Italy Italy

Azienda Ospedaliero Universitaria Senese

50,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-01-27.

Rank · Sector
#65
of 270 in Health Care
Rank · Italy
#111
of 543
Rank · All fines
#708
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-01-27
Controller / Processor
Azienda Ospedaliero Universitaria Senese
Sector
Health Care
Quoted Articles
Art. 5 (1) f) GDPR, Art. 9 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had been mistakenly sent to an uninvolved third party. The report contained information about a genetic consultation and the health status and sex life of the data subjects. The incident occurred due to an error in packaging the letter, according to a statement from the controller.

Open original source Links to the regulator's original publication or another source.

Related fines