Azienda Sanitaria Locale Roma

€46,000

Insufficient legal basis for data processing

Dato for beslutning

26. mai 2022

Myndighet

Italian Data Protection Authority (Garante)

IT

Sektor

Health Care

Land

IT

Lov og rett

GDPR

Status

FINAL

Beskrivelse

The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc.... In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.

Juridiske henvisninger

Art. 5 (1)Art. 6 (1)Art. 6 (2)Art. 9 (1)Art. 2Art. 2

Problemer og overtredelser

Insufficient legal basis for data processing

Hold deg oppdatert om håndheving av personvern

Vi respekterer personvernet ditt. Én e-post per måned, ingen spam, avmelding når som helst.