Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Cluster S.r.l.: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidance Guidelines 9/2022 on personal data breach notification under GDPR News De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures News De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.
Full text
The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had been published on the internet. The controller had organized a medical training event at which documents containing personal data of the data subject and their deceased son were forwarded to the participants without sufficient anonymization. Some documents were later published on the internet by a third party.
Industry: Health Care
Original document at the source www.garanteprivacy.it