Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing

The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina .

€55,000 Fine
Azienda Universitaria Giuliano Isontina
ITALY
Art. 5 GDPR Art. 9 GDPR Art. 14 GDPR Art. 35 GDPR Art. 2 GDPR

Full text

The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal patient data to indicate the risk of having complications in the event of a Covid 19 infection. This was intended to identify appropriate diagnostic and therapeutic pathways in a timely manner in the event of complications. However, the DPA found that the health authority did not have a valid legal basis to process patients' personal data for profiling. In addition, the DPA found that the health authority had failed to conduct a data protection impact assessment. In calculating the fine, the DPA took into account the aggravating factor that a large number of individuals were affected.

Industry: Health Care

How it connects

C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
W256 2227693-1 Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by… Federal Administrative Court Sep 28, 2023 Marketing Profiling Automated Decision-Making
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers