The Italian authority imposes a €20,000 fine on Azienda Sanitaria Provinciale di Enna for unlawful dissemination of judicial personal data

The Italian data protection authority sanctions a health organization for the online publication of judicial data without legal basis and for not effectively erasing this data following the request of the data subject, as the data remained inadvertently accessible in another section of the site.

Facts and context

The Italian data protection authority, the Garantor for the Protection of Personal Data (GPDP), has today published a sanction decision against the Azienda Sanitaria Provinciale di Enna (including the imposition of a €20,000 fine) for breaches related to the unlawful dissemination of judicial data and failure to comply with a deletion request.

The case originated from a complaint by a natural person concerning the online publication, in an administrative resolution, of data relating to judicial proceedings concerning them.

Reasons for the decision

The authority found several GDPR violations against the organization:

  • Obligation of lawfulness, fairness, transparency, and data minimization (Article 5 of the GDPR): The authority judged that the publication of judicial data in an online resolution, without necessary justification, violated the minimization principle. The dissemination of this information, irrelevant to the purpose of publishing the act, was also contrary to the principles of lawfulness and fairness, as recalled by the GPDP 2014 guidelines on transparency of public administrations.
  • Obligation to have a legal basis for processing (Article 6 of the GDPR): The authority found that the public body could not demonstrate the existence of a valid legal basis, such as a legal obligation or a public interest mission, that would specifically authorize the dissemination of this personal data on its website.
  • Prohibition of processing data relating to criminal convictions and offenses (Article 10 of the GDPR): The processing of judicial data is strictly regulated and can only be carried out under public authority control or if authorized by an EU or Member State law. The authority concluded that the organization disseminated this sensitive data without any legal or regulatory provision authorizing it.
  • Obligation to respect the right to erasure (Article 17 of the GDPR): Although the organization claimed to have deleted the data following the complainant's request, the data remained inadvertently accessible in another section of the site. The authority considered that this partial and ineffective deletion constituted a failure to erase data without undue delay, the initial processing being unlawful under Article 17(1)(d).

Authority's decision

Consequently, the authority imposed a €20,000 fine on the Azienda Sanitaria Provinciale di Enna.

Furthermore, the authority ordered the publication of its decision on its website.

Lessons learned

This decision reminds that:

  • A deletion request is only considered fulfilled if the data is removed from all locations where it was published; partial deletion, even if inadvertent, constitutes a violation of the data subject's rights.
  • The publication of documents by a public body on its website must be based on a specific legal basis authorizing the dissemination of the personal data they contain, not merely on the obligation to publish the administrative act itself.
  • The online dissemination of data relating to criminal convictions or offenses is subject to particularly strict conditions and can only occur in the presence of an explicit legal or regulatory provision authorizing it.
  • The accountability principle requires the data controller to actively verify the relevance and necessity of publishing each personal data contained in an administrative document, systematically applying the minimization principle before any online publication.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire