Garante per la protezione dei dati personali (Italy) - 551/2026
Italian DPA fines Bologna University Hospital for GDPR violations in candidate selection.
Summary
The Italian Data Protection Authority (Garante per la protezione dei dati personali) fined the Bologna University Hospital IRCCS for violating GDPR Articles 5, 6, and 9. The hospital published a list of candidates' names and eligibility status for an income-based selection process on its website, which was also indexed by Google. The DPA found this processing violated data protection principles, particularly by potentially associating individuals with sensitive data like disability.
Full text
Help Garante per la protezione dei dati personali (Italy) - 551/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 12:36, 8 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsTag: Visual edit← Older edit Revision as of 13:04, 8 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsTag: Visual editNewer edit → Line 97: Line 97: === Facts ====== Facts === A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible.The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based selection process. The data was also indexed on Google. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law.A data subject who was deemed ineligible lodged a complaint with the DPA. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data.Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data. Revision as of 13:04, 8 September 2026 Garante per la protezione dei dati personali - 551/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 10000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number/Name: 551/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based selection process. The data was also indexed on Google. A data subject who was deemed ineligible lodged a complaint with the DPA. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller further clarified that the data processed did not fall within the special category nature of Article 9 GDPR, claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that they have taken measures to prevent such unlawful processing from happening again. Holding The DPA held that the controller’s reference to national law was irrelevant given the fact that the requirement does not apply to the publishing of ineligible candidates carried out through the placement of individuals registered on employment lists. The DPA clarified that this law applies to the final rankings of the eligible candidates who were not selected as part of a competitive selection procedure, which was not the case. Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA found that the mere fact that participating in such a procedure could lead to inference of special category data which may have adverse effects on the data subject, makes the publication of such unlawful in light of Article 9 GDPR. The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of Article 5 GDPR, Article 6 GDPR and Article 9 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10287326] Decision of July 23, 2026 Register of Decisions No. 551 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “Code”); HAVING REGARD TO Regu