Italian Data Protection Authority (Garante) · 31 August 2023
Mednow Medical Center di Giugni Marco
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 31 August 2023
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/IT/032
What happened
The Italian DPA fined a medical centre €10,000 after a complaint was lodged by the data subject. It was found that the PCR test results of the data subject contained incorrect personal data, breaching Article 5(1)(a) GDPR and Article 5(1)(d) GDPR. Furthermore, since the result was first mistakenly sent to the e-mail address of an unauthorised third party, the controller also breached Article 9 GDPR, as well as Article 5(1)(f) GDPR and Article 32 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 9Processing of special categories of personal dataRead →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 15Right of access by the data subjectRead →
- Art. 16Right to rectificationRead →
- Art. 17Right to erasure (‘right to be forgotten’)Read →
- Art. 18Right to restriction of processingRead →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Data subject rights
- Special categories
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/IT/032.