Azienda Sanitaria Locale Roma

€46,000

Insufficient legal basis for data processing

Beslissingsdatum

26 mei 2022

Autoriteit

Italian Data Protection Authority (Garante)

IT

Sector

Health Care

Land

IT

Wet

GDPR

Status

FINAL

Beschrijving

The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc.... In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.

Juridische citaten

Art. 5 (1)Art. 6 (1)Art. 6 (2)Art. 9 (1)Art. 2Art. 2

Problemen en overtredingen

Insufficient legal basis for data processing

Blijf op de hoogte van privacybescherming

We respecteren je privacy. Eén e-mail per maand, geen spam, afmelden kan altijd.