Reed NewsReed News
Health1 min

Örebro Region Sent Staff Data to Sri Lanka Without Proper GDPR Agreements

Key Points
  • Region Örebro län transferred healthcare staff personal data to Sri Lanka when implementing the Cosmic medical record system without completed data protection agreements.
  • Experts warn the transfer may violate GDPR regulations as Sri Lanka is not EU-approved for sensitive data handling.
  • Regional officials defended the decision, stating postponement would have created greater risks from manual workarounds.

Region Örebro län transferred personal data of healthcare staff to support services in Sri Lanka when implementing the Cosmic medical record system, despite lacking completed data protection agreements. The incident occurred as the region was among the first to adopt the Cosmic system, which is now used by nine Swedish regions.

According to SVT Örebro's investigation, the data transfer happened before all necessary agreements were finalized, potentially violating GDPR regulations. Sri Lanka is not approved by the EU for handling sensitive personal data transfers.

delaying the system rollout would have involved manual routines and double documentation, which also posed risks

Martin Gunnarsson, acting health and medical care director

Martin Gunnarsson, acting health and medical care director for the region, defended the decision, stating that postponing the system implementation would have involved greater risks from manual routines and duplicate documentation. He emphasized that only names and contact information of healthcare staff were sent to Sri Lanka, not patient medical records.

Experts warn that implementing the system without completed agreements means there was no legal basis for transferring personal data outside the EU. The region has since updated the agreement, but questions remain about why the system was put into use before all data protection measures were in place.

only staff names and contact details were sent, not patient records

Martin Gunnarsson, acting health and medical care director

other agreements govern patient data, which were never sent to a third country

Martin Gunnarsson, acting health and medical care director

work on the agreement started early but was delayed due to many parties involved

Martin Gunnarsson, acting health and medical care director

Transparency

How we verified this article

UnconfirmedBased on 1 sources
1 sources3 Involved