Italian Data Protection Authority (Garante) · 18 June 2026
Docplanner Italy S.r.l.
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 18 June 2026
- Country
- Italy
- Sector
- Media, Telecoms and Broadcasting
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/092
What happened
The Italian DPA has imposed a fine of EUR 10,000 on Docplanner Italy S.r.l. Docplanner Italy manages software used by hospitals for management purposes. As a data processor it notified the data controllers about ransomware attacks on its systems. In the subsequent investigation investigators found that attackers had accessed one hard drive containing the personal data of 26 data subjects but had not exfiltrated any data. Neither the hospitals, the data subjects nor the data processor received any ransom demands. Investigators found that the processor's authentication process was inadequate, particularly given the processing of health data.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/092.