Azienda Usl Toscana Sud Est.
€20,000
Non-compliance with general data processing principles
Decision Date
June 1, 2023
Authority
Italian Data Protection Authority (Garante)
IT
Sector
Health Care
Country
IT
Law
GDPRStatus
FINALDescription
The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare professional at a computer, on which an emergency protocol with the personal data (including health data) of a data subject was visible. In response to a request from the DPA, the healthcare provider explained that the publication of the data was due to mere inattention and that the poster had only been displayed for a few weeks.
Legal Citations
Art. 5 (1)Art. 9Art. 25 (1)Art. 2
Issues & Violations
Non-compliance with general data processing principles