Italian Red Cross – €700 Fine (Italy, 2026)

€700Garante per la protezione dei dati personali28 May 2026Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Italian Red Cross was fined €700 after a patient’s HIV status was improperly disclosed on a food tray. This case is significant because it highlights the importance of protecting sensitive health information. Organizations must be careful to keep personal health data confidential.

What happened

The Italian Red Cross disclosed a patient's full name and HIV status on a food tray note without proper justification.

Who was affected

The patient whose HIV status was revealed through the food tray note was affected.

What the authority found

The authority found that the Italian Red Cross did not have a legal basis to disclose the patient's sensitive health information.

Why this matters

This case underscores the need for healthcare providers to ensure confidentiality and protect sensitive information, especially regarding health conditions.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 5(1)(c) GDPR
Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 5(1)(f) GDPR
Art. 9(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 157 of the Code
Source verified 8 July 2026
articles corrected
national law identified
Full Legal Summary
Detailed

A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised, they received their food tray with a note stating their full name and medical condition as a patient with HIV. The data subject had also contacted the health directorate of the hospital, but had not received a response. During the DPA’s investigations, the controller stated that it included information on patients’ conditions to alert the kitchen staff on protective measures needed. The controller later modified the form alerting the staff to replace the patient’s medical condition with specific requests (e.g. to use disposable tableware). The DPA found a violation of Article 9 GDPR. The DPA highlighted that under national law, the controller has additional responsibilities in ensuring the confidentiality of data subjects that have HIV or AIDS. National law also requires medical facilities to implement protective measures to prevent the transmission of HIV. However, this requirement does not justify including the data subject’s full name and condition in the context of meal service. Therefore, the controller did not have a legal basis to process the data subject’s personal data in the context of disclosing the data subject’s HIV status while providing meals. This was the case for both including the patient's medical information in the form to the kitchen staff and disclosing the data through the note in the meal tray. The DPA also found a violation of Articles 5(1)(c) and (f) GDPR. The DPA considered that the processing activity violated the principle of data minimisation. The controller also failed to ensure security of processing by disclosing the data subject’s medical condition. Finally, the DPA found a violation of [https://www.gazzettaufficiale.it/atto/stampa/serie_generale/originario Article 157 of the Code], as the controller had not complied with its obligation to provide informat

Related Enforcement Actions (0)

No other enforcement actions found for Italian Red Cross in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

28 May 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€700

Enforcement Tracker ID

3243

GDPRhub ID

gdprhub-10103

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Italian Red Cross - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: