Medical association

€3,000

Insufficient legal basis for data processing

Tanggal Keputusan

9 Mei 2024

Wewenang

Italian Data Protection Authority (Garante)

IT

Sektor

Health Care

Negara

IT

Hukum

GDPR

Status

FINAL

Deskripsi

The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the COVID-19 vaccination obligation and also informed their employer of this. An email from the association requesting notification of the employer was inadvertently sent to other individuals, as a result of which their email addresses and vaccination status became known.

Kutipan Hukum

Art. 5 (1)Art. 6Art. 2

Masalah & Pelanggaran

Insufficient legal basis for data processing

Tetap Terupdate tentang Penegakan Privasi

Kami menghormati privasi Anda. Satu email per bulan, tidak ada spam, berhenti berlangganan kapan saja.