Italian Data Protection Authority (Garante) · 16 January 2025
San Pio Hospital in Benevento
Insufficient legal basis for data processing
Fine€6,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 16 January 2025
- Country
- Italy
- Sector
- Employment
- Regulator’s reference
- Not recorded
- Fino case number
- 2025/IT/081
What happened
The DPA fined a hospital €6,000 for unlawfully disclosing employees' health data by sending it to a shared email account.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 6Lawfulness of processingRead →
- Art. 9Processing of special categories of personal data9(2)(b)Read →
- Special categories
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/IT/081.