Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) ·551/2026 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based selection process

The data was also indexed on Google.

How it connects

Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 Guidelines ·EDPB May 25, 2018 Privacy Shield Lawful Basis Data Portability
2026 If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Dariusz Kloza, Laura Drechsler, Elora Fernandes, Arian Birth et al. — Computer law & security review Computer law & security review ·full text Jan 23, 2026 Right to Explanation AI Enforcement Actions Privacy by Default
Study on the secondary use of personal data in the context of scientific research 2 This study has been prepared by Milieu under Contract No EDPS/2019/02 - 04 for the benefit of the EDPB. The study has been carried out by researchers from KU Leuven (CiTiP) and… EDPB Apr 3, 2025 Scientific Research Genetic Data Statistics
Recommendations 1/2025 2027 WADA World Anti-Doping Code Recommendations ·EDPB Feb 13, 2025 Privacy Shield Social Media Accountability
2025 Generative AI and data protection Hannah Ruschemeier — Cambridge Forum on AI Law and Governance Cambridge Forum on AI Law and Governance ·full text Jan 1, 2025 Training Data Requirements Data Governance for AI Social Media
EDPB Annual Report 2023 EDPB Annual Report 2023 1 2023 ANNUAL REPORT SAFEGUARDING INDIVIDUALS' DIGITAL RIGHTS 2 FOREWORD 4 HIGHLIGHTS 2023 6 1. THE EDPB SECRETARIAT 8 1.1. MISSION AND ACTIVITIES IN 2023… Apr 23, 2024 Social Media Mutual Assistance Between Member States for AI Oversight AI Enforcement Actions

Full text

[Web Doc. No. 10287326] Decision of July 23, 2026 Register of Decisions No. 551 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at the performance of the tasks and the exercise of the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Prof. Ginevra Cerrina Feroni; WHEREAS 1. Introduction. In a complaint filed with this Authority, a representative stated that the Bologna University Hospital IRCCS (hereinafter “the Hospital”) had published on its institutional website the complainant’s personal data “relating to a selection process based on income conducted through the employment center, the result of which—a determination of ineligibility—was published on the website and indexed on Google.” Based on the information provided by the complainant and following the investigations conducted by the Office, it was confirmed that a PDF file titled “LIST OF ELIGIBLE/INELIGIBLE CANDIDATES FROM THE PRE-SELECTION LIST SUBMITTED VIA NOTE NO. XX OF XX FOR THE POSITION OF XX,” containing the names of the participants in the selection process (eligible and ineligible). 2. The Preliminary Investigation. As part of the preliminary investigation, the Hospital Authority, in a note dated XX, stated, in particular, that: - “The selection procedure in question is aimed at hiring personnel from employment centers into the public sector. As provided for in Article 35, paragraph 1, subparagraph b) of Legislative Decree No. 165/2001, in fact, the initiation of a selection process pursuant to Art. 16 of Law No. 56 of February 28, 1987, constitutes a ‘recruitment procedure’ used in the public sector for the permanent or fixed-term hiring of workers to be classified infor which an educational qualification no higher than that of compulsory education is required, based on selections made from among those registered on the employment placement and mobility lists, who possess any required professional skills and meet the requirements for access to public service”; - “By memorandum ref. no. XX dated XX (and subsequent amendments), the Administrative Directorate of this Company requested that the Unified Metropolitan Service for Personnel Administration and Management (SUMAGP) initiate the hiring procedure. SUMAGP forwarded the request to the Bologna Employment Center (CpI) in order to proceed with the permanent hiring of 22 staff members”; - “The Bologna Employment Center, by executive decision No. XX of XX, effective as of XX, approved the ranking list containing 1,329 names to be considered for selection”; - “The selection process was designed exclusively to assess the candidate’s suitability to perform the relevant duties and did not involve any comparative evaluation. Therefore, for each candidate selected in order of ranking by the Employment Center, the committee issued a determination of suitability or unsuitability”; - “As can be inferred from the detailed description of the procedure and the relevant legislation cited, the initiation of the selection process, pursuant to Art. 16 of Law No. 56 of February 28, 1987, No. 56—although not competitive in nature, as it does not include any assessment of the applicants’ qualifications or professional competence—constitutes a recruitment procedure for public service positions, at the conclusion of which the candidate deemed suitable is to be hired on a fixed-term or permanent basis in the public sector”; - “The Company has published the final ranking list in the dedicated ‘Competition Announcements’ section of ‘Transparent Administration’ on its institutional website, in accordance with the specific technical rules and the provisions of the law and ANAC.” - “With regard to publication timelines, it is specified that, pursuant to Art. 8, paragraph 3, of Legislative Decree No. 33/2013 “data, information, and documents subject to mandatory publication under current legislation are published for a period of 5 years, beginning on January 1 of the year following the one in which the publication obligation takes effect”; - “Failure to publish or incorrect publication of the key elements of the described procedure would result in this administration’s failure to properly publicize—or incorrect publicization of—a selection procedure aimed at identifying and hiring candidates on a permanent or fixed-term basis. Legislative Decree No. 33 of 2013 states that the final ranking list is subject to the publication requirement. Therefore, to ensure proper compliance with the regulatory provisions, the entire ranking list set forth in Annex A of Executive Decision No. XX of XX has been published”; - “In any case, having considered the observations of this esteemed Authority, the publication of the ranking list in question has been revised by removing the personal data of ineligible candidates. Furthermore, through the company’s privacy services—with the necessary support of the DPO and the RPCT— an administrative review of the procedures by which this entity fulfills its publication obligations, also with the aim of promoting future training and informational improvement initiatives for the offices involved in these activities.” In a letter dated the XX, the Authority, based on the evidence gathered, the verifications carried out, and the facts that emerged following the preliminary investigation, notified the Hospital District, pursuant to Article 166, paragraph 5, of the Code, the initiation of proceedings for the adoption of the measures referred to in Art. 58, para. 2, of the Regulation, for having published on its institutional website, in the “Transparent Administration” Section, a PDF file containing the “list of eligible/ineligible candidates from the shortlist transmitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of “administrative assistant, category B,” containing the names of the participants in the procedure (eligible and ineligible), in violation of Articles 5, 6, and 9 of the Regulations, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. In the same letter, the aforementioned official was invited to submit written defenses or documents to the Authority or to request a hearing before the Authority (Art. 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). In a letter dated XX, the hospital submitted a defense brief, stating, in particular, that: - “the requirements and conditions for participation allowed even individuals without a disability or any adverse financial situation to participate in the selection process. In this regard, for example, the selection process was also open to individuals currently employed under any type of employment contract”; - “as for the publication of the selection results on the hospital’s website, the operational units involved evidently assessed whether the provisions of Art. 19 of Legislative Decree No. 33 of 2013 were applicable to the case at hand. In fact, by establishing the ‘Reorganization of the regulations concerning the right of access and the obligations of public administrations regarding publicity, transparency, and the dissemination of information,’ this provision governs the impartiality and transparency of public administrations, requiring public administrations to publish notices of competitive examinations for the recruitment, for any purpose, of personnel within the public administration, the evaluation criteria of the selection committee, the examination questions, and the final rankings—updated to reflect any subsequent promotion of eligible candidates who were not initially selected”; - “Nevertheless, in light of the concern raised by this esteemed Authority—namely, that participation in the described selection process could associate the data subjects with a generic disability status and thus unequivocally reveal special category data as well— the undersigned Data Controller, in order to ensure the fullest possible cooperation, removed the publication of the entire ranking list (containing the personal data of the candidates deemed eligible in the selection process) from the “Transparent Administration” website on XX”; - The number of data subjects (and their respective data) affected by the violation is 95. To describe their composition, reference is made to the Decisions of the Head of the Sumagp Unified Metropolitan Personnel Administration and Management Service: Decision No. XX of XX, by which the data of 19 eligible and 69 ineligible candidates were published on XX […] Decision No. XX of XX, by which the data of 3 eligible and 4 ineligible candidates were published on XX; - “The data of ineligible candidates were removed on XX. The data of eligible candidates were removed as a precautionary measure and, in any case, in a spirit of cooperation with the relevant Authority, on XX”; - “In accordance with the principle of accountability, the undersigned, starting with the planning of the XX budget allocated to the DPO’s Operational Unit (approved in May XX), has set the objective of ‘adopting guidelines for the quantitative and qualitative review of information published on the Company’s Institutional Websites regarding data protection,’ an activity still underway to evaluate processing operations carried out for the purpose of transparency”; - “Frequent training courses are offered to employees, including both basic training (an average of at least two per year over the last three years) and specialized courses focused on specific data processing operations or categories thereof. All staff are authorized for data processing and have been provided with appropriate instructions.” During the hearing—requested pursuant to Article 166, paragraph 6, of the Code and held on XX—the Hospital Authority stated, in particular, that: - “With regard to the nature of the data being processed, it should be noted that such data fall exclusively within the category of general data and do not fall under the special categories of data referred to in Art. 9 of Regulation (EU) 2016/679; inclusion on the mobility and placement list does not, in fact, in and of itself indicate any specific characteristics of the data subject participating in the procedure and included on said list”; - “Following the incident, the data controller has implemented numerous measures to prevent similar data breaches from occurring […] confirming the great care and sensitivity that the Hospital has always demonstrated regarding the processing of personal data”; - “Due to certain financial constraints, the staff responsible for handling these procedures is particularly limited (5 employees)”; - “Specifically, attention is drawn to the complexity of these hiring procedures within the context of a healthcare organization, which processes a wide variety of personal data in these areas; - “We also draw the legislature’s attention to transparency in personnel management, with particular reference to recruitment procedures, areas at high risk of corruption, as a measure to prevent corruption in this context, in accordance with Art. 19 of Legislative Decree 33/2013.” 3. Outcome of the Preliminary Investigation. Applicable Legislation. Data protection regulations provide that public entities, even when conducting competitive, selection, or other evaluative procedures prior to the establishment of an employment relationship, may process the personal data of data subjects (Art. 4(1) of the Regulation) if the processing is necessary “to comply with a legal obligation to which the controller is subject” (such as specific obligations under national law “for recruitment purposes,” Articles 6(1)(c), 9(2)(b), and 9(4); 88 of the Regulation) or “for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller” (Art. 6(1)(c) and (e) of the Regulation and Art. 2-ter of the Code). Such processing must, however, be based on Union or Member State law, which must pursue a public interest objective and be proportionate to the pursuit of that objective. The processing purpose must be necessary for the performance of a task carried out in the public interest or related to the exercise of official authority vested in the controller (see Article 6(3) of the Regulation and Article 2-ter of the Code). With regard to special categories of personal data, including data concerning health (for which there is a general prohibition on processing, except in the cases specified in Article 9(2) of the Regulation, and, in any event, a regime providing greater safeguards than for other types of data (see Article 9(4) as well as Article 2-septies, paragraph 8, of the Code), processing is permitted where it is “necessary for reasons of substantial public interest on the basis of Union or Member State law, which must be proportionate to the purpose pursued, respect the essence of the right to data protection, and provide for appropriate and specific measures to safeguard the data subject rights and interests” (Article 9, para 2, subparagraph (g), of the Regulation). The controller is required to comply with data protection principles, including those of “lawfulness, fairness, and transparency” as well as “data minimisation,” according to which personal data must be “processed lawfully, fairly, and transparently in relation to the data subject” and must be “adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed” (Art. 5, paragraph 1, subparagraphs (a) and (c) of the Regulation). 3.1. The Online Disclosure of Personal Data. As evidenced by the documents and statements provided by the controller during the preliminary investigation, as well as by the findings based on the evidence gathered, it appears that the Hospital Authority published, on its institutional website in the “Transparent Administration” Section, a PDF file containing the “list of eligible/ineligible candidates from the shortlist submitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of “Administrative Assistant, Category B,” containing the names of the participants in the procedure (eligible and ineligible). With regard to the legal basis that would have justified the disclosure of the aforementioned data, the hospital authority has not demonstrated the existence of a specific legal provision requiring the online publication, on its institutional website, of the list of eligible and ineligible candidates following a selection process for personnel registered with employment centers, pursuant to Art. 16 of Law No. 56 of 1987. The reference to Article 19 of Legislative Decree No. 33 of 2013, cited by the hospital to justify the publication of these lists for the purpose of “ensuring maximum transparency in administrative actions,” is irrelevant, given that thethe publication requirement applies exclusively to the “final rankings, updated to include any eligible candidates who were not selected” among those participating in a public competitive examination, but makes no provision regarding the publication of the list of candidates participating in that particular form of hiring provided for by Art. 16 of Law No. 56 of 1987. In this regard, it should also be noted that Art. 19 of Legislative Decree No. 33 of March 14, 2013, in requiring the publication of only “final rankings,” which, moreover, contain only the names of the successful candidates and not those of ineligible candidates, refers exclusively to competitive selection procedures arising from “recruitment calls for applications” and not to those carried out “through the placement of individuals registered on employment lists” (see Art. 35, paragraph 1, subpar. b) of Legislative Decree No. 165 of 2001). Consequently, the reference to Art. 8, paragraph 3, of Legislative Decree No. 33 of 2013, which would allow for the publication of the aforementioned rankings for five years, is irrelevant, given that the specific form of hiring provided for in Art. 16 of the aforementioned Law No. 56 of 1987 cannot be equated with “a public competitive examination” such as the competitive procedures to which Art. 19 of the aforementioned decree applies. As is well known, the Data Protection Authority has provided specific guidance to public administrations regarding the precautions to be taken when disseminating personal data on the Internet for the purposes of transparency and public disclosure of administrative actions through the Guidelines on Transparency, (Provision No. 243 of May 15, 2014, Web Doc. No. 3134436, specifically Parts I and II, para. 3.b; see also the “Guidelines on the Processing of Personal Data of Employees for the Purpose of Managing Employment Relationships in the Public Sector,” Provision No. 161 of June 14, 2007, Web Doc. No. 1417809), to ensure that compliance with sector-specific provisions by the obligated administrative bodies also occurs in accordance with data protection regulations. In particular, with regard to obligations to publish data, information, and documents of the public administration online, as provided for by specific sector-specific provisions other than those concerning transparency—such as, among other things, those aimed at ensuring that administrative acts or measures are made available to data subjects—it should be noted that “where the online publication of data, information, and documents involves the processing of personal data, the requirements of publicity and transparency must be appropriately balanced against the fundamental rights and freedoms, as well as the dignity of the data subject, with particular reference to confidentiality, personal identity, and the right to data protection” (see the Guidelines of May 15, 2014, cited above). As the Data Protection Authority has traditionally pointed out on numerous occasions, the online publication of personal data—unlike traditional forms of publicity—constitutes a particularly invasive form of data dissemination, as it allows anyone to indiscriminately access, in real time, a substantial amount of personal information that is not always up to date and varies in nature. It should also be noted that the Data Protection Authority has long maintained that “even though, at times, sector-specific regulations expressly provide for specific and limited forms of disclosure (such as, for example, simply making documents available at offices or posting documents on bulletin boards within the administration’s premises, or through public posting on the municipal bulletin board), such forms of publication do not, in and of themselves, authorize the transfer of all documents containing personal data published in this manner to a freely accessible Section of the administration’s website. At the same time, this does not preclude the administration from publishing some of the aforementioned documents online, based on a responsible and careful assessment of the limits set by the principles of relevance and non-excess” (see the guidelines cited above). When using this dissemination tool, it is therefore necessary to establish appropriate methods for selecting the information; in this specific case, the hospital system could have employed methods to anonymize the personal data so that only the data subject concerned could determine their position on the ranking list. Furthermore, with particular regard to the information contained in the aforementioned ranking list, it should be noted that Art. 24 of Presidential Decree No. 487 of 1994 stipulates that the employment centers—from which the names of the participants in the aforementioned procedure were identified—shall compile “rankings […] based on the elements set forth in the table attached to this decree,” which also refers to special categories of personal data, such as the “degree of disability” (see the annex to Presidential Decree No. 487 of 1994, “CRITERIA FOR THE COMPILATION OF RANKING LISTS”). In this regard, although it is not possible to determine, based on the published ranking list, the reason for each data subject’s participation in the aforementioned procedure—that is, whether it is due to a disability or an unfavorable financial or income situation— the mere participation in this procedure may lead to the association of the data subjects concerned with a disability. This information—not all of which falls under special categories of data but rather relates to the specific personal circumstances of the participants in the aforementioned procedure—must undoubtedly be processed by the administration; however, in light of the relevant regulatory framework, the conditions for its disclosure through online publication are not met. In any case, the processing in question—even when it does not directly relate to data concerning health of the data subjects—could still have detrimental effects on them and compromise their dignity, since it involves the disclosure of personal data that reveals sensitive economic or social aspects. In light of the foregoing considerations, the online publication on the hospital system’s institutional website, in the “Transparent Administration” Section, of a PDF file containing the “list of eligible/ineligible candidates from the preliminary list submitted via note ref. no. XX dated XX for the filling of n. 22 permanent positions in the professional profile of “Administrative Assistant, Category B,” containing the names of the participants in the procedure (eligible and ineligible), was carried out without an adequate legal basis and in a manner inconsistent with the principles of “lawfulness, fairness, and transparency,” as well as “data minimisation,” in violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. 3.2. Conclusions. In light of the assessments referred to above, it is noted that the statements made by the controller during the preliminary investigation—the veracity of which may be called into question pursuant to Article 168 of the Code—although worthy of consideration, do not suffice to rebut the findings notified by the Office in the notice initiating the proceedings and are insufficient to warrant the dismissal of these proceedings pursuant to the combined provisions of Articles 11 and 14 of the Data Protection Authority’s Regulation No. 1/2019. Therefore, the Office’s preliminary assessments are confirmed, and the processing is found to be unlawful with regard to the disclosure of personal data that the Hospital Authority published on its institutional website, in the Section “Transparent Administration,” a PDF file containing the “list of eligible/ineligible candidates from the preliminary list submitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of administrative assistant, category B,” containing the names of ninety-five participants in the procedure, including both eligible and ineligible candidates, in violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing or interconnected processes), Article 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the most serious violations—relating to Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code—are subject to the penalty provided for in Article 83, para 5, of the Regulation, as also referred to in Art 166, paragraph 2, of the Code, the total amount of the penalty is to be set at up to 20,000,000 euros. In any case, considering that the conduct has exhausted its effects—given that the hospital, upon receiving the Authority’s request for information, removed the names of the ineligible candidates from its institutional website and, subsequently, upon receipt of the notice of the initiation of the investigation, also removed the names of the eligible candidates—the conditions for the adoption of corrective measures, as provided for in Art 58, para 2, of the Regulation, do not apply. 4. Adoption of the injunction ordering the imposition of the administrative fine and ancillary sanctions (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The Data Protection Authority, pursuant to Articles 58(2)(i) and 83 of the Regulation as well as Article 166 of the Code, has the power to “impose an administrative fine pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in lieu of such measures, depending on the circumstances of each individual case” and, in this context, “the Board [of the Data Protection Authority] issues an injunction order, by which it also orders the application of the ancillary administrative sanction of its publication, in full or in part, on the Data Protection Authority’s website pursuant to Article 166, paragraph 7, of the Code” (Art. 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019). In this regard, taking into account Article 83(3) of the Regulation, in the present case, the violation of the aforementioned provisions is subject to the application of the administrative fine provided for in Article 83(5) of the Regulation. The amount of the aforementioned administrative fine, depending on the circumstances of each individual case, must be determined by taking due account of the factors set forth in Art. 83(2) of the Regulation. It is considered that, in the present case, the severity of this violation committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60), given that: - the processing in question, which lasted, overall, from XX to XX, involved the publication of personal data of approximately 90 participants in the aforementioned procedure, including both eligible and ineligible individuals (Article 83(2)(a) of the Regulation); - the violation occurred in good faith based on the mistaken belief that the hospital was acting in accordance with applicable sector-specific regulations, given that the hospital operated under the erroneous assumption that it could pursue purposes of publicity and transparency regarding its administrative actions, also considering that the applicable sector-specific regulations are outdated and not easily interpreted in light of personal data protection legislation, but without taking into account the guidance provided over time by the Data Protection Authority to all public entities on this matter (Article 83(2)(b) of the Regulation); - the publication also concerned, albeit indirectly, personal data falling within the special categories referred to in Article 9 of the Regulation (see Article 83(2)(g) of the Regulation). That said, the following mitigating circumstances must be taken into account: - The hospital system took specific measures to remove the aforementioned personal data from its institutional website and stated that it had implemented technical and organizational measures aimed at complying with applicable regulations and the Data Protection Authority’s guidelines (Art. 83, para. 2, subparagraph (c) of the Regulation); - the hospital system has cooperated fully with the Authority (Article 83, para 2, subparagraph (f) of the Regulation); - there are no previous relevant violations committed by the controller that are of the same nature as those ascertained in connection with the facts of the complaint (see Article 83, para 2, subparagraph e) of the Regulation). In light of the aforementioned factors, assessed as a whole, it is determined that the amount of the administrative fine shall be set at 10,000.00 (ten thousand/00) euros for the violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code, as an administrative fine deemed, pursuant to Article 83(1) of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the large amount of personal data—including special categories of personal data—pertaining to approximately ninety participants in the procedure that was published on the hospital’s institutional website. Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met. NOW THEREFORE, THE DATA PROTECTION AUTHORITY pursuant to Articles 57, para 1, letter f) and 83 of the Regulation, finds that the processing carried out by the Hospital Authority is unlawful under the terms set forth in the reasoning, due to a violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code; ORDERS pursuant to Article 58, para 2, subparagraph i) of the Regulation, the University Hospital of Bologna IRCCS, in the person of its pro tempore legal representative, with headquarters at Via Albertoni No. 15, 40138 Bologna, Tax ID 92038610371, to pay the sum of 10,000.00 euros (ten thousand/00) as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the hospital to pay the aforementioned sum of 10,000.00 euros (ten thousand/00) in accordance with the procedures set forth in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8 of the Code, the offender retains the right to settle the dispute by paying —always in accordance with the procedures set forth in the attachment—of an amount equal to half of the imposed penalty within the time limit specified in Art. 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; c) pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation. Pursuant to Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts, on pain of inadmissibility, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 23, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori [Web Doc. No. 10287326] Decision of July 23, 2026 Register of Decisions No. 551 of July 23, 2026 THE DATA PROTECTION COMMISSIONER AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, setting forth provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Prof. Ginevra Cerrina Feroni; WHEREAS 1. Introduction. In a complaint filed with this Authority, a representative stated that the Bologna University Hospital IRCCS (hereinafter “the Hospital”) had published on its institutional website the complainant’s personal data “relating to a selection process based on income conducted through the employment center, the result of which—a determination of ineligibility—was published on the website and indexed on Google.” Based on the information provided by the complainant and following the Office’s investigation, it was confirmed that a PDF file titled “LIST OF ELIGIBLE/INELIGIBLE CANDIDATES WITH QUALIFICATIONS FROM THE INITIAL LIST SUBMITTED BY NOTE NO. XX OF XX FOR THE POSITION OF XX,” containing the names of the participants in the selection process (eligible and ineligible). 2. The Preliminary Investigation. As part of the preliminary investigation, the Hospital Authority, in a note dated XX, stated, in particular, that: - “The selection procedure in question is aimed at hiring personnel from employment centers into public service. As provided for in Article 35, paragraph 1, subparagraph b) of Legislative Decree No. 165/2001, in fact, the initiation of a selection process pursuant to Art. 16 of Law No. 56 of February 28, 1987, constitutes a ‘recruitment procedure’ used in the public sector for the permanent or fixed-term hiring of workers to be classified infor which an educational qualification no higher than that of compulsory education is required, based on selections made from among those registered on the employment placement and mobility lists, who possess any required professional skills and meet the requirements for entry into public service”; - “By memorandum ref. no. XX dated XX (and subsequent amendments), the Administrative Department of this Company requested that the Unified Metropolitan Service for Personnel Administration and Management (SUMAGP) initiate the hiring procedure. SUMAGP forwarded the request to the Bologna Employment Center (CpI) in order to proceed with the permanent hiring of 22 staff members”; - “The Bologna Employment Center, by executive decision No. XX dated XX, effective as of XX, approved the ranking list containing 1,329 names to be considered for selection”; - “The selection process was designed exclusively to assess the candidate’s suitability to perform the relevant duties and did not involve any comparative evaluation. Therefore, for each candidate selected in order of ranking by the Employment Center, the committee issued a determination of suitability or unsuitability”; - “As can be inferred from the detailed description of the procedure and the relevant legislation cited, the initiation of the selection process, pursuant to Art. 16 of Law No. 56 of February 28, 1987, No. 56—although not competitive in nature, as it does not include any assessment of the applicants’ qualifications or professional competence—constitutes a recruitment procedure for public service positions, at the conclusion of which the candidate deemed suitable is to be hired on a fixed-term or permanent basis in the public sector”; - “The Company has published the final ranking list in the dedicated ‘Competition Announcements’ section of ‘Transparent Administration’ on its institutional website, in accordance with the specific technical rules and the provisions of the law and ANAC.” - “With regard to publication timelines, it should be noted that, pursuant to Art. 8, paragraph 3, of Legislative Decree No. 33/2013 “data, information, and documents subject to mandatory publication under current legislation are published for a period of 5 years, beginning on January 1 of the year following the one in which the publication obligation takes effect”; - “Failure to publish or incorrect publication of the key elements of the described procedure would result in this administration’s failure to properly publicize—or incorrect publicization of—a selection process aimed at identifying and hiring candidates for permanent or fixed-term positions. Legislative Decree No. 33 of 2013 states that the final ranking list is subject to the publication requirement. Therefore, to ensure proper compliance with the regulatory provisions, the entire ranking list referred to in Annex A of Executive Decision No. XX of XX has been published”; - “In any case, having considered the observations of this esteemed Authority, the publication of the ranking list in question has been revised by removing the personal data of ineligible candidates. Furthermore, through the company’s privacy services, with the necessary support of the DPO and the RPCT, an administrative review of the procedures by which this entity fulfills its publication obligations, also with the aim of promoting future improvement measures—in the form of training and information—for the offices involved in these activities.” In a letter dated the XX, the Authority, based on the information gathered, the verifications carried out, and the facts that emerged following the preliminary investigation, notified the Hospital District, pursuant to Article 166, paragraph 5, of the Code, the initiation of proceedings for the adoption of the measures referred to in Art. 58, para. 2, of the Regulations, for having published on its institutional website, in the “Transparent Administration” Section, a PDF file containing the “list of eligible/ineligible candidates from the shortlist transmitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of “administrative assistant, category B,” containing the names of the participants in the procedure (eligible and ineligible), in violation of Articles 5, 6, and 9 of the Regulations, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. In the same letter, the aforementioned head was invited to submit written defenses or documents to the Authority or to request a hearing before the Authority (Art. 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). In a letter dated XX, the hospital submitted a defense brief, stating, in particular, that: - “the requirements and conditions for participation allowed even individuals without a disability or any adverse financial situation to participate in the selection process. In this regard, for example, the selection process was also open to individuals currently employed under any type of employment contract”; - “as regards the publication of the selection results on the hospital’s website, the operational units involved evidently assessed whether the provisions of Art. 19 of Legislative Decree No. 33 of 2013 were also applicable to the case at hand. In fact, by establishing the ‘Reorganization of the regulations concerning the right of access and the obligations of public administrations regarding publicity, transparency, and the dissemination of information,’ this provision governs the impartiality and transparency of public administrations, requiring public administrations to publish notices of competitive examinations for the recruitment, for any purpose, of personnel within the public administration, the evaluation criteria of the selection committee, the exam questions, and the final rankings, updated to reflect any subsequent promotion of eligible candidates who were not initially selected”; - “Nevertheless, in light of the concern raised by this esteemed Authority—namely, that participation in the described selection process could associate the data subjects with a general condition of disability and thus unequivocally reveal special category data as well— the undersigned Data Controller, in order to ensure the fullest possible cooperation, removed the publication of the entire ranking list (containing the personal data of the candidates deemed eligible in the selection process) from the “Transparent Administration” website on XX”; - The number of data subjects (and their respective data) affected by the violation is 95. To describe their composition, reference is made to the Decisions of the Head of the Sumagp Unified Metropolitan Personnel Administration and Management Service: Decision No. XX of XX, by which the data of 19 eligible and 69 ineligible candidates were published on XX […] Decision No. XX of XX, by which the data of 3 eligible and 4 ineligible candidates were published on XX; - “The data of ineligible candidates were removed on XX. The data of eligible candidates were removed as a precautionary measure and, in any case, in a spirit of cooperation with the competent Authority, on XX”; - “In accordance with the principle of accountability, the undersigned, starting with the planning of the XX budget allocated to the DPO’s Operational Unit (approved in May XX), has set the objective of ‘adopting guidelines for the quantitative and qualitative review of information published on the Company’s Institutional Websites regarding data protection,’ an activity still underway to evaluate processing operations carried out for the purpose of transparency”; - “Frequent training courses are offered to employees, including both basic training (an average of at least two per year over the last three years) and specialized courses focused on specific data processing operations or categories thereof. All staff are authorized for data processing and have been provided with appropriate instructions.” During the hearing—requested pursuant to Article 166, paragraph 6, of the Code and held on XX—the hospital system stated, in particular, that: - “With regard to the nature of the data being processed, it should be noted that such data fall exclusively within the category of general data and do not fall under the special categories of data referred to in Art. 9 of Regulation (EU) 2016/679; inclusion on the mobility and placement list does not, in fact, in and of itself indicate any specific characteristics of the data subject participating in the procedure and included on said list”; - “Following the incident, the data controller has implemented numerous measures to prevent similar data breaches from occurring […] confirming the great care and sensitivity that the hospital has always demonstrated regarding the processing of personal data”; - “Due to certain financial constraints, the staff responsible for handling these procedures is particularly limited (5 employees)”; - “Specifically, attention is drawn to the complexity of these hiring procedures within the context of a healthcare organization, which processes a wide variety of personal data in these areas; - “We also draw the legislature’s attention to transparency in personnel management, with particular reference to recruitment procedures, areas at high risk of corruption, as a measure to prevent corruption in this context, in accordance with Art. 19 of Legislative Decree 33/2013.” 3. Outcome of the preliminary investigation. Applicable legislation. Data protection regulations provide that public entities, even when conducting competitive, selection, or other evaluative procedures prior to the establishment of an employment relationship, may process the personal data of data subjects (Art. 4(1) of the Regulation) if the processing is necessary “to comply with a legal obligation to which the controller is subject” (such as specific obligations under national law “for recruitment purposes,” Articles 6(1)(c), 9(2)(b), and 9(4); 88 of the Regulation) or “for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller” (Art. 6, para. 1, subpars. (c) and (e) of the Regulation and Art. 2-ter of the Code). Such processing must, however, be based on Union or Member State law, which must pursue a public interest objective and be proportionate to the pursuit of that objective. The processing purpose must be necessary for the performance of a task carried out in the public interest or related to the exercise of official authority vested in the controller (see Article 6(3) of the Regulation and Article 2-ter of the Code). With regard to special categories of personal data, including data concerning health (for which there is a general prohibition on processing, except in the cases specified in Art. 9(2) of the Regulation, and, in any event, a regime providing greater safeguards than for other types of data (see, Article 9(4) as well as Article 2-septies, paragraph 8 of the Code), processing is permitted where it is “necessary for reasons of substantial public interest on the basis of Union or Member State law, which must be proportionate to the purpose of processing, respect the essence of the right to data protection, and provide for appropriate and specific measures to safeguard the data subject rights and interests” (Article 9, para 2, subparagraph (g), of the Regulation). The controller is required to comply with data protection principles, including those of “lawfulness, fairness, and transparency” as well as “data minimisation,” according to which personal data must be “processed lawfully, fairly, and in a transparent manner in relation to the data subject” and must be “adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed” (Article 5, paragraph 1, subparagraphs (a) and (c) of the Regulation). 3.1. The Online Disclosure of Personal Data. As evidenced by the documents and statements provided by the controller during the preliminary investigation, as well as by the findings based on the information gathered, it appears that the Hospital Authority published, on its institutional website, in the “Transparent Administration” section, a PDF file containing the “list of eligible/ineligible candidates from the shortlist submitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of “administrative assistant, category B,” containing the names of the participants in the procedure (eligible and ineligible). With regard to the legal basis that would have justified the disclosure of the aforementioned data, the hospital system has not demonstrated the existence of a specific legal provision requiring the online publication, on its institutional website, of the list of eligible and ineligible candidates following a selection process for personnel registered with employment centers, pursuant to Art. 16 of Law No. 56 of 1987. The reference to Article 19 of Legislative Decree No. 33 of 2013, cited by the hospital to justify the publication of these lists for the purpose of “ensuring maximum transparency in administrative actions,” is irrelevant, given that thethe publication requirement applies exclusively to the “final rankings, updated to include any eligible candidates who were not selected” among those participating in a public competitive examination, but makes no provision regarding the publication of the list of candidates participating in that particular form of hiring provided for in Art. 16 of Law No. 56 of 1987. In this regard, it should also be noted that Art. 19 of Legislative Decree No. 33 of March 14, 2013, in requiring the publication of only “final rankings,” which, moreover, contain only the names of the successful candidates and not those of ineligible candidates, refers exclusively to competitive selection procedures arising from “recruitment announcements” and not to those carried out “through the placement of individuals registered on employment placement lists” (see Art. 35, paragraph 1, subpar. b) of Legislative Decree No. 165 of 2001). Consequently, the reference to Art. 8, paragraph 3, of Legislative Decree No. 33 of 2013, which would allow for the publication of the aforementioned rankings for five years, is irrelevant, given that the specific form of hiring provided for in Art. 16 of the aforementioned Law No. 56 of 1987 cannot be equated with “a public competitive examination” such as the competitive procedures to which Art. 19 of the aforementioned decree applies. As is well known, the Data Protection Authority has provided specific guidance to public administrations regarding the precautions to be taken when disseminating personal data on the Internet for the purposes of transparency and public disclosure of administrative actions through the Guidelines on Transparency, (Provision No. 243 of May 15, 2014, Web Doc. No. 3134436, specifically Parts I and II, para. 3.b; see also the “Guidelines on the Processing of Personal Data of Employees for the Purpose of Managing Employment Relationships in the Public Sector,” Provision No. 161 of June 14, 2007, Web Doc. No. 1417809), to ensure that compliance with sector-specific provisions by the obligated public administrations also occurred in accordance with data protection regulations. In particular, with regard to obligations to publish data, information, and documents of the public administration online, as provided for by specific sector-specific provisions other than those concerning transparency—such as, among other things, those aimed at ensuring that administrative acts or measures are made available to data subjects—it should be noted that “where the online publication of data, information, and documents involves the processing of personal data, the requirements of publicity and transparency must be appropriately balanced against the fundamental rights and freedoms, as well as the dignity of the data subject, with particular reference to confidentiality, personal identity, and the right to data protection” (see the Guidelines of May 15, 2014, cited above). As the Data Protection Authority has traditionally pointed out on numerous occasions, the online publication of personal data—unlike traditional forms of publicity—constitutes a particularly invasive form of data dissemination, as it allows anyone to indiscriminately access, in real time, a substantial amount of personal information that is not always up-to-date and varies in nature. It should also be noted that the Data Protection Authority has long maintained that “even though, at times, the relevant sector-specific regulations expressly provide for specific and limited forms of disclosure (such as, for example, simply making documents available at offices or posting documents on bulletin boards within administrative premises, or through posting on the official notice board), such forms of publication do not, in and of themselves, authorize the transfer of all documents containing personal data published in this manner to a freely accessible Section of the administration’s website. At the same time, this does not preclude the administration from publishing some of the aforementioned documents online, based on a responsible assessment that carefully considers the limits set by the principles of relevance and non-excess” (see the guidelines cited above). When using this dissemination tool, it is therefore necessary to establish appropriate methods for selecting the information; in this specific case, the hospital system could have employed methods to anonymize the personal data so that only the data subject concerned could determine their position on the ranking list. Furthermore, with particular regard to the information contained in the aforementioned ranking list, it should be noted that Art. 24 of Presidential Decree No. 487 of 1994 stipulates that the employment centers, from which the names of the participants in the aforementioned procedure were identified, shall compile “rankings […] based on the elements set forth in the table attached to this decree,” which also refers to special categories of personal data, such as the “degree of disability” (see the annex to Presidential Decree No. 487 of 1994, “CRITERIA FOR THE COMPILATION OF RANKING LISTS”). In this regard, although it is not possible to determine, based on the published ranking list, the reason for each data subject’s participation in the aforementioned procedure—that is, whether it is due to a disability or an unfavorable financial or income situation— the mere participation in this procedure may lead to the association of the data subjects concerned with a disability. This information—not all of which falls under special categories of data but rather relates to the specific personal circumstances of the participants in the aforementioned procedure—must undoubtedly be processed by the administration; however, in light of the relevant regulatory framework, the conditions for its dissemination through online publication are not met. In any case, the processing in question—even when it does not directly concern data concerning health of the data subjects—could still have detrimental effects on them and compromise their dignity, since it involves the disclosure of personal data that reveals sensitive economic or social aspects. In light of the foregoing considerations, the online publication on the hospital system’s institutional website, in the “Transparent Administration” Section, of a PDF file containing the “list of eligible/ineligible candidates from the preliminary list submitted via note ref. no. XX dated XX for the filling of n. 22 permanent positions in the professional profile of “Administrative Assistant, Category B,” containing the names of the participants in the procedure (eligible and ineligible), was carried out without an adequate legal basis and in a manner inconsistent with the principles of “lawfulness, fairness, and transparency,” as well as “data minimisation,” in violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. 