dott. Giuseppe Rubino – €20,000 Fine (Italy, 2024)

€20,000Garante per la protezione dei dati personali12 December 2024Italy
final
ePrivacy
Fine

Dr. Giuseppe Rubino was fined for sharing a patient's surgery photos on social media without her permission. This is significant because it emphasizes the need for medical professionals to protect patient privacy. Doctors and clinics should always get clear consent before sharing any patient information.

What happened

Dr. Giuseppe Rubino published unauthorized photos of a patient on Instagram after her surgery.

Who was affected

The patient whose surgery photos were shared without her consent.

What the authority found

The data protection authority determined that Dr. Rubino violated GDPR by sharing sensitive personal data without proper consent.

Why this matters

This ruling serves as a reminder for healthcare providers to prioritize patient privacy and obtain explicit consent before sharing any personal information, especially sensitive data.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 9(GDPR)
View original scraped data
Art. 5(GDPR)
Art. 9(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 2-septies Codice Privacy
Source verified 5 April 2026
articles corrected
national law identified
verified correct
Full Legal Summary
Detailed

The data subject, a patient, filed a complaint against her plastic surgeon, the controller. The controller published, without authorisation, photographs depicting her during an aesthetic surgery on Instagram. The images showed her recognizable face before (wearing a surgical cap) and after the procedure, with controller's logo displayed on his personal page. The data subject stated that she had not given any consent for the sharing of the photographs, which had been taken for internal use only. Informed by a friend about the publication, she took legal action to request the removal of the images and compensation for damages. In the context of this separate civil procedure, the controller explained that he requested the removal of all patient images from his social media profiles years earlier. He further clarified that the issue arose because the patient had signed consent forms with another colleague at the clinic, without specific authorization for the publication of the images. Although he did not admit any wrongdoing, the doctor resolved the separate legal through a settlement agreement, providing financial compensation. The DPA considered the violation committed by the controller to be of a high level of severity, given the particularly sensitive nature of the personal data involved (images of the face following an aesthetic procedure) and the processing carried out (unauthorized sharing). In light of these circumstances and in application of the principles of effectiveness, proportionality, and deterrence, the DPA imposed a financial penalty of €20,000 for violations of Articles 5 and 9 GDPR, as well as [https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2003-06-30;196~art2septies Article 2-septies, paragraph 8, of the Privacy Code].

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for dott. Giuseppe Rubino in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

12 December 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€20,000

GDPRhub ID

gdprhub-8864

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. dott. Giuseppe Rubino - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: