Azienda Ospedaliero Universitaria Senese

€50,000

Non-compliance with general data processing principles

Datum der Entscheidung

27. Januar 2021

Behörde

Italian Data Protection Authority (Garante)

IT

Sektor

Health Care

Land

IT

Recht

GDPR

Status

FINAL

Beschreibung

The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had been mistakenly sent to an uninvolved third party. The report contained information about a genetic consultation and the health status and sex life of the data subjects. The incident occurred due to an error in packaging the letter, according to a statement from the controller.

Juristische Zitate

Art. 5 (1)Art. 9

Probleme und Verstöße

Non-compliance with general data processing principles

Bleiben Sie auf dem Laufenden über die Durchsetzung des Datenschutzes

Wir respektieren Ihre Privatsphäre. Eine E-Mail pro Monat, kein Spam, jederzeit abbestellbar.