Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement September 22, 2026 6 min

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

A colleague opens the complainant's health record to check whether she has Covid and organise the shifts. The employer argues it was lawful because it served the work. The authority separates the two roles: whoever acts as employer does not enter the care record

In two lines

Italian DPA, decision no. 616 of 3 September 2026 (doc. web no. 10293994): EUR 24,000 against the Friuli Centrale university health authority for breach of Arts. 5(1)(a), (b), (c) and (f), 9, 25 and 32 GDPR, Art. 75 of the Italian Privacy Code and the Health Dossier Guidelines of 4 June 2015.

In 2022 a colleague from the ward opens the complainant's health record — an employee and at the same time a patient of the same facility — to check whether she had Covid-19 and to draw up the shifts. In the criminal complaint the employer itself files with the Udine prosecutor, that access is described as «not unlawful», because it was «carried out on the instructions of the medical management» and «for the performance of the work». During the investigation further accesses emerge, by healthcare professionals who were not treating the complainant.

Why the defence does not hold

The health record exists to help the professional place the patient's condition within their care pathway: that, and only that, is what makes consulting it lawful. An organisational need — knowing which staff you can count on — is a different purpose, and must be met with dedicated tools. The authority adds a practical argument worth more than many admonitions: the record is inherently incomplete, because the data subject can mask entries, and the masked ones may be exactly those the organisational purpose would need. Using it to plan shifts is not only unlawful: it is inefficient.

What the authority ordered, within sixty days:

  • Limit access to the record to care purposes only, excluding staff acting as the data subject's employer
  • Introduce access limits configured in the system, not left to individual behaviour
  • Deploy anomaly detection that flags suspicious conduct automatically
  • Report the measures taken to the authority within sixty days of notification, under Art. 58(2)(d)

The detail that makes the case

Since 2024 the employer says it has an anomaly detection system: it consists of examining an Excel file collecting the results of queries on the viewer's audit log. It is worth reading twice. Access monitoring that exists as a spreadsheet someone looks at by hand is not a technical measure under Art. 32: it is a good intention with a technical name. And when the employer tries to explain the accesses it cannot attribute, it suggests that someone «took over» an unattended workstation — which is the exact description of the control that is missing.

What to ask your healthcare client

1) Ask whether there is a technical separation between those who access to treat and those who access to administer, and have it shown to you in the configuration, not in the procedure. 2) Ask how an anomalous access is detected: if the answer contains the word «Excel», you have found your finding. 3) Ask for evidence of the last alert raised and what happened next: a system that has flagged nothing in three years is not a quiet system, it is an off system. 4) Check that staff know that access without a care relationship is also unlawful access to a computer system under Art. 615-ter of the Italian criminal code, and that the facility has already reported such cases.

Official source:Italian Data Protection Authority, decision of 3 September 2026, register no. 616, doc. web no. 10293994

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
72hours of retention never justified

Cameras in the changing rooms since 2007: the defence lists what they did not film, and loses

The defence brief is a list of things that were not visible: not the cubicles, not the showers, not the toilets; and near the lockers there are no benches «that might induce someone undressing to sit there and so be captured by the video system». It is reasoning by subtraction, and in a changing room it does not work. For the DPO, though, the passage to keep is another: among the provisions breached is Art. 5(1)(e), because the seventy-two hours of retention declared were not supported by any assessment showing they were necessary.

Sep 22, 2026New 5 min