Medical association

€3,000

Insufficient legal basis for data processing

Datum rozhodnutí

9. května 2024

Úřad

Italian Data Protection Authority (Garante)

IT

Sektor

Health Care

Země

IT

Právo

GDPR

Stav

FINAL

Popis

The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the COVID-19 vaccination obligation and also informed their employer of this. An email from the association requesting notification of the employer was inadvertently sent to other individuals, as a result of which their email addresses and vaccination status became known.

Právní citace

Art. 5 (1)Art. 6Art. 2

Problémy a porušení

Insufficient legal basis for data processing

Aktualizujte informace o prosazování ochrany osobních údajů

Respektujeme vaše soukromí. Jeden e-mail měsíčně, žádný spam, kdykoli se můžete odhlásit.