Azienda Ospedaliero Universitaria di Parma

€10,000

Non-compliance with general data processing principles

Sprendimo priėmimo data

2021 m. sausio 27 d.

Institucija

Italian Data Protection Authority (Garante)

IT

Sektorius

Health Care

Šalis

IT

Teisė

GDPR

Statusas

FINAL

Aprašymas

The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which patient data was mistakenly disclosed to third parties. In the first incident, parents found the report of a microbiological examination of another patient in the file of their minor child. The report revealed the data subject´s name, tax number, address, birth date and various health data. In the second incident, the heir of a patient received the health report of another patient, which contained the name and birth date as well as data on the health status of the data subject.

Teisinės citatos

Art. 5 (1)Art. 9

Problemos ir pažeidimai

Non-compliance with general data processing principles

Gaukite naujausią informaciją apie privatumo vykdymo užtikrinimą

Gerbiame jūsų privatumą. Vienas el. laiškas per mėnesį, jokių šlamšto, atsisakykite prenumeratos bet kada.