3.2. Conclusions. In light of the assessments outlined above, it is noted that the statements made by the controller during the preliminary investigation—the veracity of which may be called into question pursuant to Art. 168 of the Code—although worthy of consideration, do not suffice to rebut the findings notified by the Office in the notice initiating the proceedings and are insufficient to warrant the dismissal of these proceedings pursuant to the combined provisions of Articles 11 and 14 of the Data Protection Authority’s Regulation No. 1/2019. Therefore, the Office’s preliminary assessments are confirmed, and the processing is found to be unlawful in relation to the disclosure of personal data: the Hospital Authority published, on its institutional website, in the Section “Transparent Administration,” a PDF file containing the “list of eligible/ineligible candidates from the preliminary list submitted via note ref. no. XX dated XX for the filling of 22 permanent positions in the professional category of administrative assistant, category B,” containing the names of ninety-five participants in the procedure—both eligible and ineligible—in violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing or related processing activities), Article 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the most serious violations—relating to Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code—are subject to the penalty provided for in Article 83, para 5, of the Regulation, as also referred to in Art 166, paragraph 2, of the Code, the total amount of the fine is to be set at up to 20,000,000 euros. In any case, considering that the conduct has exhausted its effects—given that the hospital, upon receiving the Authority’s request for information, removed the names of the ineligible candidates from its institutional website and, subsequently, upon receipt of the notice of the initiation of the investigation, also removed the names of the eligible candidates—the conditions for the adoption of corrective measures, as provided for in Art 58, para 2, of the Regulation, do not apply. 4. Adoption of the injunction ordering the imposition of the administrative fine and ancillary sanctions (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The Data Protection Authority, pursuant to Articles 58(2)(i) and 83 of the Regulation as well as Article 166 of the Code, has the power to “impose an administrative fine pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in lieu of such measures, depending on the circumstances of each individual case” and, in this context, “the Board [of the Data Protection Authority] issues an injunction order, by which it also orders the application of the ancillary administrative sanction of its publication, in full or in part, on the Data Protection Authority’s website pursuant to Article 166, paragraph 7, of the Code” (Art. 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019). In this regard, taking into account Article 83(3) of the Regulation, in the present case, the violation of the aforementioned provisions is subject to the application of the administrative fine provided for in Article 83(5) of the Regulation. The amount of the aforementioned administrative fine, depending on the circumstances of each individual case, must be determined by taking due account of the factors set forth in Article 83(2) of the Regulation. It is considered that, in the present case, the severity of this violation committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60), given that: - the processing in question, which lasted, overall, from XX to XX, involved the publication of personal data of approximately 90 participants in the aforementioned procedure, including both eligible and ineligible individuals (Article 83(2)(a) of the Regulation); - the violation occurred in good faith based on the mistaken belief that the hospital was acting in accordance with the applicable sector-specific regulations, given that the hospital operated under the erroneous assumption that it could pursue purposes of publicity and transparency in its administrative actions, also considering that the applicable sector-specific regulations are outdated and not easily interpreted in light of personal data protection legislation, but without taking into account the guidance provided over time by the Data Protection Authority to all public entities on this matter (Recital 83(2)(b) of the Regulation); - the publication also concerned, albeit indirectly, personal data falling within the special categories referred to in Article 9 of the Regulation (see Article 83(2)(g) of the Regulation). That said, the following mitigating circumstances must be taken into account: - The hospital system took specific measures to remove the aforementioned personal data from its institutional website and stated that it had implemented technical and organizational measures aimed at complying with applicable regulations and the Data Protection Authority’s guidelines (Art. 83(2), para 2, subparagraph (c) of the Regulation); - the hospital system has offered full cooperation with the Authority (Article 83, para 2, subparagraph (f) of the Regulation); - there are no previous relevant violations committed by the controller that are of the same nature as those ascertained in connection with the facts of the complaint (see Article 83, para 2, subparagraph e), of the Regulation). In light of the aforementioned factors, assessed as a whole, it is determined that the amount of the administrative fine shall be set at 10,000.00 (ten thousand/00) euros for the violation of Articles 5, 6, and 9 of the Regulation, as well as Sections 2-ter and 2-septies, paragraph 8, of the Code, as an administrative fine deemed, pursuant to Article 83, para 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the numerous pieces of personal data—including special categories of personal data—pertaining to approximately ninety participants in the proceedings that were published on the hospital’s institutional website. Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met. NOW THEREFORE, THE DATA PROTECTION AUTHORITY pursuant to Articles 57, para 1, letter f) and 83 of the Regulation, finds that the processing carried out by the Hospital Authority is unlawful under the terms set forth in the reasoning, due to a violation of Articles 5, 6, and 9 of the Regulation, as well as Articles 2-ter and 2-septies, paragraph 8, of the Code; ORDERS pursuant to Article 58, para 2, subparagraph i) of the Regulation, the Bologna University Hospital IRCCS, in the person of its pro tempore legal representative, with headquarters at Via Albertoni No. 15, 40138 Bologna, Tax ID 92038610371, to pay the sum of 10,000.00 euros (ten thousand/00) as an administrative fine for the violations indicated in this order; THEREFORE ORDERS the hospital to pay the aforementioned sum of 10,000.00 euros (ten thousand/00) in accordance with the procedures set forth in the attachment, within thirty days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8, of the Code, the offender retains the right to settle the dispute by paying —always in accordance with the procedures set forth in the attachment—of an amount equal to half of the penalty imposed within the time limit specified in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; c) pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2 of the Regulation, in the Authority’s internal register provided for by Article 57, para 1, letter u) of the Regulation. Pursuant to Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts; failure to do so within within thirty days from the date of notification of the decision or within sixty days if the appellant resides abroad. Rome, July 23, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori