Azienda Sanitaria Locale Roma
46,000 €
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-05-26.
Rank · Sector
#73
of 270 in Health Care
Rank · Italy
#125
of 543
Rank · All fines
#760
of 3,050
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2022-05-26
- Controller / Processor
- Azienda Sanitaria Locale Roma
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) c) GDPR, Art. 6 (1) c), d) GDPR, Art. 6 (2), (3) GDPR, Art. 9 (1), (2), (4) GDPR, Art. 2-ter (1), (2) Codice della privacy, Art. 2-septies (8) Codice della privacy
- Type of violation
- Insufficient legal basis for data processing
Summary
The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000.
The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc....
In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.
Open original source
Links to the regulator's original publication or another source.
Related fines
Italy
2024-02-08
79,100,000 €
ETid-2306
Enel Energia SpA
Transportation and Energy
Italy
2026-03-26
31,800,000 €
ETid-3162
Intesa Sanpaolo S.p.A.
Finance, Insurance and Consulting
Italy
2020-01-15
27,800,000 €
ETid-189
TIM (telecommunications operator)
Media, Telecoms and Broadcasting
Italy
2022-02-10
20,000,000 €
ETid-1098
Clearview Al Inc.
Industry and Commerce
Italy
2020-07-13
16,700,000 €
ETid-336
Wind Tre S.p.A.
Media, Telecoms and Broadcasting
Italy
2024-11-02
15,000,000 €
ETid-2497
OpenAI OpCo LLC
Media, Telecoms and Broadcasting