Garante per la protezione dei dati personali (Italy) - 10254256
Italy's DPA fines Ministry of Justice €12,000 for posting employee's medical details publicly.
Summary
Italy's Garante per la protezione dei dati personali has fined the Ministry of Justice €12,000 for unlawfully disclosing an employee's health data. The data subject's service order, which included references to their physical conditions and need for posture alternation, was posted on a canteen bulletin board accessible to all staff. The DPA ruled this constituted a violation of GDPR, classifying the information as health data.
Full text
Help Garante per la protezione dei dati personali (Italy) - 10254256: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 11:51, 20 July 2026 view source Ligialagev (talk | contribs)38 edits Tag: submission [1.0]Newer edit → (No difference) Revision as of 11:51, 20 July 2026 Garante per la protezione dei dati personali - 10254256 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 4(9) GDPR Article 4(10) GDPR Article 4(15) GDPR Article 4(15) GDPR Article 5(1)(a) GDPR Article 6 GDPR Article 9 GDPR Article 28(3)(b) GDPR 2 ter Type: Complaint Outcome: Upheld Started: Decided: Published: 29.04.2026 Fine: 12,000 EUR Parties: Ministry of Justice National Case Number/Name: 10254256 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: ligialagev The DPA fined a ministry €12,000 for including medical details of a data subject in its canteen area's bulletin board. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relaxation area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff, particularly since the assignment had been made in excess of the available posts. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [web doc. no. 10254256] Provision of April 29, 2026 Register of Provisions No. 304 of April 29, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the f