Azienda Sanitaria Locale TO4 – €8,400 Fine (Italy, 2024)
Azienda Sanitaria Locale TO4 was fined for accidentally exposing email addresses of patients. This incident shows the importance of handling personal data carefully. Companies must use secure methods when communicating sensitive information.
What happened
Azienda Sanitaria Locale TO4 mistakenly disclosed email addresses of 45 patients by using the 'cc' field instead of 'bcc' in an email.
Who was affected
The 45 patients whose email addresses and health information were disclosed.
What the authority found
The DPA found that the health authority violated GDPR by improperly disclosing personal data due to a human error.
Why this matters
This case underscores the need for organizations to train employees on proper data handling practices. Mistakes can lead to serious privacy breaches and fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller, a health authority, sent an email to 45 data subjects containing instructions on how to get medications used to cure multiple sclerosis. The person sending the email put the email addresses of the recipients in the “cc” field instead of choosing the “bcc” one. This resulted in the email addresses of the data subject being disclosed to each other. After receiving a report by one of the data subject, the controller made a data breach notification to the DPA according to Article 33(1) GDPR. The controller argued that the data breach happened due to a human mistake and that it had repeatedly instructed its employees to use the “bcc” field when sending emails to multiple people. Moreover, the controller pointed out that the number of data subjects concerned was quite low and that the breach lasted for a short period of time. First, the DPA noted that an email address is personal data even in the case it is not composed by the name and the surname of the data subject, since it however allows to identify a natural person. Secondly, the DPA pointed out that data relating to the administration of a medication is data concerning health under Article 9(1) GDPR, which need a higher protection since its processing implies a higher risk for the freedom and rights of the data subjects. Thirdly, the DPA noted that using the “cc” field resulted in the unlawful disclosure of the names and health data of 45 patients. Therefore, the DPA found a violation of Article 5(1)(f) and 9 GDPR and issued a file of €8,400.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Azienda Sanitaria Locale TO4 in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
23 May 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€8,400
GDPRhub ID
gdprhub-8155About this data
Cite as: Cookie Fines. Azienda Sanitaria Locale TO4 - Italy (2024). Retrieved from cookiefines.eu
Last updated: