Fino

Italian Data Protection Authority (Garante) · 3 September 2026

Friuli Centrale University Health Authority

Insufficient technical and organisational measures to ensure information security

Fine€24,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
3 September 2026
Country
Italy
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2026/IT/107
Export as PDF

What happened

The Italian DPA has imposed a fine of EUR 24,000 on the Friuli Centrrale University Health Authority. The data subject stated that the controller had accessed her personal data, such as verifying whether she had tested positive for COIVD-19. She also stated that unauthorised personnel had accessed her health records and records from other healthcare facilities, and that there was a lack of documentation of these accesses. Although certain emergency measures were in place during the pandemic, none of them made access to the data subject's health records and personal data lawful, especially because, in this situation, there was no necessity for that access. Furthermore, the controller did not take adequate measures to ensure the security and integrity of the data subject's data. Staff who were not treating the data subject were granted access to their records, and the controller also accessed records from other facilities without the necessary documentation for processing.

Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Data security
  • Special categories

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/107.