Italy Italy

Monaldi-Cotugno-CTO

15,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-05-14.

Rank · Sector
#124
of 281 in Health Care
Rank · Italy
#251
of 573
Rank · All fines
#1,252
of 3,106

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2026-05-14
Controller / Processor
Monaldi-Cotugno-CTO
Sector
Health Care
Quoted Articles
Art. 5 (1) a), b), c), e), f), (2) GDPR, Art. 9 GDPR, Art. 13 GDPR, Art. 25 GDPR, Art. 32 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 15,000 on Monaldi-Cotugno-CTO. The controller operates a hospital using central software to manage personal and health data. Access to this data is mainly managed through roles; for example, doctors and nurses can only access patient documents if the patients are or were under their care. The controller did not implement adequate measures to inform data subjects about processing in a transparent manner. The controller did not obtain data subjects' consent for processing their data into health records. The controller's employees could access health records of patients not being treated by them. Furthermore accesses and operations regarding data subjects' medical records were not adequately traceable.

Open original source Links to the regulator's original publication or another source.

Related fines