Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security

The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio.

€20,000 Fine
Cooperativa Sociale Quadrifoglio
ITALY
Art. 28 GDPR Art. 32 GDPR

Full text

The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the personal and health data of children. There was no legal basis for this, and it happened due to insufficient technical and organisational measures to ensure data security.

Industry: Health Care

How it connects

C-667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts The CJEU (Third Chamber) ruled on a preliminary reference from the Bundesarbeitsgericht in a case where ZQ sought compensation from his employer, Medizinischer Dienst der… Third Chamber Dec 21, 2023 Health Data Healthcare Integrity and Confidentiality Principle
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision