Hospital – €20,000 Fine (Malta, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A hospital in Malta was fined for mishandling personal data by combining health information with data from a public electoral register. They did not have permission to process this data, which led to unauthorized access. This case highlights the need for proper data handling practices in healthcare.
What happened
The hospital processed personal data from the public electoral register without legal permission and combined it with health data.
Who was affected
Patients whose health data was improperly combined with information from the electoral register.
What the authority found
The Maltese Data Protection Authority found that the hospital violated multiple GDPR rules by failing to have a legal basis for processing the data and not ensuring its accuracy.
Why this matters
This ruling underscores the importance of having a valid legal basis for processing personal data, especially in sensitive sectors like healthcare. Organizations must ensure they follow strict data handling protocols.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Non-compliance with general data processing principles
Related Enforcement Actions (0)
No other enforcement actions found for Hospital in MT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
2 April 2025
Authority
Information and Data Protection Commissioner
Fine Amount
€20,000
Enforcement Tracker ID
3142
About this data
Cite as: Cookie Fines. Hospital - Malta (2025). Retrieved from cookiefines.eu
Last updated: