Docplanner Italy S.r.l.
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-06-18.
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2026-06-18
- Controller / Processor
- Docplanner Italy S.r.l.
- Sector
- Media, Telecoms and Broadcasting
- Quoted Articles
- Art. 5 (1) f) GDPR, Art. 32 GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Italian DPA has imposed a fine of EUR 10,000 on Docplanner Italy S.r.l. Docplanner Italy manages software used by hospitals for management purposes. As a data processor it notified the data controllers about ransomware attacks on its systems. In the subsequent investigation investigators found that attackers had accessed one hard drive containing the personal data of 26 data subjects but had not exfiltrated any data. Neither the hospitals, the data subjects nor the data processor received any ransom demands. Investigators found that the processor's authentication process was inadequate, particularly given the processing of health data.