Azienda Sanitaria Locale Roma
€46,000
Insufficient legal basis for data processing
Ngày ra quyết định
26 tháng 5, 2022
Thẩm quyền
Italian Data Protection Authority (Garante)
IT
Ngành
Health Care
Quốc gia
IT
Luật
GDPRTrạng thái
FINALMô tả
The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc.... In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.
Trích dẫn pháp lý
Art. 5 (1)Art. 6 (1)Art. 6 (2)Art. 9 (1)Art. 2Art. 2
Vấn đề & Vi phạm
Insufficient legal basis for data processing