Physician

€2,000

Insufficient legal basis for data processing

تاريخ القرار

29 سبتمبر 2021

الهيئة

Italian Data Protection Authority (Garante)

IT

القطاع

Health Care

البلد

IT

القانون

GDPR

الحالة

FINAL

الوصف

The Italian DPA (Garante) has fined a physician EUR 2,000. A patient had complained to the DPA that the doctor had disclosed his personal data to third parties without authorization. The doctor had recommended medical products to the data subject as part of his treatment. A few days later, the data subject received a call from the marketing consultant behind the recommended products. The data subject pointed out that he had never given his consent to the disclosure of his data. The Garante states that no specific consent is required for the processing of personal data necessary for medical treatment. Here, however, the data was processed for the purpose of product promotion, and therefore explicit consent would have been required under Art. 9 GDPR. The physician thus processed the data unlawfully.

الاستشهادات القانونية

Art. 5 (1)Art. 9

القضايا والانتهاكات

Insufficient legal basis for data processing

ابق على اطلاع على آخر المستجدات بشأن إنفاذ الخصوصية

نحن نحترم خصوصيتك. بريد إلكتروني واحد في الشهر، لا رسائل غير مرغوب فيها، يمكنك إلغاء الاشتراك في أي وقت.