The provincial Health Authority of Enna – €20,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The provincial Health Authority of Enna was fined for improperly publishing a person's judicial records online. This is significant because it shows that organizations must handle sensitive information carefully. Health authorities need to follow strict rules to protect people's privacy.
What happened
The Health Authority published personal judicial data on its website without proper removal after a request.
Who was affected
A person whose judicial records were published without their consent was affected.
What the authority found
The Italian data protection authority found that the Health Authority violated GDPR rules by failing to lawfully process sensitive data.
Why this matters
This case emphasizes the importance of data minimization and responding to removal requests. Organizations must be diligent in protecting sensitive information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.
Related Enforcement Actions (0)
No other enforcement actions found for The provincial Health Authority of Enna in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
18 July 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€20,000
GDPRhub ID
gdprhub-10125About this data
Cite as: Cookie Fines. The provincial Health Authority of Enna - Italy (2026). Retrieved from cookiefines.eu
Last updated: