In two lines
Italian DPA, decision no. 616 of 3 September 2026 (doc. web no. 10293994): EUR 24,000 against the Friuli Centrale university health authority for breach of Arts. 5(1)(a), (b), (c) and (f), 9, 25 and 32 GDPR, Art. 75 of the Italian Privacy Code and the Health Dossier Guidelines of 4 June 2015.
In 2022 a colleague from the ward opens the complainant's health record — an employee and at the same time a patient of the same facility — to check whether she had Covid-19 and to draw up the shifts. In the criminal complaint the employer itself files with the Udine prosecutor, that access is described as «not unlawful», because it was «carried out on the instructions of the medical management» and «for the performance of the work». During the investigation further accesses emerge, by healthcare professionals who were not treating the complainant.
Why the defence does not hold
The health record exists to help the professional place the patient's condition within their care pathway: that, and only that, is what makes consulting it lawful. An organisational need — knowing which staff you can count on — is a different purpose, and must be met with dedicated tools. The authority adds a practical argument worth more than many admonitions: the record is inherently incomplete, because the data subject can mask entries, and the masked ones may be exactly those the organisational purpose would need. Using it to plan shifts is not only unlawful: it is inefficient.
What the authority ordered, within sixty days:
- Limit access to the record to care purposes only, excluding staff acting as the data subject's employer
- Introduce access limits configured in the system, not left to individual behaviour
- Deploy anomaly detection that flags suspicious conduct automatically
- Report the measures taken to the authority within sixty days of notification, under Art. 58(2)(d)
The detail that makes the case
Since 2024 the employer says it has an anomaly detection system: it consists of examining an Excel file collecting the results of queries on the viewer's audit log. It is worth reading twice. Access monitoring that exists as a spreadsheet someone looks at by hand is not a technical measure under Art. 32: it is a good intention with a technical name. And when the employer tries to explain the accesses it cannot attribute, it suggests that someone «took over» an unattended workstation — which is the exact description of the control that is missing.
What to ask your healthcare client
1) Ask whether there is a technical separation between those who access to treat and those who access to administer, and have it shown to you in the configuration, not in the procedure. 2) Ask how an anomalous access is detected: if the answer contains the word «Excel», you have found your finding. 3) Ask for evidence of the last alert raised and what happened next: a system that has flagged nothing in three years is not a quiet system, it is an off system. 4) Check that staff know that access without a care relationship is also unlawful access to a computer system under Art. 615-ter of the Italian criminal code, and that the facility has already reported such cases.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free