Azienda Universitaria Giuliano Isontina

€55,000

Insufficient legal basis for data processing

Päätöspäivä

15. joulukuuta 2022

Viranomainen

Italian Data Protection Authority (Garante)

IT

Ala

Health Care

Maa

IT

Laki

GDPR

Tila

FINAL

Kuvaus

The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal patient data to indicate the risk of having complications in the event of a Covid 19 infection. This was intended to identify appropriate diagnostic and therapeutic pathways in a timely manner in the event of complications. However, the DPA found that the health authority did not have a valid legal basis to process patients' personal data for profiling. In addition, the DPA found that the health authority had failed to conduct a data protection impact assessment. In calculating the fine, the DPA took into account the aggravating factor that a large number of individuals were affected.

Oikeudelliset viittaukset

Art. 5 (1)Art. 9Art. 14Art. 35Art. 2

Asiat ja rikkomukset

Insufficient legal basis for data processing

Pysy ajan tasalla yksityisyyden suojan valvonnasta

Kunnioitamme yksityisyyttäsi. Yksi sähköpostiviesti kuukaudessa, ei roskapostia, peruuta tilaus milloin tahansa.