Italy Italy

Azienda sanitaria provinciale di Caltanissetta

6,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-03-10.

Rank · Sector
#173
of 270 in Health Care
Rank · Italy
#329
of 543
Rank · All fines
#1,623
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-03-10
Controller / Processor
Azienda sanitaria provinciale di Caltanissetta
Sector
Health Care
Quoted Articles
Art. 5 GDPR, Art. 6 GDPR, Art. 12 GDPR, Art. 15 GDPR, Art. 37 GDPR, Art. 2-ter Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any communication regarding this matter only to their personal email inbox. Nevertheless, the controller had sent communications to the data subject's business email address.

In addition, the data subject had requested access to their data. However, the controller did not properly comply with this request.

In the course of its investigation, the DPA also found that the health care facility had failed to notify the DPA of the name and contact details of a new data protection officer and to update them on its website.

Open original source Links to the regulator's original publication or another source.

Related fines