[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWiR-IvpyuDgMnKSOWtTM8nL5y2pPGFn3beXKB9p5HQQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"ee055982-3276-436e-abd0-f77f08c940f9","italian-red-cross-fined-for-exposing-hiv-status-on-meal-tray-note","04f03ad1-4da0-417f-a6d4-c5db551159c5","Italian Red Cross Fined for Exposing HIV Status on Meal Tray Note","The Italian Red Cross violated GDPR by disclosing a patient's HIV status alongside their full name on a physical meal tray label — a deeply sensitive piece of special category health data exposed in a wholly unnecessary and insecure manner. The root cause was a failure to apply data minimization principles and a lack of staff awareness regarding the legal obligations around processing sensitive medical information. This case demonstrates that data protection failures are not limited to digital systems; paper-based and operational processes carry equal legal and ethical weight. Even well-intentioned operational shortcuts — such as labeling trays with diagnostic information — can constitute serious GDPR violations when proper safeguards are absent.","**Immediate actions:**\n- Audit all physical and paper-based processes that involve patient data to identify unnecessary exposure of special category information.\n- Replace any operational labels or documents containing sensitive health data with anonymized or coded identifiers that staff can cross-reference securely.\n\n**Long-term improvements:**\n- Implement mandatory GDPR training for all staff — including non-IT personnel such as catering, nursing, and administrative teams — focused on special category data handling.\n- Establish and enforce a data minimization policy requiring formal justification before any sensitive personal data is included in operational communications or documents.\n- Develop role-specific data handling procedures that translate GDPR obligations into clear, practical instructions for frontline workers.\n\n**Detection & Compliance measures:**\n- Conduct periodic Data Protection Impact Assessments (DPIAs) for operational workflows that involve patient data, including catering, transport, and logistics.\n- Appoint or empower a Data Protection Officer (DPO) to perform regular spot-checks on physical data handling practices across all departments.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 9 — Processing of special categories of personal data","GDPR Article 5(1)(c) — Data minimisation principle","GDPR Article 5(1)(f) — Integrity and confidentiality principle","GDPR Article 25 — Data protection by design and by default","GDPR Article 32 — Security of processing","NIST SP 800-53 MP-3 (Media Marking)","NIST SP 800-53 AT-2 (Literacy Training and Awareness)","CIS Control 3 — Data Protection","CIS Control 14 — Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 Annex A 5.34 — Privacy and protection of personally identifiable information","published","2026-07-07T10:20:34.374916+00:00","2026-07-07T10:20:34.046+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_385\u002F2026&diff=52073&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-385-2026-073707","Garante per la protezione dei dati personali (Italy) - 385\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]