Azienda Ospedale-Università Padova
€5,000
Non-compliance with general data processing principles
決定日期
2023年1月11日
權限
Italian Data Protection Authority (Garante)
IT
部門
Health Care
國家
IT
法律
GDPR狀態
FINAL說明
The Italian DPA has imposed a fine of EUR 5,000 on Azienda Ospedale-Università Padova. The controller had sent an email containing consent forms for participation in a clinical trial to several recipients in an open distribution list. This allowed the recipients to view the email addresses of all other recipients, 19 in total.
法律引文
Art. 5 (1)Art. 9
問題與違規
Non-compliance with general data processing principles