Italian Hospital Fined €10,000 for Publishing Sensitive Candidate Data Online for Five Years
Bologna University Hospital IRCCS published personal data of ineligible job candidates on its public website without a lawful basis, exposing sensitive information for five years before removal. The core failure was the absence of a proper legal justification under GDPR Articles 5, 6, and 9 for processing and publicly disclosing data that could infer special category (sensitive) information. This case highlights how data minimisation and purpose limitation principles are routinely overlooked when publishing administrative or HR-related documents online. The five-year exposure window also indicates a lack of periodic data audits and lifecycle management processes. Even inadvertent or administrative disclosures can constitute serious GDPR violations carrying financial and reputational consequences.
Tactical Insight
Immediate actions
- Conduct a full audit of all publicly accessible web pages to identify and remove any personal or sensitive data lacking a clear legal basis.
- Establish an emergency takedown procedure so improperly published data can be removed within 24–48 hours of discovery.
Long-term improvements
- Implement a formal data publication review process requiring Data Protection Officer (DPO) sign-off before any personal data is made publicly available.
- Apply data minimisation principles to all HR and administrative publications, publishing only aggregated or anonymised results where individual identification is not required.
- Define and enforce data retention schedules for all publicly posted documents, with automated expiry or periodic review triggers.
Detection & monitoring measures
- Schedule quarterly web content audits to detect lingering personal data that has outlived its legal basis.
- Deploy web-crawling or content-scanning tools to flag pages containing personal identifiers (names, ID numbers, dates of birth) on public-facing infrastructure.