Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security
The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi.
Full text
The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to search through the data subject's history, even if this was unrelated to the specific medical treatment.
Industry: Health Care
How it connects
Related across sources
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) CJEU Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Nov 12, 2019 Territorial scope (GDPR) IP Address Processors
Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Apr 4, 2023 Notification Obligation Data Breaches Personal Data
C-210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein C-210/16 (Wirtschaftsakademie) CJEU Jun 5, 2018 IP Address Controllers Processors
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address