Garante per la protezione dei dati personali (Italy) - 616/2026
Italy's Garante fines healthcare agency €24,000 for inadequate access controls to patient records.
Summary
Italy's Garante per la protezione dei dati personali has fined the Azienda sanitaria universitaria Friuli centrale €24,000 for inadequate configuration of access to electronic health records. The agency allowed unauthorized access to patient data for shift scheduling purposes, violating multiple GDPR articles related to data minimization, purpose limitation, and security. The Garante emphasized that access should be strictly limited to those involved in patient care.
Full text
Help Garante per la protezione dei dati personali (Italy) - 616/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:04, 14 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:04, 14 September 2026 Garante per la protezione dei dati personali - 616/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 9 GDPR Article 25 GDPR Article 32 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 24000.0 EUR Parties: Azienda sanitaria universitaria Friuli centrale National Case Number/Name: 616/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of Article 5(1)(a), (b), (c) and (f), Article 9, Article 25 and Article 32 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The data subject complained about a few activities of the controller: - The access of her medical records, for the purpose of verifying whether she had Covid-19 in order to schedule her shifts. - The access to her medical records by individuals who were not caring for the data subject, through a reservation system. - The ability for healthcare professionals to access medical records from other healthcare facilities. - The ability for healthcare professionals to access all records from the surgical department regardless of whether they are treating the patient. - The lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. The controller underscored that the purpose of such verification was to comply with the requirement that the shift schedule be finalised by the 20th of each month. In this regard it was underlined that on the day that the data subject’s records were accessed, she was already admitted for treatment. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Holding The DPA found the fact that the data subject was already admitted for treatment at the time that her file was accessed was irrelevant because the access actually had nothing to do with her treatment, but rather for the management of the schedule of shifts. Emphasis was placed by the DPA on the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. This would ensure data minimisation, allowing employees to access the data that is essential for their tasks and nothing more. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Similarly, the reference to the large number of staff on duty was found to be invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing nor alters of such. The DPA found that the controller insufficiently relies on after the fact complaints by data subjects, and does not have a system of conducting random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too. In light of the foregoing, the DPA found the controller in violation of Articles 5(1)(a), (b), (c), and (f), Article 9, Article 25 and Article 32 GDPR and correspondingly imposed a fine of €24.000 on them. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Newsletter of September 11, 2026 [Web Doc. No. 10293994] Decision of September 3, 2026 Register of Decisions No. 616 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, members; and Attorney Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, the “General Data Protection Regulation” (hereinafter the “Regulation”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO the “Guidelines on Health Records” adopted by the Data Protection Authority on June 4, 2015 (Decision published in the Official Gazette No. 164 of July 17, 2015, web doc. No. 4084632); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); HAVING CONSIDERED the documentation on file; HAVING REGARD TO the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the Office of the Data Protection Authority, available at www.gpdp.it, web doc. No. 1098801; Rapporteur: Prof. Ginevra Cerrina Feroni; WHEREAS 1. FACTS AND COURSE OF THE PRELIMINARY INVESTIGATION 1.1 Origin of the preliminary investigation The Authority received a complaint from XX alleging multiple violations of the regulations governing the processing of personal data carried out by the Friuli Centrale University Health Authority (ASUFC) through the institutional health record. In particular, the main complaint