Ama S.p.a. – €239,000 Fine (Italy, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Ama S.p.a. was fined for mishandling sensitive information about abortions in cemeteries in Rome. The company acted beyond its instructions and failed to protect personal health data, which is a serious violation. This case highlights the importance of following data protection rules when handling sensitive information.
What happened
Ama S.p.a. improperly managed sensitive health data related to abortions in cemeteries.
Who was affected
Women whose abortion-related information was mishandled by Ama S.p.a.
What the authority found
The Italian DPA ruled that Ama S.p.a. acted as a data controller without a valid legal basis, violating GDPR rules.
Why this matters
This ruling emphasizes that companies must strictly follow data protection regulations, especially when dealing with sensitive health information. Other businesses should review their data handling practices to ensure compliance.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
After numerous press reports, the Italian DPA learned that some cemeteries in Rome had a specific area for 'products of conception' and 'fetuses' that were buried in small graves over which the names of women who had had abortions were affixed on a cross. Differently from other areas of the cemeteries, where fetuses were buried after a cerimony, in this specific areas the burials were made at the request of the local health agency and did not receive a funeral. The Italian DPA then opened a wide investigation that was divided in 3 procedures: one against the local health agency (ASL), one against the public company that managed the cemeteries (AMA) and one against the City of Rome (owner of the public company). In the course of the investigations, the DPA found that AMA had signed a service contract with the City of Rome, through which it was identified as the processor, pursuant to Article 28 GDPR. After the investigations, the Italian DPA concluded that the AMA, originally a processor, acted beyond the instructions of the City of Rome, violating Article 29 GDPR. Therefore, it held that the company determined the purposes and means of that procesing and considered it as the controller. The DPA then highlighted that information about abortion constitutes health data and that the spontaneous or voluntary interruption of pregnancy for reasons of health risk is considered as a disease, according to Italian law. Moreover, the law establishes a strict regime of confidentiality to protect the woman's right to anonymity, criminalizing the disclosure of the identity of women by health professionals. The DPA further emphasized that there is no law requiring the names of women who had an abortion to be placed on the graves of the fetuses. According to the DPA, the controller should have implemented sufficient measures to ensure that only an identification code, associated with the name of the parents in the cemetery register, was placed on the graves. Finally, the DPA n
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Ama S.p.a. in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
27 April 2023
Authority
Garante per la protezione dei dati personali
Fine Amount
€239,000
GDPRhub ID
gdprhub-6059About this data
Cite as: Cookie Fines. Ama S.p.a. - Italy (2023). Retrieved from cookiefines.eu
Last updated: