Fino

Italian Data Protection Authority (Garante) · 23 January 2020

Azienda Ospedaliero Universitaria Integrata di Verona (Hospital)

Insufficient technical and organisational measures to ensure information security

Fine€30,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
23 January 2020
Country
Italy
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2020/IT/042
Export as PDF

What happened

The Italian DPA imposed a fine of EUR 30.000,00 (and corrective measures) on the Italian hospital, Integrated University Hospital of Verona, which had previously notified the DPA of data breaches in violation of Article 5(1)(f) GDPR. The data controller did not process personal data in a manner that ensured appropriate security of personal data, namely protection against unauthorised or unlawful processing, and the data controller did not use appropriate technical and organizational measures to ensure confidentiality of patients' health data.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/042.