Azienda socio sanitaria locale n. 3 di Nuoro
€13,000
Insufficient legal basis for data processing
Decision Date
13 de abril de 2023
Authority
Italian Data Protection Authority (Garante)
IT
Sector
Health Care
Country
IT
Law
GDPRStatus
FINALDescription
The Italian DPA has imposed a fine of EUR 13,000 on Azienda socio sanitaria locale n. 3 di Nuoro. An individual had filed a complaint with the DPA because the health authority had published their personal data (date of birth, residence, health-related data) on the internet in the context of a medication request. In the course of its investigation, the DPA found that the controller had published the data without a valid legal basis and therefore had acted unlawfully.
Legal Citations
Art. 5Art. 6Art. 9Art. 2
Issues & Violations
Insufficient legal basis for data processing