Italian DPA Fines Il Fatto Quotidiano for Publishing Sensitive Personal Health Data
Il Fatto Quotidiano published an article containing detailed personal and health information about a data subject without adequate legal basis, violating core GDPR principles of lawfulness, fairness, and data minimization. The newspaper's initial refusal to remove the content — citing public interest — demonstrates a misapplication of journalistic exemptions under GDPR, which do not grant unlimited license to publish sensitive special-category data. Only after regulatory intervention did the outlet de-index the article, highlighting a reactive rather than proactive approach to data subject rights. This case underscores that media organizations processing personal data are not exempt from GDPR obligations and must carefully balance freedom of expression against individuals' privacy rights. Failure to embed privacy-by-design thinking into editorial workflows exposes organizations to regulatory sanctions and reputational harm.
Tactical Insight
Immediate actions
- Establish a clear takedown and data subject request procedure that editorial and legal teams must follow within GDPR-mandated timeframes.
- Conduct a rapid audit of published content containing special-category data (health, biometric, etc.) to assess whether lawful basis and necessity can be justified.
Editorial & compliance controls
- Implement a pre-publication privacy review checklist requiring editors to confirm lawful basis, necessity, and proportionality before publishing articles containing personal or health information.
- Train all editorial staff on GDPR Article 9 restrictions for special-category data and the limits of the journalistic/public-interest exemption under Article 85.
- Appoint or empower a Data Protection Officer (DPO) with authority to review and, if necessary, halt publication of legally risky content.
Long-term improvements
- Adopt a Data Protection Impact Assessment (DPIA) process for articles involving sensitive personal data about private individuals.
- Integrate data minimization principles into style guides so that only information strictly necessary to the public-interest narrative is included in published articles.
- Establish a periodic retrospective review of archived articles to identify and remediate content that no longer meets GDPR lawfulness requirements.