Italy Italy

Azienda Socio Sanitaria Territoriale Ovest Milanese

12,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-07-18.

Rank · Sector
#124
of 270 in Health Care
Rank · Italy
#247
of 543
Rank · All fines
#1,274
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-07-18
Controller / Processor
Azienda Socio Sanitaria Territoriale Ovest Milanese
Sector
Health Care
Quoted Articles
Art. 5 (1) f) GDPR, Art. 9 GDPR, Art. 32 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of several data subjects. For example, a patient's health records were given to the wrong patient. In addition, the controller had sent an email regarding Covid-19 behavior in multiple scelrose patients to 198 recipients, allowing all recipients to openly view the other email addresses. In addition, the controller sent an invitation for a disability assessment to the wrong person.

Open original source Links to the regulator's original publication or another source.

Related fines