Back to all lessons
Awareness Lessons
last month

Italian Hospital Fined for Publishing Sensitive Candidate Data Online

Bologna University Hospital IRCCS violated GDPR by publicly posting a candidate eligibility list on its website, which was subsequently indexed by Google, exposing individuals' names alongside information that could be associated with disability status. The root cause was a failure to apply data minimisation and purpose limitation principles before publishing the document, combined with inadequate web publishing controls that allowed sensitive content to be crawled by search engines. This matters because even well-intentioned administrative transparency can constitute unlawful processing when sensitive categories of personal data are unnecessarily exposed to the public. Healthcare organisations must recognise that publishing selection or eligibility outcomes online creates compounded risk when those outcomes implicitly reveal health or disability-related information.

Tactical Insight

Immediate actions

  • Audit all publicly accessible web pages and documents for inadvertent exposure of personal or sensitive data and remove or redact non-compliant content immediately.
  • Submit removal requests to search engines (e.g., Google Search Console) for any already-indexed sensitive documents to suppress cached copies.

Policy & governance improvements

  • Establish a mandatory Data Protection Impact Assessment (DPIA) process before publishing any candidate lists, eligibility outcomes, or selection results online.
  • Define a data minimisation policy for public disclosures that restricts publication to only the information legally required, replacing full names with anonymised or pseudonymised identifiers where possible.
  • Assign a named data owner responsible for reviewing and approving all web publications involving personal data prior to release.

Technical controls

  • Configure web servers to include appropriate `robots.txt` directives and `X-Robots-Tag` headers to prevent sensitive administrative pages from being indexed by search engines.
  • Implement access controls (e.g., authenticated portals) for disclosures that must reach specific individuals rather than publishing them on open public web pages.