[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9RHqj6pBPMnojYrS0Jmn-H1QiocrAwTYyGkcyi91dkc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"3b9384d7-8016-44c7-8dfc-157b1013ec37","italian-dpa-fines-il-fatto-quotidiano-for-publishing-sensitive-personal-health-data","0aff1238-4804-494b-9d7b-73c4d039b365","Italian DPA Fines Il Fatto Quotidiano for Publishing Sensitive Personal Health Data","Il Fatto Quotidiano published an article containing detailed personal and health information about a data subject without adequate legal basis, violating core GDPR principles of lawfulness, fairness, and data minimization. The newspaper's initial refusal to remove the content — citing public interest — demonstrates a misapplication of journalistic exemptions under GDPR, which do not grant unlimited license to publish sensitive special-category data. Only after regulatory intervention did the outlet de-index the article, highlighting a reactive rather than proactive approach to data subject rights. This case underscores that media organizations processing personal data are not exempt from GDPR obligations and must carefully balance freedom of expression against individuals' privacy rights. Failure to embed privacy-by-design thinking into editorial workflows exposes organizations to regulatory sanctions and reputational harm.","**Immediate actions:**\n- Establish a clear takedown and data subject request procedure that editorial and legal teams must follow within GDPR-mandated timeframes.\n- Conduct a rapid audit of published content containing special-category data (health, biometric, etc.) to assess whether lawful basis and necessity can be justified.\n\n**Editorial & compliance controls:**\n- Implement a pre-publication privacy review checklist requiring editors to confirm lawful basis, necessity, and proportionality before publishing articles containing personal or health information.\n- Train all editorial staff on GDPR Article 9 restrictions for special-category data and the limits of the journalistic\u002Fpublic-interest exemption under Article 85.\n- Appoint or empower a Data Protection Officer (DPO) with authority to review and, if necessary, halt publication of legally risky content.\n\n**Long-term improvements:**\n- Adopt a Data Protection Impact Assessment (DPIA) process for articles involving sensitive personal data about private individuals.\n- Integrate data minimization principles into style guides so that only information strictly necessary to the public-interest narrative is included in published articles.\n- Establish a periodic retrospective review of archived articles to identify and remediate content that no longer meets GDPR lawfulness requirements.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 17 – Right to erasure ('right to be forgotten')","GDPR Article 85 – Processing and freedom of expression and information","NIST Privacy Framework PR.PO-P1 – Policies, processes, and procedures for data handling","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","ISO\u002FIEC 29101 – Privacy Architecture Framework","ITIL Service Design – Information Security Management (data handling policies)","published","2026-08-25T12:20:56.264393+00:00","2026-08-25T12:20:56.17+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_491\u002F2026&diff=52776&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-491-2026-07167b","Garante per la protezione dei dati personali (Italy) - 491\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]