Medical association
€3,000
Insufficient legal basis for data processing
วันที่ตัดสินใจ
9 พฤษภาคม 2567
อำนาจ
Italian Data Protection Authority (Garante)
IT
ภาคส่วน
Health Care
ประเทศ
IT
กฎหมาย
GDPRสถานะ
FINALคำอธิบาย
The Italian DPA has imposed a fine of EUR 3,000 on a medical association. A doctor had filed a complaint because the professional association suspended them for not fulfilling the COVID-19 vaccination obligation and also informed their employer of this. An email from the association requesting notification of the employer was inadvertently sent to other individuals, as a result of which their email addresses and vaccination status became known.
การอ้างอิงทางกฎหมาย
Art. 5 (1)Art. 6Art. 2
ปัญหาและการละเมิด
Insufficient legal basis for data processing