Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North – €7,000 Fine (Italy, 2025)

€7,000Garante per la protezione dei dati personali21 May 2025Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Italian data protection authority fined the Health Protection Agency of Milan EUR 7,000 for sharing health data without proper legal grounds. This is significant because it emphasizes that companies must have a valid reason to share sensitive information. Failing to do so can lead to costly fines.

What happened

The Health Protection Agency of Milan forwarded health data to an employer without a sufficient legal basis.

Who was affected

Individuals whose health data was shared without consent were affected by this action.

What the authority found

The authority found that the agency violated GDPR by not having a valid legal basis for processing personal health data.

Why this matters

This ruling underscores the need for organizations to ensure they have a proper legal basis before sharing sensitive information. Companies should review their data-sharing practices to comply with privacy laws.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 5(1)(c) GDPR
View original scraped data
Art. 5(1) c) GDPR
f) GDPR
Art. 9(GDPR)

Original data from scraper before AI verification against source document.

Source verified 14 March 2026
national law identified
Full Legal Summary
Detailed

The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller forwarded health data of a data subject to their employer without a sufficient legal basis.

Related Enforcement Actions (0)

No other enforcement actions found for Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

21 May 2025

Authority

Garante per la protezione dei dati personali

Fine Amount

€7,000

Enforcement Tracker ID

ETid-2752

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North - Italy (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: