Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
I.S.P.R.O.: Non-compliance with general data processing principles
The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the oncology health care facility I.S.P.R.O..
Full text
The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the oncology health care facility I.S.P.R.O.. An individual had mistakenly received medical records from another patient via e-mail.
Industry: Health Care
How it connects
Related across sources
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address
2025 Study on the secondary use of personal data in the context of scientific research 2 This study has been prepared by Milieu under Contract No EDPS/2019/02 - 04 for the benefit of the EDPB. The study has been carried out by researchers from KU Leuven (CiTiP) and… EDPB Apr 3, 2025 Personal Data Statistics Scientific Research
Opinion 03/2022 EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space Opinion Jul 12, 2022 Healthcare Health Data Types of Special Categories of Personal Data
Guidelines 03/2020 processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak Guidelines ·EDPB Apr 21, 2020 Healthcare Health Data Personal Data
1 As 183/2023-62 Health insurer must disclose aggregated patient treatment data under Free Access to OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free… Supreme Administrative Court Aug 4, 2026 Pseudonymization Anonymization Personal Data
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address