Azienda socio sanitaria territoriale di Lodi CF
€40,000
Non-compliance with general data processing principles
Decision Date
October 12, 2023
Authority
Italian Data Protection Authority (Garante)
IT
Sector
Health Care
Country
IT
Law
GDPRStatus
FINALDescription
The Italian DPA has imposed a fine of ERU 40,000 on the health authority Azienda socio sanitaria territoriale di Lodi CF. Employees of the health authority had accessed the file of another employee, who was also a patient, without a medical reason or any other legal basis.
Legal Citations
Art. 5 (1)Art. 9Art. 32
Issues & Violations
Non-compliance with general data processing principles