Azienda Sanitaria Locale TO4 – €8,400 Fine (Italy, 2024)

€8,400Garante per la protezione dei dati personali23 May 2024Italy
final
ePrivacy
Fine

Azienda Sanitaria Locale TO4 was fined for accidentally exposing email addresses of patients. This incident shows the importance of handling personal data carefully. Companies must use secure methods when communicating sensitive information.

What happened

Azienda Sanitaria Locale TO4 mistakenly disclosed email addresses of 45 patients by using the 'cc' field instead of 'bcc' in an email.

Who was affected

The 45 patients whose email addresses and health information were disclosed.

What the authority found

The DPA found that the health authority violated GDPR by improperly disclosing personal data due to a human error.

Why this matters

This case underscores the need for organizations to train employees on proper data handling practices. Mistakes can lead to serious privacy breaches and fines.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 9(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 9(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 5 April 2026
verified correct
Full Legal Summary
Detailed

The controller, a health authority, sent an email to 45 data subjects containing instructions on how to get medications used to cure multiple sclerosis. The person sending the email put the email addresses of the recipients in the “cc” field instead of choosing the “bcc” one. This resulted in the email addresses of the data subject being disclosed to each other. After receiving a report by one of the data subject, the controller made a data breach notification to the DPA according to Article 33(1) GDPR. The controller argued that the data breach happened due to a human mistake and that it had repeatedly instructed its employees to use the “bcc” field when sending emails to multiple people. Moreover, the controller pointed out that the number of data subjects concerned was quite low and that the breach lasted for a short period of time. First, the DPA noted that an email address is personal data even in the case it is not composed by the name and the surname of the data subject, since it however allows to identify a natural person. Secondly, the DPA pointed out that data relating to the administration of a medication is data concerning health under Article 9(1) GDPR, which need a higher protection since its processing implies a higher risk for the freedom and rights of the data subjects. Thirdly, the DPA noted that using the “cc” field resulted in the unlawful disclosure of the names and health data of 45 patients. Therefore, the DPA found a violation of Article 5(1)(f) and 9 GDPR and issued a file of €8,400.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Azienda Sanitaria Locale TO4 in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

23 May 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€8,400

GDPRhub ID

gdprhub-8155

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Azienda Sanitaria Locale TO4 - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: