Fino

Italian Data Protection Authority (Garante) · 30 September 2020

Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital)

Insufficient technical and organisational measures to ensure information security

Fine€80,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
30 September 2020
Country
Italy
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2020/IT/019
Export as PDF

What happened

The Italian DPA fined a hospital €80,000 for publishing on its website personal data of participants of an open competition. The DPA held that the hospital was the controller for the data and thus liable for the breach.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security
  • Processor obligations
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/019.