Azienda ULSS 6 Euganea – €22,000 Fine (Italy, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Azienda ULSS 6 Euganea was fined €22,000 after a cyberattack exposed personal data of employees and patients. The health authority failed to implement proper security measures to protect sensitive information. This case emphasizes the need for strong data protection practices, especially in healthcare.
What happened
Azienda ULSS 6 Euganea experienced a cyberattack that led to unauthorized access to personal data.
Who was affected
Employees and patients whose personal data was stored on the health authority's servers.
What the authority found
The Italian Data Protection Authority found that the company did not take adequate security measures to protect personal data, violating GDPR rules.
Why this matters
This ruling stresses the importance of robust cybersecurity measures for organizations handling sensitive data. It serves as a warning for other companies to strengthen their data protection strategies.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller, a health authority managing several hospitals and other health facilities, experienced a cyberattack. This led to the unauthorised access to files stored in the controller's servers. These files contained personal data of both employees and patients, including medical documents and images. The controller notified the data breach to the DPA in accordance with Article 33 GDPR and to data subjects according to Article 34 GDPR. Moreover, several data subjects filed a complaint with the DPA. The controller argued that it was in the process of updating its IT system and improving its security measures. First, the DPA considered that the data breach notification to itself and data subjects was made without an undue delay and, therefore, did not find a violation of Article 33 and 34 GDPR. However, the DPA noted that the controller did not implement appropriate measures to ensure that it could timely learn about unauthorised accesses to the IT system. Therefore, it found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. Secondly, the DPA held that the technical and organisational measures implemented by the controller to avoid cyberattacks were not adequate. For example, two-factor authentication was not implemented. Therefore, the DPA found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. On these grounds, the DPA fined the controller €22,000.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving Azienda ULSS 6 Euganea in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
17 July 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€22,000
GDPRhub ID
gdprhub-8336About this data
Cite as: Cookie Fines. Azienda ULSS 6 Euganea - Italy (2024). Retrieved from cookiefines.eu
Last updated: