Skip to content
Enforcement · Garante EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Garante investigates University Health Agency of Friuli Centrale EHR access logs

Facts. Facts The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system.

Original title: Garante per la protezione dei dati personali (Italy) - 616/2026

Italy

How it connects

T-318/24 GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725 An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and… General Court Dec 3, 2025 Right of Access Right of Access Procedures Personal Data
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Supervision Right of Access
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Liability

Full text

Facts. Facts The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA received a complaint from an employee (the data subject) of the University Health Agency of Friuli Centrale (the controller) concerning the controller's processing of the electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organi