Cluster S.r.l. – €18,000 Fine (Italy, 2023)

€18,000Garante per la protezione dei dati personali16 November 2023Italy
final
ePrivacy
Fine

Cluster S.r.l. was fined €18,000 for publishing sensitive health-related information without proper consent. This is important because it shows that companies must protect personal information, especially sensitive data like health records. Failing to do so can lead to serious consequences.

What happened

Cluster S.r.l. published health-related data and personal information without sufficient anonymization.

Who was affected

A person whose health-related data and personal information were published online was affected.

What the authority found

The Italian data protection authority found that Cluster S.r.l. violated GDPR by not adequately protecting personal data.

Why this matters

This ruling emphasizes the need for companies to ensure they have strong privacy protections in place, particularly when handling sensitive information. It serves as a warning that inadequate safeguards can lead to fines and reputational damage.

GDPR Articles Cited

Art. 5(1)(f) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Full Legal Summary
Detailed

The Italian DPA imposed a fine of EUR 18,000 on Cluster S-r.l. A data subject had complained to the DPA because their son's health-related data and their own personal data had been published on the internet. The controller had organized a medical training event at which documents containing personal data of the data subject and their deceased son were forwarded to the participants without sufficient anonymization. Some documents were later published on the internet by a third party.

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Cluster S.r.l. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 November 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€18,000

Enforcement Tracker ID

ETid-2165

GDPRhub ID

gdprhub-7436

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Cluster S.r.l. - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: