The Italian authority imposes a €4,500 fine on ASL Lecce for data protection breaches in the urology department
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against the local health authority of Lecce (ASL Lecce) (including the imposition of a €4,500 fine) for breaches related to personnel designation, instructions, and security measures.
The case originated from a report by the Carabinieri for health protection, which revealed a lack of formalized procedures for protecting patient data within the urology department of a hospital.
Reasons for the decision
- Obligation to process data only on the controller's instructions (Article 29 of the GDPR): The authority found that the urology department staff had not been formally designated as authorized data processors. The entity claimed to have given oral instructions but provided no documentation to prove it. The authority recalled, referring to the European Data Protection Board (EDPB) Guidelines 07/2020, that instructions must be documented to be verifiable. The absence of formal designation and written instructions therefore constitutes a violation.
- Obligation to ensure the security of processing (Article 32 of the GDPR): The investigation highlighted inadequate physical security measures. Patients' medical records were kept in a trolley equipped with a lock, but it was constantly left open for convenience. Moreover, the infirmary door where the trolley was located was not locked when staff were absent. These practices were deemed a failure to implement appropriate organizational measures to ensure the confidentiality of health data.
- Obligation to guarantee integrity and confidentiality and accountability principle (Article 5, paragraphs 1, point f) and 2 of the GDPR and Article 24 of the GDPR): The authority concluded that the entity had not respected the accountability principle. In the absence of documentation on personnel designation, instructions provided, and training, the entity was unable to demonstrate compliance. It was noted that none of the 44 employees in the department had participated in data protection training organized at the entity level, constituting a serious organizational deficiency.
Authority's decision
Consequently, the authority imposed a €4,500 fine on the local health authority of Lecce.
Furthermore, the authority ordered the publication of its decision on its website.
Lessons learned
This decision confirms / specifies / recalls that:
- Oral instructions given to personnel, even in a dynamic operational context such as a hospital, are insufficient to meet GDPR requirements; they must be documented to be proven.
- The existence of a general regulation at the entity level does not exempt from the need to formally designate personnel and provide them with specific and adapted instructions at the level of each department or operational unit.
- The absence of personnel participation in data protection training, even if offered at the entity level, constitutes an organizational deficiency and a violation of the accountability principle.
- Physical security measures, such as locking cabinets containing medical records, must be effective and cannot be disregarded for mere operational convenience.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire