Italy Italy

Medical association

3,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2024-05-09.

Rank · Sector
#212
of 270 in Health Care
Rank · Italy
#431
of 543
Rank · All fines
#2,110
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2024-05-09
Controller / Processor
Medical association
Sector
Health Care
Quoted Articles
Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the COVID-19 vaccination obligation and also informed their employer of this. An email from the association requesting notification of the employer was inadvertently sent to other individuals, as a result of which their email addresses and vaccination status became known.

Open original source Links to the regulator's original publication or another source.

Related fines