Azienda Socio Sanitaria Territoriale Ovest Milanese
€12,000
Non-compliance with general data processing principles
決定日
2023年7月18日
権威
Italian Data Protection Authority (Garante)
IT
セクター
Health Care
国名
IT
法律
GDPRステータス
FINAL説明
The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of several data subjects. For example, a patient's health records were given to the wrong patient. In addition, the controller had sent an email regarding Covid-19 behavior in multiple scelrose patients to 198 recipients, allowing all recipients to openly view the other email addresses. In addition, the controller sent an invitation for a disability assessment to the wrong person.
法的引用
Art. 5 (1)Art. 9Art. 32
問題と違反
Non-compliance with general data processing principles