[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffZ6hCNpLW0NqIe7CD72HnPoMAy-ZoBPd87O-jBHK4_A":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"abf9ba84-468f-46b1-a6f6-ae8ad9f03fb9","italian-hospital-fined-10000-for-unlawfully-publishing-sensitive-personal-data-online","16e00870-a13d-42f0-bccf-b704c09768c6","Italian Hospital Fined €10,000 for Unlawfully Publishing Sensitive Personal Data Online","Bologna University Hospital IRCCS violated GDPR by publishing individuals' personal data — including disability-related eligibility status — on its public website without a valid legal basis, where it was subsequently indexed by Google. The root cause reflects a failure in data governance: staff responsible for publishing content did not assess whether a lawful basis existed before making sensitive data publicly accessible. This matters because health and disability-related data constitutes a special category under GDPR Article 9, attracting stricter protections and higher regulatory scrutiny. The incident demonstrates that public-sector organizations must treat web publication as a data processing activity requiring the same rigorous legal review as any other form of data sharing.","**Immediate actions:**\n- Audit all publicly accessible web pages for personal or sensitive data and remove any content lacking a documented legal basis.\n- Submit removal requests to search engine operators (e.g., Google Search Console) for any indexed pages containing personal data published in error.\n\n**Process & governance improvements:**\n- Establish a mandatory Data Protection Impact Assessment (DPIA) review gate before any personal data is published on public-facing systems.\n- Define and enforce a content approval workflow requiring DPO sign-off for any online publication involving personal, health, or disability-related data.\n- Maintain a Record of Processing Activities (RoPA) entry for every category of data published online, explicitly documenting the legal basis under GDPR Article 6 and Article 9.\n\n**Long-term improvements:**\n- Deliver targeted GDPR training for HR, communications, and administrative staff who manage public procurement or selection process results.\n- Implement automated web-crawling tools to continuously detect and alert on unexpected personal data exposure across the organization's digital properties.\n- Adopt a 'privacy by default' configuration standard requiring that all new web content be private until explicitly approved for public release.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 6 – Lawfulness of processing","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 25 – Data protection by design and by default","GDPR Article 35 – Data Protection Impact Assessment","NIST SP 800-53 AC-22 (Publicly Accessible Content)","NIST SP 800-53 RA-3 (Risk Assessment)","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 Annex A 5.12 – Classification of Information","ISO\u002FIEC 27701 – Privacy Information Management","published","2026-09-08T10:22:53.069213+00:00","2026-09-08T10:22:52.793+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_551\u002F2026&diff=52932&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-551-2026-450168","Garante per la protezione dei dati personali (Italy) - 551\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]