dott. Giuseppe Rubino – €20,000 Fine (Italy, 2024)
Dr. Giuseppe Rubino was fined for sharing a patient's surgery photos on social media without her permission. This is significant because it emphasizes the need for medical professionals to protect patient privacy. Doctors and clinics should always get clear consent before sharing any patient information.
What happened
Dr. Giuseppe Rubino published unauthorized photos of a patient on Instagram after her surgery.
Who was affected
The patient whose surgery photos were shared without her consent.
What the authority found
The data protection authority determined that Dr. Rubino violated GDPR by sharing sensitive personal data without proper consent.
Why this matters
This ruling serves as a reminder for healthcare providers to prioritize patient privacy and obtain explicit consent before sharing any personal information, especially sensitive data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The data subject, a patient, filed a complaint against her plastic surgeon, the controller. The controller published, without authorisation, photographs depicting her during an aesthetic surgery on Instagram. The images showed her recognizable face before (wearing a surgical cap) and after the procedure, with controller's logo displayed on his personal page. The data subject stated that she had not given any consent for the sharing of the photographs, which had been taken for internal use only. Informed by a friend about the publication, she took legal action to request the removal of the images and compensation for damages. In the context of this separate civil procedure, the controller explained that he requested the removal of all patient images from his social media profiles years earlier. He further clarified that the issue arose because the patient had signed consent forms with another colleague at the clinic, without specific authorization for the publication of the images. Although he did not admit any wrongdoing, the doctor resolved the separate legal through a settlement agreement, providing financial compensation. The DPA considered the violation committed by the controller to be of a high level of severity, given the particularly sensitive nature of the personal data involved (images of the face following an aesthetic procedure) and the processing carried out (unauthorized sharing). In light of these circumstances and in application of the principles of effectiveness, proportionality, and deterrence, the DPA imposed a financial penalty of €20,000 for violations of Articles 5 and 9 GDPR, as well as [https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2003-06-30;196~art2septies Article 2-septies, paragraph 8, of the Privacy Code].
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for dott. Giuseppe Rubino in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
12 December 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€20,000
GDPRhub ID
gdprhub-8864About this data
Cite as: Cookie Fines. dott. Giuseppe Rubino - Italy (2024). Retrieved from cookiefines.eu
Last updated: