Monaldi-Cotugno-CTO
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-05-14.
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2026-05-14
- Controller / Processor
- Monaldi-Cotugno-CTO
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) a), b), c), e), f), (2) GDPR, Art. 9 GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 32 GDPR
- Type of violation
- Non-compliance with general data processing principles
Summary
The Italian DPA has imposed a fine of EUR 15,000 on Monaldi-Cotugno-CTO. The controller operates a hospital using central software to manage personal and health data. Access to this data is mainly managed through roles; for example, doctors and nurses can only access patient documents if the patients are or were under their care. The controller did not implement adequate measures to inform data subjects about processing in a transparent manner. The controller did not obtain data subjects' consent for processing their data into health records. The controller's employees could access health records of patients not being treated by them. Furthermore accesses and operations regarding data subjects' medical records were not adequately traceable.