Italian Data Protection Authority (Garante) · 30 September 2020
Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital)
Insufficient technical and organisational measures to ensure information security
Fine€80,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 30 September 2020
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/IT/019
What happened
The Italian DPA fined a hospital €80,000 for publishing on its website personal data of participants of an open competition. The DPA held that the hospital was the controller for the data and thus liable for the breach.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a)Read →
- Art. 6Lawfulness of processingRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 28ProcessorRead →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Processor obligations
- Transparency
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/019.