Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Azienda Socio Sanitaria Territoriale Ovest Milanese: Non-compliance with general data processing principles
The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese.
Full text
The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of several data subjects. For example, a patient's health records were given to the wrong patient. In addition, the controller had sent an email regarding Covid-19 behavior in multiple scelrose patients to 198 recipients, allowing all recipients to openly view the other email addresses. In addition, the controller sent an invitation for a disability assessment to the wrong person.
Industry: Health Care
How it connects
Related across sources
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Jan 3, 2022 Notification Obligation Data Breaches Personal Data
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Jan 30, 2020 Personal Data Processing Material scope (GDPR)
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
Opinion 12/2024 “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF 1 Adopted Opinion 12 /202 4 on the draft decision of the French Supervisory Authority regarding the “ Code of Conduct for Service Providers in Clinical Research” submitted by… ·Opinion ·EDPB Jun 18, 2024 Codes of Conduct Supervision Supervisory Authorities