Azienda Sanitaria Locale Roma

€46,000

Insufficient legal basis for data processing

决定日期

2022年5月26日

权力

Italian Data Protection Authority (Garante)

IT

部门

Health Care

国家

IT

法律

GDPR

现状

FINAL

说明

The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most cases, this involved the health records of the data subjects, including medical documents, disability assessments, tests, technical reports, etc.... In this context, the DPA found that the healthcare institution had processed the data unlawfully as well as violated principle of data minimization.

法律引文

Art. 5 (1)Art. 6 (1)Art. 6 (2)Art. 9 (1)Art. 2Art. 2

问题与违规

Insufficient legal basis for data processing

随时了解隐私执法的最新情况

我们尊重您的隐私。每月一封电子邮件,无垃圾邮件,随时退订。