# Azienda Socio Sanitaria Territoriale Ovest Milanese: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Italian Data Protection Authority (Garante)
- Date: 2023-07-18
- Original: https://www.enforcementtracker.com/ETid-2054
- Canonical: https://overview.legal/posts/48169
- Topics: Data Breaches, Healthcare, IP Address, Controllers, Processing Agreement, Personal Data, Processing, Supervisory Authorities, Data Controller

## Summary

The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of several data subjects. For example, a patient's health records were given to the wrong patient. In addition, the controller had sent an email regarding Covid-19 behavior in multiple scelrose patients to 198 recipients, allowing all recipients to openly view the other email addresses. In addition, the controller sent an inv

## Full text

The Italian DPA has imposed a fine of EUR 12,000 on Azienda Socio Sanitaria Territoriale Ovest Milanese. The controller had suffered data breaches that affected the privacy of several data subjects. For example, a patient's health records were given to the wrong patient. In addition, the controller had sent an email regarding Covid-19 behavior in multiple scelrose patients to 198 recipients, allowing all recipients to openly view the other email addresses. In addition, the controller sent an invitation for a disability assessment to the wrong person.

GDPR Articles: Art. 5 (1) f) GDPR, Art. 9 GDPR, Art. 32 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/48169 · 2026-08-22
