Back to Feed
PolicySep 8, 2026

Garante per la protezione dei dati personali (Italy) - 551/2026

Italian DPA fines Bologna University Hospital €10,000 for GDPR violations.

Summary

The Italian Data Protection Authority (Garante) fined the Bologna University Hospital IRCCS €10,000 for violating GDPR. The hospital published personal data of 96 individuals, including sensitive information potentially indicating disability, on its website as part of a recruitment process. This publication, indexed by Google, was found to breach Articles 5, 6, and 9 of the GDPR.

Full text

Help Garante per la protezione dei dati personali (Italy) - 551/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 08:40, 8 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators54 editsmTag: Visual edit← Older edit Revision as of 12:36, 8 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsTag: Visual editNewer edit → Line 99: Line 99: A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible.A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which personnel are hired from employment centres into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law.The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law. Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data.Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data. Revision as of 12:36, 8 September 2026 Garante per la protezione dei dati personali - 551/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 10000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number/Name: 551/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law. Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller further clarified that the data processed did not fall within the special category nature of Article 9 GDPR, claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that they have taken measures to prevent such unlawful processing from happening again. Holding The DPA held that the controller’s reference to national law was irrelevant given the fact that the requirement does not apply to the publishing of ineligible candidates carried out through the placement of individuals registered on employment lists. The DPA clarified that this law applies to the final rankings of the eligible candidates who were not selected as part of a competitive selection procedure, which was not the case. Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA found that the mere fact that participating in such a procedure could lead to inference of special category data which may have adverse effects on the data subject, makes the publication of such unlawful in light of Article 9 GDPR. The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of Article 5 GDPR, Article 6 GDPR and Article 9 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10287326] Decision of July 23, 2026 Register of Decisions No. 551 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the process

Entities

Google (vendor)Bologna University Hospital IRCCS (product)