Italian Data Protection Authority (Garante) · 8 February 2024
Medtronic Italia
Non-compliance with general data processing principles
Fine€300,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 8 February 2024
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2024/IT/050
What happened
The DPA imposed a €300,000 fine against a medical technology firm for its use of the 'To' field instead of the 'Bcc' field when sending emails to the users of its app, leading to unauthorized processing of health data.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 9Processing of special categories of personal dataRead →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 32Security of processingRead →
- Data principles
- Data security
- Special categories
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/IT/050.