Italy Italy

Azienda Provinciale per i Servizi Sanitari di Trento

150,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-05-27.

Rank · Sector
#32
of 270 in Health Care
Rank · Italy
#65
of 543
Rank · All fines
#405
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-05-27
Controller / Processor
Azienda Provinciale per i Servizi Sanitari di Trento
Sector
Health Care
Quoted Articles
Art. 5 (1) a), f) GDPR, Art. 9 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA (Garante) has fined Azienda Provinciale per i Servizi Sanitari di Trento EUR 150,000. The controller had accidentally forwarded 293 medical reports of 175 patients to their general practitioners, even though the patients had asked not to forward the reports to their general practitioners. Among the patients in question had been two minors and several women who had undergone abortions. The investigation by Garante found that the data had been accidentally transmitted due to an error in the software that manages patient reports.

Open original source Links to the regulator's original publication or another source.

Related fines