Italian Data Protection Authority (Garante) · 17 December 2020
Azienda Unità Sanitaria Locale Toscana Sud Est
Non-compliance with general data processing principles
Fine€100,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 17 December 2020
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/IT/005
What happened
The Italian DPA (Garante) imposed a fine of € 100,000 on a local public health body amid the violation of several GDPR provisions. The data processing involved the sharing of patients’ data across several health care stakeholders.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 14Information to be provided where personal data have not been obtained from the data subjectRead →
- Art. 28ProcessorRead →
- Art. 30Records of processing activitiesRead →
- Art. 32Security of processingRead →
- Art. 35Data protection impact assessmentRead →
- DPIA
- Data principles
- Data security
- Processor obligations
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/005.