Trento health authority – €150,000 Fine (Italy, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Trento health authority shared 293 health documents with general practitioners, even though the individuals involved had requested that their information remain private. This case is crucial as it underscores the importance of respecting individuals' rights to control their personal health data.
What happened
The Trento health authority incorrectly shared health documents of 175 individuals with general practitioners, violating their requests for confidentiality.
Who was affected
Individuals whose health documents were shared, including two minors who had opted to keep their information private.
What the authority found
The Italian DPA found that the authority violated data protection rules by sharing health data without proper consent from the individuals.
Why this matters
This ruling stresses the necessity for health organizations to adhere to strict data privacy standards. Companies must ensure they respect individuals' choices regarding their health information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
By a technical mistake, the Trento health authority shared with general practitioners a total of 293 health documents referring to 175 interested parties (including 2 minors) although the interested parties had exercised their right to obscure these documents. The Italian DPA considered that the personal data had been shared in violation of art. 75 of the Italian “Codice in materia di protezione dei dati personali” and of Article 9 GDPR as well as the principles of lawfulness, integrity and confidentiality of the processing as per Article 5 GDPR. In fact, according to Article 9 GDPR, health data may only be disclosed to the person concerned and may only be disclosed to third parties on the basis of an appropriate legal base or on the basis of written authorization by the data subject. In the case under examination, the data subjects explicitly requested not to share their data with their general practitioners, and the DPA therefore found that Article 9 had been violated. The DPA also referred to specific health data guidelines published by the Italian DPA itself (“Linee guida in materia di Dossier sanitario - 4 giugno 2015”) and to Article 75 of the Italian Data Protection Code. According to these guidelines, an important guarantee to protect the confidentiality of the interested party consists in the possibility that the interested party decides to obscure certain data or health documents that can be consulted through the Health Dossier. Since the parties specifically exercised this right, the DPA deemed that these Guidelines, and therefore article 75 of the Italian Code, were also violated. With the power conferred by Article 58(2)(i) and 83 GDPR, the Italian DPA imposed a fine of €150,000 on the Trento health authority.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Trento health authority in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
27 May 2021
Authority
Garante per la protezione dei dati personali
Fine Amount
€150,000
GDPRhub ID
gdprhub-3676About this data
Cite as: Cookie Fines. Trento health authority - Italy (2021). Retrieved from cookiefines.eu
Last updated: