Italy Italy

Friuli Centrale University Health Authority

24,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-09-03.

Rank · Sector
#96
of 283 in Health Care
Rank · Italy
#193
of 595
Rank · All fines
#1,028
of 3,127

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2026-09-03
Controller / Processor
Friuli Centrale University Health Authority
Sector
Health Care
Quoted Articles
Art. 5 (1) a), b), c), f) GDPR, Art. 9 GDPR, Art. 25 GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA has imposed a fine of EUR 24,000 on the Friuli Centrrale University Health Authority. The data subject stated that the controller had accessed her personal data, such as verifying whether she had tested positive for COIVD-19. She also stated that unauthorised personnel had accessed her health records and records from other healthcare facilities, and that there was a lack of documentation of these accesses. Although certain emergency measures were in place during the pandemic, none of them made access to the data subject's health records and personal data lawful, especially because, in this situation, there was no necessity for that access. Furthermore, the controller did not take adequate measures to ensure the security and integrity of the data subject's data. Staff who were not treating the data subject were granted access to their records, and the controller also accessed records from other facilities without the necessary documentation for processing.

Open original source Links to the regulator's original publication or another source.

Related fines