Azienda Unità Sanitaria Locale Toscana Sud Est – €100,000 Fine (Italy, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Azienda USL Toscana Sud Est was fined for not properly informing patients about how their health data would be used and stored. The company failed to protect sensitive health information and did not conduct necessary assessments. The €100,000 fine serves as a warning for healthcare providers to improve their data handling practices.
What happened
Azienda USL Toscana Sud Est was fined for multiple violations related to the handling of patient health data.
Who was affected
Patients whose health data was processed without adequate information and protection measures.
What the authority found
The authority imposed a €100,000 fine for failing to inform patients about their data rights and for not implementing proper data protection measures.
Why this matters
This case underscores the critical need for healthcare organizations to prioritize patient data protection and transparency. It serves as a reminder that all businesses must comply with data protection laws to avoid penalties.
GDPR Articles Cited
The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the so-called 'Sanità di iniziativa' (Health Initiative) program. Within the framework of this program, participating healthcare companies transmit data on chronically ill patients to the controller. On the basis of this data, the controller then develops health plans for the patients. The Italian DPA notes several violations of data protection provisions related to this program. For example, when giving consent to the processing of their data, the data subjects were not adequately informed about how long their data would be stored, what rights they had (in particular their rights of complaint and access), and how exactly their data would be processed and for what purpose. In addition, the controller had not kept a register of processing activities. Finally, the controller had neither implemented adequate technical and organizational measures to protect the processing nor conducted a data protection impact assessment, although this would have been necessary due to the nature of the data processed (health data).
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving Azienda Unità Sanitaria Locale Toscana Sud Est in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
17 December 2020
Authority
Garante per la protezione dei dati personali
Fine Amount
€100,000
Enforcement Tracker ID
ETid-539
About this data
Cite as: Cookie Fines. Azienda Unità Sanitaria Locale Toscana Sud Est - Italy (2020). Retrieved from cookiefines.eu
Last updated: