The French Data Protection Authority had identified multiple GDPR infringements.
Dedalus Biologie experienced a data leak. The compromised data encompassed information such as names, social security number, name of treating physician, medical tests, and health conditions of data subjects.
In addition, Dedalus had violated Article 29 GDPR by extracting an excessive amount of data during the processing on behalf of two laboratories.
Furthermore, the Data Protection Authority found that DEDALUS had failed to implement appropriate technical and organizational measures to ensure the protection of personal data, constituting a breach of Article 32 of the GDPR. The absence of such appropriate security measures was identified as one of the main causes for the data breach.
Finally, the Data Protection Authority found that the agreements between DEDALUS and its customers did not comply with Article 28 GDPR.