Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
ITALIAN SUPERVISORY AUTHORITY: Certificates for absence from work, Guarantor: no to health data

ITALIAN SUPERVISORY AUTHORITY: Certificates for absence from work, Guarantor: no to health data

Certifications attesting to the presence in the hospital, to justify an absence from work or the impossibility of participating in a competition, must not include the information of the facility where the health service was provided, the stamp with the doctor’s specialization, or information that could lead to the state of health.

This is what the Guarantor reiterated by fining a Territorial Health Authority for 17 thousand euros.

The Authority intervened following a complaint from a patient who had asked the health facility for a certificate for absence from work.

The certificate issued indicated the department that had provided the health service, violating safety obligations and the principle of minimizing personal data.

The data processed, in fact, must be adequate, relevant and limited to what is necessary with respect to the purposes for which they are processed.

Furthermore, the Authority has ascertained the violation of the principle of privacy by design as the Company, the data controller, has failed to implement, from the design stage, adequate technical and organizational measures aimed at effectively implementing the principles of data protection and protecting the rights of the interested parties.

The Health Authority will therefore have to pay a fine of 17 thousand euros because, despite having, following the intervention of the Guarantor, modified the forms and carried out specific training for the staff on personal data protection, the violation involved a potentially high number of patients for a long period. In defining the fine, the Authority also considered that the Authority did not provide feedback to the Guarantor’s request for information, committing a further violation of the Code.

https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10086101

Recommended to you

Advanced Research