Back to Feed
PolicySep 22, 2026

Garante per la protezione dei dati personali (Italy) - 550/2026

Italy's Garante fines Bologna University Hospital €30,000 for unlawful data disclosure.

Summary

Italy's data protection authority, the Garante, has fined the Bologna University Hospital IRCCS €30,000 for unlawfully disclosing the personal data of approximately 700 individuals. The hospital published a ranking list on its website as part of a recruitment procedure, which included personal data and was indexed for five years. The Garante found that the hospital could not sufficiently identify a legal basis for this disclosure and that it violated GDPR principles of lawfulness, fairness, transparency, and data minimization.

Full text

Help Garante per la protezione dei dati personali (Italy) - 550/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 07:00, 22 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators83 edits Tag: Decisions [1.0] (No difference) Latest revision as of 07:00, 22 September 2026 Garante per la protezione dei dati personali - 550/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 30000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number/Name: 550/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the controller €30,000 for unlawfully disclosing the personal data of 700 individuals, by publishing a ranking list as part of a recruitment procedure, on their website. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the controller). The data subject had requested the erasure of her personal data present in the ranking list, and de-indexing from search engines, as the list appears with the google of the data subjects first and last name. The data subject is on complainant amongst approximately 700 individuals whose names got published. The controller responded in time, however refused erasure. This was justified by the necessary transparency requirements embedded in national law. In accordance with the law, the controller had established a 5-year disclosure period of the rankings of candidates which were admitted to the recruitment procedure. The controller emphasised that this procedure did not include the assessment of worker’s suitability to perform the duties. Rather the procedure consisted of a comparative assessment of qualifications. Furthermore, the controller clarified that this procedure two public administrations are hired and conduct two independent and separate procedures. After the first procedure is completed, a ranking list, based solely on qualifications is generated. The list is then reviewed, and once it is approved, it is published and forwarded to the entity responsible for the distinct hiring process. Holding The DPA held that the controller was unable sufficiently identify a legal basis which allowed for the publication of the ranking list and the subsequent indexing for 5-years. Reference made by the controller, to national law, was not applicable to the recruitment procedure in the case at hand, as it only covered competitive selection procedures. Furthermore, the DPA held that whilst it was not possible to determine, based on the ranking list, the reason for participation by the individuals and data subject. The mere fact that participating, may lead to the inference of the data health status, makes this data fall under special category data. Correspondingly, requiring a higher level of protection. Similarly, the DPA found that even where the disclosure of personal data reveals sensitive economic or social aspects, could have adverse effects on data subjects, compromising their dignity. The DPA found that this constituted unlawful disclosure of personal data, and was contrary to the principles of lawfulness, fairness and transparency, data minimisation. The DPA found the controller in violation of Articles 5, 6, 9 GDPR, and imposed a €30,000 fine on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Newsletter of September 11, 2026 [Web Doc. No. 10287084] Decision of July 23, 2026 Register of Decisions No. 550 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having reviewed the documentation on file; Having considered the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Prof. Pasquale Stanzione; PREAMBLE 1. Introduction. A complaint was filed pursuant to Article 77 of the Regulation—following the approval by the Emilia-Romagna Regional Employment Agency (hereinafter “Regional Agency”) of a ranking list as part of a procedure initiated pursuant to Art. 16 of Law No. 56 of 1987 for the permanent hiring of a technical receptionist at the IRCCS University Hospital of Bologna, Sant’Orsola Polyclinic—the complainant represented that she had requested the “erasure of [her] data [contained in the aforementioned ranking list] as well as de-indexing from search engines. […since] when typing [her] first and last name into Google, the ranking in question appears along with its position. […] The Agency refused to delete the data from that procedure, […citing] alleged transparency requirements imposed by law.” Based on the information provided by the complainant and following the Office’s investigation, it was confirmed that the decision titled “REGION OF EMILIA-ROMAGNA Administrative Acts EMPLOYMENT AGENCY Act of the Director DECISION No. XX of XX BOLOGNA,” containing the names of those enrolled in the aforementioned procedure, had been published online. 2. The Preliminary Investigation. As part of the preliminary investigation, the Regional Agency, in a note dated XX, stated, in particular, that: - “By Decision No. XX of XX, the Regional Employment Agency approved the ‘Public Notice of the Initiation of a Selection Process in the Public Administration pursuant to Art. 16 of Law No. 56/1987 at the University Hospital of Bologna – IRCCS - Sant’Orsola Polyclinic, for 10 positions as technical reception staff, Category B, permanent—full-time”; - “This was followed by Resolution No. XX of XX concerning the “Approval of the ranking list for the recruitment process in the public administration pursuant to Art. 16 of Law No. 56/87 for permanent, full-time positions, at the University Hospital of Bologna/IRCCS-Sant’Orsola Polyclinic for 10 positions as technical reception staff (Category B)”; - “In a communication dated XX, the dat

Entities

Garante per la protezione dei dati personali (vendor)Bologna University Hospital IRCCS (product)