The Italian authority fines the Italian Red Cross 700 euros for violating health data rules
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against the Italian Red Cross – Regional Committee of Tuscany – Anna Torrigiani Facility (including a fine of €700) for breaches related to the unlawful disclosure of health data and lack of cooperation.
The case began with a complaint from a patient who, during her hospitalization, saw her serological status (HIV and HCV), as well as her first and last name, written on a note accompanying her meal trays.
Reasons for the decision
The authority found several violations against the organization:
- Data minimization obligation (Article 5(1)(c) of the GDPR): The authority judged that the explicit communication of the patient's HIV and HCV status to kitchen staff was excessive. It based its reasoning on Italian sectoral regulations (Law No. 135/1990 and the decree of 28 September 1990) which impose the adoption of universal protective measures for all patients, precisely because it is impossible to identify with certainty all seropositive persons. Consequently, the disclosed information was neither adequate, relevant, nor limited to what was necessary to ensure staff protection.
- Integrity and confidentiality obligation (Article 5(1)(f) of the GDPR): By placing a handwritten note mentioning highly sensitive health data on a meal tray, the data controller did not ensure appropriate security against unauthorized disclosure. This communication method exposed confidential information to a high risk of consultation by third parties, contrary to data protection requirements.
- Prohibition of processing health data (Article 9 of the GDPR): The processing of data relating to HIV infection, which benefits from enhanced protection under Italian law, was carried out without an appropriate legal basis for communication to third parties. The authority recalled that such information can only be communicated based on a valid legal ground, which was not the case for this disclosure to catering staff.
- Cooperation obligation with the supervisory authority: The data controller did not respond to the authority's initial request for information, made under Article 157 of the Italian Data Protection Code. This failure to cooperate constituted a separate violation, as the organization provided no justification for its initial lack of response.
Authority's decision
Consequently, the authority imposed a fine of €700 on the Italian Red Cross – Regional Committee of Tuscany – Anna Torrigiani Facility, broken down into €500 for the health data violation and €200 for the lack of cooperation.
Furthermore, the authority ordered the publication of the decision on its website.
Lessons learned
This decision reminds that:
- The existence of "universal precautions" protocols in a sector, such as healthcare, makes the processing of specific health data to achieve the same security objective non-compliant with the minimization principle.
- The communication of sensitive information, even internally, must be done through secure channels and not by means (such as a note on a tray) that expose data to the risk of accidental disclosure to third parties.
- Data relating to HIV status benefit from an enhanced protection regime requiring particular vigilance and strict justification of the necessity of each processing.
- Failure to respond to a supervisory authority's request for information constitutes a separate infringement and may be subject to a specific financial penalty, regardless of the substance of the case.
- The prompt implementation of corrective measures and the absence of prior violations are significant mitigating factors in determining the amount of the fine.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire