GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Italian Data Protection Authority

Country
Italy
Fine
30,000 EUR
Date
2020-01-23
Sector
Azienda Ospedaliero Universitaria Integrata di Verona (hospital)
Articles
Art. 5 par. 1 lett. f) and 9 of GDPR

This fine concerns insufficient technical and organisational measures to ensure information security

In may 2019, the Hospital notified to the Italian DPA a data breach, due to the illegal conduct of some employees who, in absence of the necessary authorization, had had access to the health records of their colleagues who were also patients of the Hospital.The investigations carried out by the Italian DPA showed that the technical and organizational measures adopted by the Hospital to patients’ dossiers were not suitable to ensure adequate protection of patients' personal data and to protect them from unauthorized access, thus leading to an unlawful data processing.<br />According to the Italian DPA, the violations could have been avoided if the data controller had applied the Guidelines on Health Data published by the Authority in 2015, in which it was established that access to patients’ health data should be allowed only to the personnel directly involved in the patient care process, through personal authorization profile. <br /><br />