Italian Data Protection Authority (Garante) · 3 July 2026
Giuliano Isontina University Health Authority
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 3 July 2026
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/090
What happened
The Italian DPA has imposed a fine of EUR 10,000 on Giuliano Isontina University Health Authority. The controller notified the relevant authorities of a personal data breach regarding a data subject's health record. The data subject's former spouse and three other healthcare professionals employed by the controller accessed this data without authorisation. The personal data could be accessed due to a loophole that allowed unauthorised personnel to access personal data via an override using a self-declaration form stating the reason for accessing that data.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 9Processing of special categories of personal dataRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Accountability
- Data security
- Special categories
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/090.