Friuli Centrale University Health Authority
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-09-03.
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2026-09-03
- Controller / Processor
- Friuli Centrale University Health Authority
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) a), b), c), f) GDPR, Art. 9 GDPR, Art. 25 GDPR, Art. 32 GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Italian DPA has imposed a fine of EUR 24,000 on the Friuli Centrrale University Health Authority. The data subject stated that the controller had accessed her personal data, such as verifying whether she had tested positive for COIVD-19. She also stated that unauthorised personnel had accessed her health records and records from other healthcare facilities, and that there was a lack of documentation of these accesses. Although certain emergency measures were in place during the pandemic, none of them made access to the data subject's health records and personal data lawful, especially because, in this situation, there was no necessity for that access. Furthermore, the controller did not take adequate measures to ensure the security and integrity of the data subject's data. Staff who were not treating the data subject were granted access to their records, and the controller also accessed records from other facilities without the necessary documentation for processing.