Fino

Italian Data Protection Authority (Garante) · 18 June 2026

Docplanner Italy S.r.l.

Insufficient technical and organisational measures to ensure information security

Fine€10,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
18 June 2026
Country
Italy
Sector
Media, Telecoms and Broadcasting
Regulator’s reference
Not recorded
Fino case number
2026/IT/092
Export as PDF

What happened

The Italian DPA has imposed a fine of EUR 10,000 on Docplanner Italy S.r.l. Docplanner Italy manages software used by hospitals for management purposes. As a data processor it notified the data controllers about ransomware attacks on its systems. In the subsequent investigation investigators found that attackers had accessed one hard drive containing the personal data of 26 data subjects but had not exfiltrated any data. Neither the hospitals, the data subjects nor the data processor received any ransom demands. Investigators found that the processor's authentication process was inadequate, particularly given the processing of health data.

Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/092.