Bulgaria: Medical Center Contracted By Insurance Company Is A Data Controller Under GDPR

Fox Rothschild LLP
Contact

A medical center contracted by an insurance company to provide examinations and studies to individuals covered by insurance may be a “data controller” under the EU General Data Protection Regulation (GDPR) says the Commission for the Protection of Personal Data of Bulgaria.

The CPPD determined that in the case before it, the medical center was a data controller and not a “data processor” because:

  1. The processing of personal data in connection with the carrying out of examinations and research cannot be carried out on behalf of the insurer (data controller) because such services are required, by law, to be carried out by an organization having the status of a “medical establishment” within the meaning of the Bulgarian Law on Medical Establishments.
  2. Special legislation in the field of healthcare provides for a number of obligations, measures, mechanisms, procedures and conditions for the protection of health information containing personal data which can not be delegated to a data processor.*

* summary based on an informal translation

View the original CPPD determination.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide