[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn4AIbLSDdXAOXnmIUmIrgl1zjjzxIITmpYCujgKpGkA":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"160a295c-b252-4e5a-9e30-a36698c22cc1","Garante per la protezione dei dati personali (Italy) - 616\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-616-2026-91bc1f","← Older revision Revision as of 08:10, 16 September 2026 Line 113: Line 113: === Facts === === Facts === The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA received a complaint from an employee (the data subject) of the University Health Agency of Friuli Centrale (the controller) concerning the controller's processing of the electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. Line 121: Line 121: Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. === Holding === === Holding === The DPA insisted on the principle of data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. The DPA found a violation of the principle of data minimisation by the controller, as there were no restrictions limiting the access by employees to electronic health records solely to those involved with the patients care. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Moreover, the DPA found the controller's data protection by design and default inadequate, particularly the automatic locking mechanism. It held that the period of inactivity chosen did not take into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Similarly, the reference to the large number of staff on duty was found invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. The DPA further emphasised that the systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access and ensure a level of security appropriate to the posed risk. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing. The DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too. Finally, the DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks, as a mechanism deterring unauthorised access. In light of the foregoing, the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a), (b), (c), and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them. In light of the foregoing, the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a), (b), (c), and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them.","The Italian Data Protection Authority (Garante) has fined the University Health Agency of Friuli Centrale €24,000 for violations related to its electronic health record system. The agency failed to adequately restrict access to patient data, particularly Covid-19 results and surgical department information, to only those directly involved in patient care. Additionally, the DPA found that the system's automatic computer lockout mechanism had an inappropriate inactivity period, and the agency lacked a system for detecting anomalous processing activities.","Italian DPA fines healthcare agency €24,000 for data minimization and access control violations.","Help Garante per la protezione dei dati personali (Italy) - 616\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:23, 15 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators421 editsTag: Visual edit← Older edit Latest revision as of 08:10, 16 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators74 editsmTag: Visual edit Line 113: Line 113: === Facts ====== Facts === The DPA received a complaint from a data subject concerning the processing operations of the University Health Agency of Friuli Centrale’s (the controller) electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA received a complaint from an employee (the data subject) of the University Health Agency of Friuli Centrale (the controller) concerning the controller's processing of the electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward.The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The controller deemed the use of these verification methods justified as it was the only method to quickly ensure a negative test and allow the data subject access to a ward. Line 121: Line 121: Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. Moreover, the controller addressed the upcoming implementation of a system which detects anomalies, and that given the number of staff on duty, especially in emergency room areas, it is plausible to assume that the person who viewed the list of the data subject’s documents would have been able to gain access even if a shorter automatic lockout period was implemented. With this the controller addressed their systemic vulnerability to malicious conduct by employees. === Holding ====== Holding === The DPA insisted on the principle of data minimisation, the risk of unauthorised access and the necessity of imposing restrictions to limit the access to electronic health records solely to those involved with the patients care, and not those in administrative positions. The DPA found a violation of the principle of data minimisation by the controller, as there were no restrictions limiting the access by employees to electronic health records solely to those involved with the patients care. The DPA found the measures implemented by the controller to ensure data protection by design and default were not adequate. Namely, as the automatic locking of the computers was not established with an appropriate inactivity period which took into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Moreover, the DPA found the controller's data protection by design and default inadequate, particularly the automatic locking mechanism. It held that the period of inactivity chosen did not take into account the nature, subject matter, context, processing purpose and risk to the rights and freedoms of data subjects. Similarly, the reference to the large number of staff on duty was found invalid by the DPA as the implementation of an automatic lockout based on the specific needs and nature of tasks would have constituted a technical measure which is suitable to ensure a level of security appropriate to the risk of unauthorised access. The systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access. The DPA further emphasised that the systemic vulnerability should have in fact prompted the controller to adopt all technical and organisational measures to reduce the risk of unauthorised access and ensure a level of security appropriate to the posed risk. Finally, the DPA found that the controller never adopted a system for automatic detection of anomalies possibly constituting unlawful processing. The DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks to electronic health record access which could have also been a mechanism to deter employees from gaining access to records that they should not have access too.Finally, the DPA found that the controller insufficiently relied on conducting checks after data subject's complain rather than implementing a system of random checks, as a mechanism deterring unauthorised access. In light of the foregoing, the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a), (b), (c), and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them.In light of the foregoing, the DPA found the controller in violation of [[Article 5 GDPR|Articles 5(1)(a), (b), (c), and (f)]], [[Article 9 GDPR|Article 9]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]] and correspondingly imposed a fine of €24.000 on them. Latest revision as of 08:10, 16 September 2026 Garante per la protezione dei dati personali - 616\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 9 GDPR Article 25 GDPR Article 32 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 24000.0 EUR Parties: Azienda sanitaria universitaria Friuli centrale National Case Number\u002FName: 616\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €24,000 for having an inadequate configuration of access to electronic health records, which resulted in unlawful processing of the data subject’s personal data in violation of Article 5(1)(a), (b), (c) and (f), Article 9, Article 25 and Article 32 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from an employee (the data subject) of the University Health Agency of Friuli Centrale (the controller) concerning the controller's processing of the electronic health record system. The complaint related in particular to access by the controller, its staff and other healthcare professionals from other facilities to Covid-19 results and surgical department data. It also concerned the lack of access logs. The DPA initiated an investigation. The controller highlighted the exceptional circumstances of Covid-19, and the difficulties of organisational management of healthcare facilities. The con","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_616\u002F2026&diff=53086&oldid=53036","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-16T08:10:43+00:00","2026-09-16T10:00:21.147411+00:00",7,[18,21],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor",{"name":22,"type":23},"electronic health record system","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,37],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]