Azienda ULSS 6 Euganea – €22,000 Fine (Italy, 2024)

€22,000Garante per la protezione dei dati personali17 July 2024Italy
final
ePrivacy
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Azienda ULSS 6 Euganea was fined €22,000 after a cyberattack exposed personal data of employees and patients. The health authority failed to implement proper security measures to protect sensitive information. This case emphasizes the need for strong data protection practices, especially in healthcare.

What happened

Azienda ULSS 6 Euganea experienced a cyberattack that led to unauthorized access to personal data.

Who was affected

Employees and patients whose personal data was stored on the health authority's servers.

What the authority found

The Italian Data Protection Authority found that the company did not take adequate security measures to protect personal data, violating GDPR rules.

Why this matters

This ruling stresses the importance of robust cybersecurity measures for organizations handling sensitive data. It serves as a warning for other companies to strengthen their data protection strategies.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(GDPR)
Art. 33(1) GDPR
Art. 34(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 4 April 2026
articles corrected
Full Legal Summary
Detailed

The controller, a health authority managing several hospitals and other health facilities, experienced a cyberattack. This led to the unauthorised access to files stored in the controller's servers. These files contained personal data of both employees and patients, including medical documents and images. The controller notified the data breach to the DPA in accordance with Article 33 GDPR and to data subjects according to Article 34 GDPR. Moreover, several data subjects filed a complaint with the DPA. The controller argued that it was in the process of updating its IT system and improving its security measures. First, the DPA considered that the data breach notification to itself and data subjects was made without an undue delay and, therefore, did not find a violation of Article 33 and 34 GDPR. However, the DPA noted that the controller did not implement appropriate measures to ensure that it could timely learn about unauthorised accesses to the IT system. Therefore, it found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. Secondly, the DPA held that the technical and organisational measures implemented by the controller to avoid cyberattacks were not adequate. For example, two-factor authentication was not implemented. Therefore, the DPA found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. On these grounds, the DPA fined the controller €22,000.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

17 July 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€22,000

GDPRhub ID

gdprhub-8336

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Azienda ULSS 6 Euganea - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: