Azienda Ospedaliero Universitaria Senese
- Country
- Italy
- Fine
- 10,000 EUR
- Date
- 2021-01-27
- Sector
- Hospital
- Articles
- Art. 5, par. 1, lett. f) andart. 9 of GDPR
This fine concerns breaches due to: (i) failure to comply with the integrity and confidentiality principle; (ii) processing of special categories of personal data without adequate legal basis.
The Hospital breached the GDPR by sending a medical report referring to two data subjects to a third party, due to a material error made by an employee during the enveloping process. The medical report, which was received by email at the third party's residence, contained special categories of personal data of the two data subjects, such as data relating to their health and sex life and information on the health of their family members. For this reason, the hospital did not ensure a sufficient level of integrity and confidentiality and disclosed special categories of data to third parties without an adequate legal basis.
