Italy Italy

Azienda Usl Toscana Sud Est.

20,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-06-01.

Rank · Sector
#98
of 269 in Health Care
Rank · Italy
#200
of 543
Rank · All fines
#1,072
of 3,039

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-06-01
Controller / Processor
Azienda Usl Toscana Sud Est.
Sector
Health Care
Quoted Articles
Art. 5 (1) a), c), f) GDPR, Art. 9 GDPR, Art. 25 (1), (2) GDPR, Art. 2-septies (8) Codice della privacy
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare professional at a computer, on which an emergency protocol with the personal data (including health data) of a data subject was visible. In response to a request from the DPA, the healthcare provider explained that the publication of the data was due to mere inattention and that the poster had only been displayed for a few weeks.

Open original source Links to the regulator's original publication or another source.

Related fines