Italy Italy

Azienda Universitaria Friuli Occidentale

55,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-12-15.

Rank · Sector
#59
of 270 in Health Care
Rank · Italy
#106
of 543
Rank · All fines
#675
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-12-15
Controller / Processor
Azienda Universitaria Friuli Occidentale
Sector
Health Care
Quoted Articles
Art. 5 (1) a) GDPR, Art. 9 GDPR, Art. 14 GDPR, Art. 35 GDPR, Art. 2-sexies Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal patient data to indicate the risk of having complications in the event of a Covid 19 infection. This was intended to identify appropriate diagnostic and therapeutic pathways in a timely manner in the event of complications. However, the DPA found that the health authority did not have a valid legal basis to process patients' personal data for profiling. In addition, the DPA found that the health authority had failed to conduct a data protection impact assessment. In calculating the fine, the DPA took into account the aggravating factor that a large number of individuals were affected.

Open original source Links to the regulator's original publication or another source.

Related fines