Italian Data Protection Authority (Garante) · 3 September 2026
Friuli Centrale University Health Authority
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 3 September 2026
- Country
- Italy
- Sector
- Health Care
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/107
What happened
The Italian DPA has imposed a fine of EUR 24,000 on the Friuli Centrrale University Health Authority. The data subject stated that the controller had accessed her personal data, such as verifying whether she had tested positive for COIVD-19. She also stated that unauthorised personnel had accessed her health records and records from other healthcare facilities, and that there was a lack of documentation of these accesses. Although certain emergency measures were in place during the pandemic, none of them made access to the data subject's health records and personal data lawful, especially because, in this situation, there was no necessity for that access. Furthermore, the controller did not take adequate measures to ensure the security and integrity of the data subject's data. Staff who were not treating the data subject were granted access to their records, and the controller also accessed records from other facilities without the necessary documentation for processing.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 9Processing of special categories of personal dataRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Accountability
- Data security
- Special categories
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/107.