Physician

€5,000

Insufficient legal basis for data processing

决定日期

2021年4月15日

权力

Italian Data Protection Authority (Garante)

IT

部门

Health Care

国家

IT

法律

GDPR

现状

FINAL

说明

The Italian DPA (Garante) has imposed a fine of EUR 5,000 on a physician. The controller had shown slides of a clinical case at a congress, which were subsequently published on the website of the Società triveneta di chirurgia. The slides contained personal data of a patient, such as the patient's initials, age, gender, a detailed medical history of the patient, details of admissions from 1980 to 2016 and surgical procedures performed during that period, indicating the date of admission and the date of surgery, the surgical department that performed the procedures, the days spent in hospital, numerous diagnostic images and 22 photographs showing the patient during the surgeries. At no time had the data subject consented to such processing of his or her personal data.

法律引文

Art. 5 (1)Art. 6Art. 9

问题与违规

Insufficient legal basis for data processing

随时了解隐私执法的最新情况

我们尊重您的隐私。每月一封电子邮件,无垃圾邮件,随时退订。