Italian Hospital Fined €10,000 for Unlawfully Publishing Sensitive Personal Data Online
Bologna University Hospital IRCCS violated GDPR by publishing individuals' personal data — including disability-related eligibility status — on its public website without a valid legal basis, where it was subsequently indexed by Google. The root cause reflects a failure in data governance: staff responsible for publishing content did not assess whether a lawful basis existed before making sensitive data publicly accessible. This matters because health and disability-related data constitutes a special category under GDPR Article 9, attracting stricter protections and higher regulatory scrutiny. The incident demonstrates that public-sector organizations must treat web publication as a data processing activity requiring the same rigorous legal review as any other form of data sharing.
Tactical Insight
Immediate actions
- Audit all publicly accessible web pages for personal or sensitive data and remove any content lacking a documented legal basis.
- Submit removal requests to search engine operators (e.g., Google Search Console) for any indexed pages containing personal data published in error.
Process & governance improvements
- Establish a mandatory Data Protection Impact Assessment (DPIA) review gate before any personal data is published on public-facing systems.
- Define and enforce a content approval workflow requiring DPO sign-off for any online publication involving personal, health, or disability-related data.
- Maintain a Record of Processing Activities (RoPA) entry for every category of data published online, explicitly documenting the legal basis under GDPR Article 6 and Article 9.
Long-term improvements
- Deliver targeted GDPR training for HR, communications, and administrative staff who manage public procurement or selection process results.
- Implement automated web-crawling tools to continuously detect and alert on unexpected personal data exposure across the organization's digital properties.
- Adopt a 'privacy by default' configuration standard requiring that all new web content be private until explicitly approved for public release.