Medical association
3,000 €
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2024-05-09.
Rank · Sector
#212
of 270 in Health Care
Rank · Italy
#431
of 543
Rank · All fines
#2,110
of 3,050
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2024-05-09
- Controller / Processor
- Medical association
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 2-ter Codice della privacy
- Type of violation
- Insufficient legal basis for data processing
Summary
The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the COVID-19 vaccination obligation and also informed their employer of this. An email from the association requesting notification of the employer was inadvertently sent to other individuals, as a result of which their email addresses and vaccination status became known.
Open original source
Links to the regulator's original publication or another source.
Related fines
Italy
2024-02-08
79,100,000 €
ETid-2306
Enel Energia SpA
Transportation and Energy
Italy
2026-03-26
31,800,000 €
ETid-3162
Intesa Sanpaolo S.p.A.
Finance, Insurance and Consulting
Italy
2020-01-15
27,800,000 €
ETid-189
TIM (telecommunications operator)
Media, Telecoms and Broadcasting
Italy
2022-02-10
20,000,000 €
ETid-1098
Clearview Al Inc.
Industry and Commerce
Italy
2020-07-13
16,700,000 €
ETid-336
Wind Tre S.p.A.
Media, Telecoms and Broadcasting
Italy
2024-11-02
15,000,000 €
ETid-2497
OpenAI OpCo LLC
Media, Telecoms and Broadcasting