Azienda Ospedaliero Universitaria di Parma

€10,000

Non-compliance with general data processing principles

决定日期

2021年1月27日

权力

Italian Data Protection Authority (Garante)

IT

部门

Health Care

国家

IT

法律

GDPR

现状

FINAL

说明

The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria di Parma EUR 50,000. The controller, a hospital, had reported two data breaches to the Italian DPA in which patient data was mistakenly disclosed to third parties. In the first incident, parents found the report of a microbiological examination of another patient in the file of their minor child. The report revealed the data subject´s name, tax number, address, birth date and various health data. In the second incident, the heir of a patient received the health report of another patient, which contained the name and birth date as well as data on the health status of the data subject.

法律引文

Art. 5 (1)Art. 9

问题与违规

Non-compliance with general data processing principles

随时了解隐私执法的最新情况

我们尊重您的隐私。每月一封电子邮件,无垃圾邮件,随时退订。