Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Azienda Ospedaliero Universitaria Senese: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) News De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). News DeFine is a calculator for GDPR fines based on method of the EDPB Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Literature General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain
Full text
The Italian DPA (Garante) fined Azienda Ospedaliero Universitaria Senese EUR 50,000. The controller, a hospital, had reported to the Italian DPA that a couple's medical report had been mistakenly sent to an uninvolved third party. The report contained information about a genetic consultation and the health status and sex life of the data subjects. The incident occurred due to an error in packaging the letter, according to a statement from the controller.
Industry: Health Care
Original document at the source www.garanteprivacy.it