Back to all lessons
Awareness Lessons
last month

Italian Hospital Fined €10,000 for Unlawfully Publishing Sensitive Personal Data Online

Bologna University Hospital IRCCS violated GDPR by publishing individuals' personal data — including disability-related eligibility status — on its public website without a valid legal basis, where it was subsequently indexed by Google. The root cause reflects a failure in data governance: staff responsible for publishing content did not assess whether a lawful basis existed before making sensitive data publicly accessible. This matters because health and disability-related data constitutes a special category under GDPR Article 9, attracting stricter protections and higher regulatory scrutiny. The incident demonstrates that public-sector organizations must treat web publication as a data processing activity requiring the same rigorous legal review as any other form of data sharing.

Tactical Insight

Immediate actions

  • Audit all publicly accessible web pages for personal or sensitive data and remove any content lacking a documented legal basis.
  • Submit removal requests to search engine operators (e.g., Google Search Console) for any indexed pages containing personal data published in error.

Process & governance improvements

  • Establish a mandatory Data Protection Impact Assessment (DPIA) review gate before any personal data is published on public-facing systems.
  • Define and enforce a content approval workflow requiring DPO sign-off for any online publication involving personal, health, or disability-related data.
  • Maintain a Record of Processing Activities (RoPA) entry for every category of data published online, explicitly documenting the legal basis under GDPR Article 6 and Article 9.

Long-term improvements

  • Deliver targeted GDPR training for HR, communications, and administrative staff who manage public procurement or selection process results.
  • Implement automated web-crawling tools to continuously detect and alert on unexpected personal data exposure across the organization's digital properties.
  • Adopt a 'privacy by default' configuration standard requiring that all new web content be private until explicitly approved for public release.