Italy Italy

Azienda Sanitaria Locale Frosinone

7,500 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-01-13.

Rank · Sector
#154
of 269 in Health Care
Rank · Italy
#319
of 543
Rank · All fines
#1,531
of 3,039

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-01-13
Controller / Processor
Azienda Sanitaria Locale Frosinone
Sector
Health Care
Quoted Articles
Art. 5 (1) a) GDPR, Art. 12 GDPR, Art. 13 GDPR
Type of violation
Insufficient fulfilment of information obligations

Summary

The Italian DPA has fined Azienda Sanitaria Locale Frosinone EUR 7,500. In the course of its investigation against the medical facility, the Garante found that their privacy policy showed significant deficiencies. For example, the facility had indicated several purposes for processing the data, but the relevant legal bases for doing so were not always indicated. Those legal bases that were stated were often incorrect or contradictory. In addition, the facility did not provide sufficient information on the storage periods of the collected data.

Open original source Links to the regulator's original publication or another source.

Related fines