The provincial Health Authority of Enna – €20,000 Fine (Italy, 2026)

€20,000Garante per la protezione dei dati personali18 July 2026Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The provincial Health Authority of Enna was fined for improperly publishing a person's judicial records online. This is significant because it shows that organizations must handle sensitive information carefully. Health authorities need to follow strict rules to protect people's privacy.

What happened

The Health Authority published personal judicial data on its website without proper removal after a request.

Who was affected

A person whose judicial records were published without their consent was affected.

What the authority found

The Italian data protection authority found that the Health Authority violated GDPR rules by failing to lawfully process sensitive data.

Why this matters

This case emphasizes the importance of data minimization and responding to removal requests. Organizations must be diligent in protecting sensitive information.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 6(GDPR)
Art. 10(GDPR)
Art. 17(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
View original scraped data
Art. 5(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 6(GDPR)
Art. 10(GDPR)
Art. 17(GDPR)

Original data from scraper before AI verification against source document.

Source verified 18 July 2026
scope corrected
date discrepancy
Full Legal Summary
Detailed

The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.

Related Enforcement Actions (0)

No other enforcement actions found for The provincial Health Authority of Enna in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

18 July 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€20,000

GDPRhub ID

gdprhub-10125

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. The provincial Health Authority of Enna - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: