Italy Italy

Bolzano municipality

30,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-03-23.

Rank · Sector
#84
of 270 in Health Care
Rank · Italy
#168
of 543
Rank · All fines
#909
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-03-23
Controller / Processor
Bolzano municipality
Sector
Health Care
Quoted Articles
Art. 5 (1) f) GDPR, Art. 25 GDPR, Art. 32 GDPR, Art. 33 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the health records of a number of patients, which was caused by a deficiency in the electronic health record service that the municipality had delegated to a processor. During its investigation, the DPA found that although the leak occurred at the processor's site, the municipality should have taken appropriate technical and organizational measures to ensure that such incidents would be avoided.

Open original source Links to the regulator's original publication or another source.

Related fines