[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9k4WCVj_w_v3YZTSVq9MdeGK9Rk3S8z4FBp_zkOLIWw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"1bc6d979-6c72-41f8-93c1-2e6b1b4e9237","italian-hospital-fined-for-publishing-sensitive-candidate-data-online","0a982b17-8cc3-4b77-ba11-4b0ffebb432c","Italian Hospital Fined for Publishing Sensitive Candidate Data Online","Bologna University Hospital IRCCS violated GDPR by publicly posting a candidate eligibility list on its website, which was subsequently indexed by Google, exposing individuals' names alongside information that could be associated with disability status. The root cause was a failure to apply data minimisation and purpose limitation principles before publishing the document, combined with inadequate web publishing controls that allowed sensitive content to be crawled by search engines. This matters because even well-intentioned administrative transparency can constitute unlawful processing when sensitive categories of personal data are unnecessarily exposed to the public. Healthcare organisations must recognise that publishing selection or eligibility outcomes online creates compounded risk when those outcomes implicitly reveal health or disability-related information.","**Immediate actions:**\n- Audit all publicly accessible web pages and documents for inadvertent exposure of personal or sensitive data and remove or redact non-compliant content immediately.\n- Submit removal requests to search engines (e.g., Google Search Console) for any already-indexed sensitive documents to suppress cached copies.\n\n**Policy & governance improvements:**\n- Establish a mandatory Data Protection Impact Assessment (DPIA) process before publishing any candidate lists, eligibility outcomes, or selection results online.\n- Define a data minimisation policy for public disclosures that restricts publication to only the information legally required, replacing full names with anonymised or pseudonymised identifiers where possible.\n- Assign a named data owner responsible for reviewing and approving all web publications involving personal data prior to release.\n\n**Technical controls:**\n- Configure web servers to include appropriate `robots.txt` directives and `X-Robots-Tag` headers to prevent sensitive administrative pages from being indexed by search engines.\n- Implement access controls (e.g., authenticated portals) for disclosures that must reach specific individuals rather than publishing them on open public web pages.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 6 – Lawfulness of processing","GDPR Article 9 – Processing of special categories of personal data","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 RA-3 – Risk Assessment","CIS Control 3 – Data Protection","CIS Control 4 – Secure Configuration of Enterprise Assets and Software","ISO\u002FIEC 27001:2022 A.5.34 – Privacy and protection of personally identifiable information","ITIL – Change Management (review of service changes impacting data exposure)","published","2026-09-08T14:21:19.424461+00:00","2026-09-08T14:21:19.304+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_551\u002F2026&diff=52956&oldid=52951","garante-per-la-protezione-dei-dati-personali-italy-551-2026-a79ce7","Garante per la protezione dei dati personali (Italy) - 551\u002F2026",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]