[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzNvRtyDekH2Rtoy9d55fbdutFi268vbSLfREsD-2G4Y":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"e07feeb8-84f6-4201-9bf7-8c76c53a348c","Garante per la protezione dei dati personali (Italy) - 551\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-551-2026-cf9645","← Older revision Revision as of 14:47, 8 September 2026 Line 92: Line 92: }} }} The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. The DPA found the Bologna University Hospital IRCCS in violation of [[Article 5 GDPR|Articles 5]], [[Article 6 GDPR|6]], and [[Article 9 GDPR|9 GDPR]] for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. == English Summary == == English Summary ==","Italy's Garante per la protezione dei dati personali has fined the Bologna University Hospital IRCCS €10,000 for violating GDPR. The hospital published a list of candidates, including their eligibility status and potentially sensitive data, on its website and it was indexed by Google. The DPA found the publication of ineligible candidates was not covered by national law and lacked a sufficient legal basis.","Italy's DPA fines Bologna University Hospital €10,000 for GDPR violations.","Help Garante per la protezione dei dati personali (Italy) - 551\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:55, 8 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators403 editsmTag: Visual edit← Older edit Latest revision as of 14:47, 8 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators57 editsmTag: Visual edit Line 92: Line 92: }}}} The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website.The DPA found the Bologna University Hospital IRCCS in violation of [[Article 5 GDPR|Articles 5]], [[Article 6 GDPR|6]], and [[Article 9 GDPR|9 GDPR]] for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. == English Summary ==== English Summary == Latest revision as of 14:47, 8 September 2026 Garante per la protezione dei dati personali - 551\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: 10000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number\u002FName: 551\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based selection process. The data was also indexed on Google. A data subject who was deemed ineligible lodged a complaint with the DPA. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The selection procedure included questions regarding the disability status and financial situations of the applicants. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller further clarified that the data processed did not fall within the special category nature of Article 9 GDPR, claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that it had taken measures to prevent such unlawful processing from happening again. Holding The DPA held that the national law did not apply to the publishing of ineligible candidates but only of selected candidates.Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA also found that the data, together with the selection criteria which included a \"degree of invalidity\" and questions on financial situations, could infer a general condition of disability, potentially revealing sensitive personal data and information on the financial situation of the applicants. The mere participation to the selection procedure could therefore already reveal certain data, in violation of Article 9 GDPR. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of Articles 5, 6 and 9 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10287326] Decision of July 23, 2026 Register of Decisions No. 551 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1\u002F2019 concerning internal procedures with external relevance, aimed at the performance of the tasks and the exercise of the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1\u002F2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1\u002F2000 on the organization and operation of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Prof. Ginevra Cerrina Feroni; WHEREAS 1. Introduction. In a complaint filed with this Authority, a representative stated that the Bologna University Hospital IRCCS (hereinafter “the Hospital”) had published on its institutional website the complainant’s personal data “relating to a selection process based on income conducted through the employment center, the result of which—a determination of ineligibility—was published on the website and indexed on Google.” Based on the information provided by the complainant and following the investigations conducted by the Office, it was confirmed that a PDF file titled “LIST OF ELIGIBLE\u002FINELIGIBLE CANDIDATES FROM THE PRE-SELECTION LIST SUBMITTED VIA NOTE NO. XX OF XX FOR THE POSITION OF XX,” containing the names of the participants in the selection process (eligible and ineligible). 2. The Preliminary Investigation. As part of the preliminary investigation, the Hospital Authority, in a note dated XX, stated, in particular, that: - “The selection procedure in question is aimed at hiring personnel from employment centers into the public sector. As provided for in Article 35, paragraph 1, subparagraph b) of Legislative Decree No. 165\u002F2001, in fact, the initiation of a selection process pursuant to Art. 16 of Law No. 56 of February 28, 1987, constitutes a ‘recruitment procedure’ used in the public sector for the permanent o","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_551\u002F2026&diff=52969&oldid=52963","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-08T14:47:18+00:00","2026-09-08T16:00:15.186474+00:00",7,[18,21],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor",{"name":22,"type":23},"Google","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]