Italy Italy

Azienda Sanitaria Locale Roma

46,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-05-26.

Rank · Sector
#73
of 270 in Health Care
Rank · Italy
#125
of 543
Rank · All fines
#760
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-05-26
Controller / Processor
Azienda Sanitaria Locale Roma
Sector
Health Care
Quoted Articles
Art. 5 (1) c) GDPR, Art. 6 (1) c), d) GDPR, Art. 6 (2), (3) GDPR, Art. 9 (1), (2), (4) GDPR, Art. 2-ter (1), (2) Codice della privacy, Art. 2-septies (8) Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000.
The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc....

In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.

Open original source Links to the regulator's original publication or another source.

Related fines