Italian Hospital Fined €10,000 for Publishing Sensitive Recruitment Data Online
Bologna University Hospital IRCCS violated GDPR by publishing personal and sensitive data — including information potentially indicating disability — of 96 individuals on its public website during a recruitment process. The data was indexed by Google, dramatically amplifying its exposure and making removal more complex. This breach highlights the failure to apply data minimisation and purpose limitation principles before publishing documents online. The incident matters because sensitive health-related data carries the highest level of GDPR protection under Article 9, and organisations handling such data must implement rigorous review processes before any public disclosure.
Tactical Insight
Immediate actions
- Remove any publicly accessible documents containing personal or sensitive data and submit de-indexing requests to search engines immediately.
- Conduct an emergency audit of all web-published recruitment, HR, and administrative documents to identify further exposure.
Policy & Process improvements
- Establish a mandatory pre-publication review checklist that requires data minimisation and redaction of personal/sensitive data before any document is posted online.
- Define a clear legal basis and data category assessment (including Article 9 special categories) for every type of data published as part of recruitment processes.
- Train HR and administrative staff on GDPR obligations, specifically around lawful processing, data minimisation, and the heightened protection required for sensitive data.
Detection & Monitoring measures
- Implement automated website content scanning tools to detect and alert on the presence of personal identifiers or sensitive data in publicly accessible files.
- Set up regular scheduled reviews of all publicly indexed organisational web content to catch accidental data exposure before it is reported externally.