Italy Italy

Casa di Cura Città di Roma

12,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2025-09-11.

Rank · Sector
#126
of 270 in Health Care
Rank · Italy
#248
of 543
Rank · All fines
#1,281
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2025-09-11
Controller / Processor
Casa di Cura Città di Roma
Sector
Health Care
Quoted Articles
Art. 5 (1) a), b), c), e), f), (2) GDPR, Art. 9 GDPR, Art. 25 GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of patient data.

Open original source Links to the regulator's original publication or another source.

Related fines