Azienda Sanitaria Locale Roma

€46,000

Insufficient legal basis for data processing

Ημερομηνία απόφασης

26 Μαΐου 2022

Αρχή

Italian Data Protection Authority (Garante)

IT

Τομέας

Health Care

Χώρα

IT

Νόμος

GDPR

Κατάσταση

FINAL

Περιγραφή

The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc.... In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.

Νομικές παραπομπές

Art. 5 (1)Art. 6 (1)Art. 6 (2)Art. 9 (1)Art. 2Art. 2

Θέματα & Παραβάσεις

Insufficient legal basis for data processing

Μείνετε ενημερωμένοι για την επιβολή του απορρήτου

Σεβόμαστε την ιδιωτικότητά σας. Ένα email ανά μήνα, χωρίς spam, διαγραφή ανά πάσα στιγμή.