Azienda ULSS 6 Euganea – €22,000 Fine (Italy, 2024)

€22,000Garante per la protezione dei dati personali17 July 2024Italy
final
ePrivacy
Fine

Azienda ULSS 6 Euganea was fined €22,000 after a cyberattack exposed personal data of patients and employees. This is significant because it shows the need for strong security measures to protect sensitive information. Health organizations must prioritize cybersecurity to safeguard personal data.

What happened

A cyberattack on Azienda ULSS 6 Euganea led to unauthorized access to personal data stored on their servers.

Who was affected

Patients and employees whose personal information was compromised in the cyberattack.

What the authority found

The Italian DPA found that the organization failed to implement adequate security measures to prevent unauthorized access to personal data.

Why this matters

This ruling stresses the importance of cybersecurity in protecting sensitive data. Organizations should adopt strong security protocols to prevent breaches.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 5(1)(f) GDPR
Art. 33(1) GDPR
Art. 34(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(GDPR)
Art. 33(1) GDPR
Art. 34(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 4 April 2026
articles corrected
Full Legal Summary
Detailed

The controller, a health authority managing several hospitals and other health facilities, experienced a cyberattack. This led to the unauthorised access to files stored in the controller's servers. These files contained personal data of both employees and patients, including medical documents and images. The controller notified the data breach to the DPA in accordance with Article 33 GDPR and to data subjects according to Article 34 GDPR. Moreover, several data subjects filed a complaint with the DPA. The controller argued that it was in the process of updating its IT system and improving its security measures. First, the DPA considered that the data breach notification to itself and data subjects was made without an undue delay and, therefore, did not find a violation of Article 33 and 34 GDPR. However, the DPA noted that the controller did not implement appropriate measures to ensure that it could timely learn about unauthorised accesses to the IT system. Therefore, it found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. Secondly, the DPA held that the technical and organisational measures implemented by the controller to avoid cyberattacks were not adequate. For example, two-factor authentication was not implemented. Therefore, the DPA found a violation of Article 5(1)(f) GDPR in combination with Article 32(1) GDPR. On these grounds, the DPA fined the controller €22,000.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

17 July 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€22,000

GDPRhub ID

gdprhub-8336

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Azienda ULSS 6 Euganea - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: