirements such as NIS-2, CSRD, and the Supply Chain Act are expanding the responsibilities of managing

02.07.2026 | KPMG Law Insights

Registered mail with return receipt no longer provides proof of delivery—here are some alternatives

Registered mail with return receipt, when used as part of electronic documentation, no longer constitutes prima facie evidence of a…

02.07.2026 | Deal Notifications

KPMG Law advises the Prinzhorn Group on the acquisition of Stora Enso’s German facilities

KPMG Law has advised Mosburger GmbH, a subsidiary of Dunapack Packaging and part of the Austrian Prinzhorn Group, on the acquisition of Stora Enso’s German…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll