dott. Giuseppe Rubino – €20,000 Fine (Italy, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Doctor Giuseppe Rubino was fined for sharing a patient's photos on Instagram without her permission. This case is important because it shows that healthcare providers must respect patient privacy and obtain consent before sharing sensitive information. Medical professionals should be careful about how they use patient data online.
What happened
Giuseppe Rubino published unauthorized photographs of a patient on social media after performing surgery.
Who was affected
The patient whose images were shared without consent.
What the authority found
The Italian DPA found that Giuseppe Rubino violated GDPR by sharing personal images without the patient's authorization.
Why this matters
This case highlights the need for healthcare providers to prioritize patient consent and privacy when sharing information, especially on social media.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The data subject, a patient, filed a complaint against her plastic surgeon, the controller. The controller published, without authorisation, photographs depicting her during an aesthetic surgery on Instagram. The images showed her recognizable face before (wearing a surgical cap) and after the procedure, with controller's logo displayed on his personal page. The data subject stated that she had not given any consent for the sharing of the photographs, which had been taken for internal use only. Informed by a friend about the publication, she took legal action to request the removal of the images and compensation for damages. In the context of this separate civil procedure, the controller explained that he requested the removal of all patient images from his social media profiles years earlier. He further clarified that the issue arose because the patient had signed consent forms with another colleague at the clinic, without specific authorization for the publication of the images. Although he did not admit any wrongdoing, the doctor resolved the separate legal through a settlement agreement, providing financial compensation. The DPA considered the violation committed by the controller to be of a high level of severity, given the particularly sensitive nature of the personal data involved (images of the face following an aesthetic procedure) and the processing carried out (unauthorized sharing). In light of these circumstances and in application of the principles of effectiveness, proportionality, and deterrence, the DPA imposed a financial penalty of €20,000 for violations of Articles 5 and 9 GDPR, as well as [https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2003-06-30;196~art2septies Article 2-septies, paragraph 8, of the Privacy Code].
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for dott. Giuseppe Rubino in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
12 December 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€20,000
GDPRhub ID
gdprhub-8864About this data
Cite as: Cookie Fines. dott. Giuseppe Rubino - Italy (2024). Retrieved from cookiefines.eu
Last updated: