Garante per la protezione dei dati personali (Italy) - 10192784

From GDPRhub
Garante per la protezione dei dati personali - 10192784
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 1 GDPR
Article 5(1)(a) GDPR
Article 5(1)(c) GDPR
Article 6(1)(c) GDPR
Article 6(1)(e) GDPR
Article 6(2) GDPR
Article 6(3) GDPR
Article 57(1)(f) GDPR
Article 58(2) GDPR
Article 83(3) GDPR
Article 83(5) GDPR
Article 52 (1) CFR
Article 7 CFR
Article 8 CFR
Guideline 4/2022 EDPB
DPR 221/1950
Type: Complaint
Outcome: Upheld
Started:
Decided:
Published: 09.10.2025
Fine: 16000 EUR
Parties: Ordine delle Professioni Infermieristiche di Pisa
Data Subject
National Case Number/Name: 10192784
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Italian
Original Source: Garante per la protezione dei dati personali (in IT)
Initial Contributor: Ariel Bassano

DPA imposed €16,000 fine on the nursing registry (OPI) of Pisa for lack of legal basis. The OPI published a full report of a nurse's data on their website by mistake.

English Summary

Facts

The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the residential address, information not necessary for the purposes of the Register [Note: the OPI is a governance body for registered nurses].

The OPI (the controller), when asked by the DPA to provide further clarification, initially stated that, in accordance with the applicable local regulation (DPR 221/1950), the public register included residential addresses to provide employers with accurate information and to avoid identity confusion in cases of identical names.

During the investigation, the National Federation of Nursing Professional Orders (the “Federation”), the representative body entrusted with functions of guidance, coordination and administrative support to the territorial Orders, indicated that the residential address was not required for the functioning or the purpose of the register, expressly referring to Article 6(3) GDPR to confirm that no legal provision required the publication of such data.

The controller subsequently revised its position, explaining that it routinely maintained two databases: a complete version and a reduced one containing only minimal information. The publication in which the residential address of a single data subject appeared resulted from an employee’s mistake during the update following a meeting of the Directive Council.

Holding

The DPA upheld the complaint and found violations of Article 5(1)(a) GDPR, Article 6(1)(e) GDPR, Article 6(2) GDPR and Article 6(3) GDPR. The publication, through the internet, of personal data that exceeds the main purpose of the professional public registry, without a proper legal basis, breached the Article 6(1).

The DPA rejected the controller’s argument that the disclosure resulted merely from an employee’s mistake, noting that the controller did not act promptly to prevent continued access through search engine caching and that such circumstances could not justify the unlawful disclosure.

It also clarified that the version of the Register published online contained the residential addresses of all registered professionals, not only that of the complainant, as later confirmed by the DPA. It was mandatory for the the controller to comply with the principles governing data protection, including the principles of lawfulness, fairness and transparency, as well as data minimisation. In accordance with this principles, the data processing should had been processed lawfully, fairly and in a transparent manner in relation to the data subject, and adequate, relevant and limited to what was strictly necessary in relation to the purposes.

Following this, the DPA imposed a €16,000 fine. In defining the amount, the DPA took into account that the violation was produced due to the negligence of the Controller (art. 83, par. 2, lett. b.) and its lack of cooperation.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10192784]

Measure of October 9, 2025

Register of Measures
no. 585 of October 9, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, Members, and Councillor Angelo Fanizza, Secretary General;

CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Pasquale Stanzione;

WHEREAS

1. Introduction.

With a complaint filed pursuant to Article 77 of the Regulation, Ms. XX, a registered professional with the Order of Nursing Professions of Pisa (hereinafter, the "Order"), complained that the professional register published by the Order on its institutional website also includes the residential address of each professional.

2. Investigative activity.

In response to a request for information made pursuant to Article 157 of the Code (see note prot. XX of XX), the Order, with note of XX (without a protocol number), stated, in particular, that:

- "the register remained published online from XX to XX";

- "at the time of publication, there were n. 3686";

- "the publication assessment was conducted by analyzing the relevant legislation, Presidential Decree 221/1950";

- "the reason for reporting the address [of residence] was the need to provide complete information to employers who needed to consult the Register and to avoid errors in any written communications with the interested party or communications to employment agencies and other public offices";

- "currently [the Order] has updated its website and the new Register of Nurses is dated XX [;] the data reported are: Sequence No. - Name - Date of Birth - Place of Birth - Registration Date - Position No.".

In response to a second request for information (see note prot. no. XX of XX), the Order, in a note dated XX (prot. no. XX), stated, in particular, that:

- "the address [subject of annotation [The] register is the one of residence and not the one where the professional performs his/her work";

- the Order "has decided to update the published list by removing the domicile of the members from the clear view."

In relation to the facts that are the subject of the complaint, the Office of the Guarantor has decided to involve the National Federation of Nursing Professions Orders (hereinafter, the "Federation") in the investigation, as it is a body of "exponential representation" to which "tasks of direction, coordination, and administrative support to the territorial Orders" are assigned (see Article 7 of Legislative Decree No. 233 of September 13, 1946). In response to a specific request for information (see note prot. No. XX of XX, also sent to the Order), the Federation, in note dated XX (prot. No. XX), stated, in particular, that:

- "The register data published on the Federation's website does not include the member's residence. as such information, in light of what is indicated in art. 6, par. 3, of the Regulation, was not deemed necessary to pursue the public interest objective of identifying the member in the relevant Register";

- "the Federation has not received any indications or communications from the Ministry of Health regarding the obligation to publish the member's residence in the Register."

With a note dated XX (ref. no. XX), the Office, based on the information acquired, the checks carried out, and the facts emerging from the preliminary investigation, notified the Association, pursuant to Art. 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the measures referred to in Art. 58, paragraph 2, of the Regulation, for the Association having recorded the information regarding the residence of professionals in the professional register and having disseminated this information online, thereby processing personal data in a manner that does not comply with the principle of "lawfulness, fairness, and transparency" and in the absence of a legal basis, in violation of Articles. 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as 2-ter of the Code.

With the same note, the aforementioned data controller was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

With a note dated XX (protocol No. XX), the Order submitted a defense brief, declaring, in particular, that:

"The register, as required by the specific law governing the Order, Presidential Decree 221/1950, Law 675/1996, the Privacy Code, Legislative Decree 196/2003, and Presidential Decree 137/2012, is maintained by the Council of the Order or by the Territorial Board and is public and contains the registry of all members with the annotation of the disciplinary measures taken against them. The set of territorial registers for each profession forms the single national register of members, maintained by the competent National Board (specifically, FNOPI), which receives all relevant information for updating the National Register.

"OPI Pisa shall publicize the Register of its members by publishing a PDF file on its website."

"[…] following each Board of Directors meeting, the list of members registered in the Register is updated."

"OPI Pisa shall update two lists: the complete list containing all personal data of members, a file internally called "Complete Register," followed by the date of the Board of Directors meeting to which it refers, for OPI internal use only; and a second file, called "Reduced Register," also followed by the date of the Board of Directors meeting to which it refers, containing the minimum information required for publication (name, surname, date and place of birth, year of registration) or amended to remove all data not relevant to publication."

"Only the file called "Reduced Register" is the one which is published on the Order's website, updating the file relating to the previous month's Board of Directors meeting";

"OPI has provided responses to the Guarantor to date, which, unfortunately, have proven to be only partially accurate. In fact, [...] only after the new Board of Directors took office, thanks also to the valuable collaboration of the employees and the thorough investigations into the technical information provided by the new IT consultant, was it possible to reconstruct the entire affair in a correct, detailed, and documented manner";

"On XX, following the Board of Directors meeting held on the same date, the OPI Pisa employee proceeded, as usual, to publish the updated Register file";

"Following the update of the Register, two lists containing the personal data of members were created, specifically one named "XX" and the other "XX"";

"Unfortunately, by pure error, likely caused by the similar names of the two files, the "XX" file was published on the OPI website instead of the "reduced" one. The employee, shortly thereafter realizing the error, promptly removed the "Complete Register" document and published the correct file, namely "XX";

"The personal data indicated was not available on the OPI website nor present on the FNOPI website, and moreover, the [complainant's] report does not refer to the presence of the disputed file on the OPI Pisa website, but only to the file being found following a Google search for "Nurse Register at XX";

"This could have happened because the "XX" file was indexed on Google at the time of publication";

"In this case, the file deleted from the website continued to appear in Google search results, and this can happen for various reasons";

"Only after OPI became aware of the presence of this page on the web […] did it arrange for its removal by the IT technician, as evidenced by the XX report";

"The register, or rather, the "XX" file, was published online for only a few hours on the XX (and not, as previously erroneously indicated, from XX to XX), and was then replaced with the "XX" file, containing only the minimum personal data, as a website update and thus allowing consultation of the register";

"no significant damage is recognized to the interested party [, given that, ...] the contested personal data was visible on the website for only a few hours and subsequently, during the indexing of the file, only through a specific and not generic search for the data."

During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX (see minutes, file no. XX of the same date), the Order stated, in particular, that:

"Search engine indexing occurs directly from the person downloading the document or viewing the page; consequently, the search engine scans the document and makes it available in the viewer's history";

"The Order […] has never arranged for the residential address to be included among the information reported in the professional register."

3. Outcome of the preliminary investigation.

In order to ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to respect for private life and the protection of personal data, enshrined in Articles Pursuant to Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (see Article 1 of the Regulation), any processing of personal data must, in particular, comply with the principles set out in Article 5 of the Regulation and meet the lawfulness requirements set out in Article 6 thereof (see, among many decisions, Court of Justice of the European Union, Case C-710/23, Ministerstvo zdravotnictví (Documents relating to the representative of a moral person), of 20th Article 20th Article).

In this framework, public bodies may, as a rule, process personal data if the processing is necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller" (Article 6, paragraph 1, letters c) and e), of the Regulation).

European legislation provides that "Member States may maintain or introduce more specific provisions to adapt the application of the rules of the […] Regulation with regard to processing in accordance with paragraph 1, points (c) and (e), by laying down more precisely specific requirements for the processing and other measures to ensure lawful and fair processing […]" (Article 6, paragraph 2, of the Regulation). In this regard, it is noted that the "dissemination" (Article 2-ter, paragraph 4, letter b), of the Code) of personal data by public bodies is permitted only under the conditions set out in Article 2-ter, paragraphs 1, 1-bis, and 3, of the Code.

More specifically, with regard to the online publication of sector registers by professional associations, Article 6(2) of the Regulation provides for the following: Article 61, paragraph 2, of the Code provides that "for the purposes of applying this Code, personal data other than those referred to in Articles 9 and 10 of the Regulation, which must be entered in a professional register in accordance with the law or a regulation, may be communicated to public and private entities or disseminated, pursuant to Article 2-ter of this Code, including via electronic communications networks. The existence of measures that impact the practice of the profession in any capacity may also be mentioned."

The data controller is, in any case, required to comply with data protection principles, including those of "lawfulness, fairness, transparency," and "data minimization," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" and "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c), of the Regulation).

Given the above, it is established that, on 2019, the Order published on its institutional website a version of the professional register containing the residential addresses of all registered professionals, including that of the complainant.

In this regard, the Order, during the investigation, initially asserted the lawfulness of the online dissemination of this information, on the basis that Article 3 of Presidential Decree No. 221 of April 5, 1950, provides that "for each member, the address, among other things, shall be indicated." It therefore maintained that it acted in accordance with the aforementioned professional register regulations in order to avoid errors in cases of homonymy, where the registered professionals' years of birth were close together.

Although the Order subsequently radically changed its reconstruction of the facts and its defense, attributing the violation to a mere error committed by one of its employees, it must nevertheless be stated that this defense argument is unfounded.

The processing of personal data may find its legal basis in Article 6, paragraph 1, letter e), of the Regulation if and to the extent that it is "necessary" for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. This condition must be examined in conjunction with the principle of data minimization enshrined in Article 6, paragraph 1, letter c), of the Regulation, according to which personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This is because, in accordance with Article 52, paragraph 1, letter c), of the Regulation, the processing of personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. 1 of the Charter of Fundamental Rights of the European Union, the fundamental rights to respect for private life and to the protection of personal data, as set out in Articles 7 and 8 of the Charter, may be subject to limitations only if they are provided for by law and respect the essence of the fundamental rights, as well as the principle of proportionality, expressly referred to in Article 6, paragraph 3, of the Regulation. In accordance with this principle, such limitations must be necessary and genuinely meet objectives of general interest recognized by the Union or the need to protect the rights and freedoms of others. They must apply only to the extent strictly necessary, and the legislation causing the interference must provide clear and precise rules governing the scope and application of the measure in question.

In order to determine whether processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, it is necessary to verify, in particular, whether, in light of the seriousness of the interference with the fundamental rights to respect for private life and the protection of personal data caused by the processing, the processing is justified and, in particular, proportionate to the achievement of the objectives pursued. As highlighted by Council 39 of the Regulation, the requirement of necessity of processing cannot be considered satisfied when the general interest objective in question can reasonably be achieved equally effectively by other means that are less prejudicial to the fundamental rights of the data subjects, in particular the rights to respect for private life and to the protection of personal rights guaranteed by Articles 7 and 8 of the Charter, given that derogations and restrictions to these rights must be limited to what is strictly necessary (see Court of Justice of the European Union, judgments C-184/20, Vyriausioji tarnybinės etikos komisija, of 1 August 2022, paras. 73, 82, 85, 93, 94, 98, 99; C-439/19, Latvijas Republikas Saeima, of 22 June 2021, paras. 99, 105, 106, and 113).

Therefore, borrowing the aforementioned legal principles formalized by the case law of the Court of Justice of the European Union, data controllers, even in the presence of provisions of national law that contemplate the processing of personal data, must assess the actual necessity and proportionality of the processing for the purposes of pursuing the public interest objective underlying such provisions, especially in cases where, like the one at issue, the national provisions are outdated, no longer reflect the changing social context, and predate the European legal framework on data protection.

With regard to the specific case, it must be noted that the residential address of a person is not information generally known to the public and, therefore, from the perspective of anyone wishing to verify the actual registration of a person practicing a particular profession in the register, the annotation of the same in the register cannot be considered necessary to pursue the public interest purpose underlying the regulations of the professional associations regarding professional registers (see art. 61, paragraph 2, of the Code), which consists in protecting members who come into contact in various capacities with those practicing the profession, allowing verification of the actual professional qualification and registration of such individuals in the relevant register (on the regime of full publicity of professional registers, also in function of the protection of the rights of those who in various capacities have relationships with those registered in the register, see the constant and long-standing orientation of the Guarantor as per, among many, the note of 30 June 1997, in Bollettino no. 1, page 33, web doc. no. 39320; July 22, 1997, in Bulletin No. 1, p. 40, web doc. No. 39456; August 4, 1997, in Bulletin No. 1, p. 46, web doc. No. 30843; June 23, 1998, in Bulletin No. 5, p. 12, web doc. No. 39901; October 26, 1998, in Bulletin No. 6, p. 12, web doc. No. 41075).

This purpose—as confirmed by the Federation itself, which, in light of the provisions of Article 6, paragraph 3 of the Regulation, does not include information regarding residence in the national register - can, however, be pursued in equally effective but less detrimental ways to the rights and freedoms of the interested parties, namely by recording only the data relating to the name, surname, date and place of birth of the registered professional, data also covered by the aforementioned Article 3 of Presidential Decree No. 221 of 5 April 1950, without prejudice to the fact that only the provision of the tax code can resolve any cases of homonymy with the same place and date of birth.

On the other hand, neither the Order nor the Federation records the information regarding "paternity" in the professional register, even though it is still formally required by Article 3 of Presidential Decree No. 221 of April 5, 1950, having disapplied this provision due to its evident anachronism and its manifest irrelevance to the pursuit of the objective of protecting members in their relationships with those who practice nursing.

Recording personal data relating to residence in the register, in addition to being useless for the purposes of pursuing the aforementioned public interest purpose, also entails the online dissemination of such information (see Article 61, paragraph 2, of the Code), unjustifiably exposing the professionals concerned to potential risks to their personal lives. In certain contexts—think, for example, of stalking cases or the increasing incidences of assault on healthcare professionals—this may also compromise their physical safety. The online dissemination of personal data “ends up [, in fact,] making such personal data freely accessible on the Internet to the general public as a whole and, consequently, to a potentially unlimited number of people” (see judgment C-184/20, cit., par. 102), with the consequent exposure of the interested parties also to potential risks (ibidem, par. 104), thus constituting a substantial interference in the right to the protection of personal data, in light of which the necessity and proportionality of the processing must be carefully weighed, within the context of a balance between, on the one hand, the public interest pursued and which would justify such an interference and, on the other, the right to the protection of personal data of the interested parties (see ibidem, pars. 110 and 111; see also, lastly, provision of 26 September 2024, no. 588, web doc. no. 10076453, where it is highlighted that the publication of Online personal data, unlike traditional forms of advertising, constitutes a particularly invasive form of data dissemination, as it allows anyone, even through common search engines, to indiscriminately retrieve a substantial amount of information in real time.

Having clarified this, it should be noted that, as mentioned above, the Order, only in its defense brief, after having allegedly conducted further and more in-depth investigations once the new Board of Directors had taken office, declared, also assuming liability pursuant to Article 168 of the Code, that the online dissemination of information regarding the residential address occurred as a result of a mere clerical error committed by one of its employees, who had unwittingly published on the Order's institutional website a version of the register prepared for internal use by the organization, which contained the private residential addresses of members.

According to the Order, this internal-use version of the register was published on the institutional website only "for a few hours on the 20th."

Subsequently, "the file, deleted from the website, continued to appear in Google search results" for reasons that the Order has not definitively ascertained ("this could happen for various reasons"), so much so that the Order, during the hearing, also alluded to the possibility that the file in question had been consulted by the complainant on the date of filing the complaint because it was stored in the cache of her browser.

This hypothesis, however, is not supported by the documentation in the case file. The Order, in fact, produced a screenshot extracted from an online tool—presumably made available by Google to monitor the status of removal requests—which shows that the removal request for two URLs specifically related to the Institution's institutional website, including the one corresponding to the page "https://www.opipisa.it/...", was only formalized on XX.

Therefore, although the Order declared, again assuming responsibility pursuant to Article 168 of the Code, that the document in question had been removed from its website a few hours after its publication, it is nevertheless established that the Order did not promptly take action to prevent online consultation of the same document via the version stored in the so-called search engine cache. Consequently, the version of the register containing the residential addresses of registered professionals, although no longer published on the Order's institutional website, remained accessible, for an extended period of time, to anyone who queried a search engine with relevant keywords.

In light of all the foregoing considerations, it must be concluded that, from 2019 and at least until 2020, the Order has disseminated online the personal data of the complainant and other professionals registered with it, relating to their residential address, in a manner that does not comply with the principles of "lawfulness, fairness, and transparency" and in the absence of a legal basis, in violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as Article 2-ter of the Code.

4. Conclusions.

In light of the above considerations, it is found that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 2-ter of the Code – are inaccurate. 168 of the Code, although worthy of consideration, do not overcome the concerns notified by the Office with the notice initiating the proceedings and are insufficient to allow the dismissal of this proceeding, since none of the cases provided for by Article 11 of the Guarantor Regulation No. 1/2019 apply.

The Office's preliminary assessments are therefore confirmed and the processing of personal data by the Order is found to be unlawful, having processed the personal data of the complainant and other members of the Order in violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as Article 2-ter of the Code.

Given that the violation of the aforementioned provisions occurred as a result of a single conduct (the same processing or related processing), Article 83, paragraph 1, applies. 3 of the Regulation, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Given that, in this case, violations of all the aforementioned provisions of the Regulation and the Code are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000.

In this context, considering, in any case, that the conduct has exhausted its effects, and given that the version of the register containing the residential addresses is no longer available online, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letters i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante Regulation No. 1/2019).

In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the pecuniary administrative sanction provided for in Article 83, paragraph 5, of the Regulation.

The aforementioned administrative fine imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

the violation involved personal data relating to a large number of data subjects (3,606 professionals, as evidenced by the copy of the register found online by the complainant and attached to the complaint) and lasted for an extended period of time, namely at least from 2015 to 2016, even though, after 2016, the version of the register containing the addresses of residence was only accessible through search engines (Article 83, paragraph 2, letter a), of the Regulation);

the violation is negligent (Article 83, paragraph 2, letter b), of the Regulation);

although the processing did not involve data belonging to the special categories referred to in Article 83, paragraph 2, letter c), of the Regulation; 9 of the Regulation, as highlighted above, led to the online dissemination of sensitive information, namely the address of residence of members. This exposes them not only to the general risk of fraud and identity theft that can always arise from the online dissemination of personal data, but also to potential specific risks to their safety, given the specific working and professional context in which they operate and the increasing incidents of aggression against healthcare professionals (see Article 83, paragraph 2, letter g), of the Regulation).

In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of 24 May 2023, point 60).

Considering this, given that the data controller is a small public body operating on a provincial basis, with approximately 3,600 members, it is believed that, in assessing the fine, the following circumstances should be taken into consideration:

The Order offered poor cooperation with the Authority during the investigation, given that it initially asserted the lawfulness of the processing and, only in its defense brief, attributed the violation to mere human error. This has consequently aggravated the Authority's administrative efforts to ascertain the facts. In this regard, it is entirely irrelevant that, as the Authority stated, only with the appointment of the new Board of Directors was it possible to conduct a thorough investigation into the matters under complaint. Furthermore, the Order has not contributed sufficiently to the technical reconstruction of the reasons why the version of the register not intended for publication remained accessible through search engines (Article 83, paragraph 2, letter f), of the Regulations);

There are no previous relevant violations committed by the Order (Article 83, paragraph 2, letter e), of the Regulations).

Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the fine at €16,000 (sixteen thousand) for the violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulations, as well as Article 2-ter of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulations, to be effective, proportionate, and dissuasive.

It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority Regulation No. 1/2019, this chapter containing the injunction order should be published on the Data Protection Authority's website. This is in consideration of the fact that, as highlighted above, the violation continued over an extended period of time and affected numerous data subjects, exposing them to potential risks arising from the dissemination of information regarding their residence.

Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met.

NOW, THE GUARANTOR

declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Order of Nursing Professions of Pisa due to violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter c), and 7, paragraph 2, of the Regulation. 1, letter e), and paragraphs 2 and 3 of the Regulations, as well as 2-ter of the Code, within the time limits set forth in the reasons;

ORDERS

the Order of Nursing Professions of Pisa, represented by its legal representative pro tempore, with registered office at Via P. Metastasio, 17 - 56017 San Giuliano Terme (PI), Tax Code 80006830501, to pay the sum of €16,000 (sixteen thousand) as an administrative fine for the violations indicated in the reasons. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

the aforementioned Order, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €16,000 (sixteen thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

- pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this order on the Authority's website;

- pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, October 9, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Fanizza

[web doc. no. 10192784]

Provision of October 9, 2025

Register of Provisions
No. 585 of October 9, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, Members, and Councillor Angelo Fanizza, Secretary General;

CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Pasquale Stanzione;

WHEREAS

1. Introduction.

With a complaint filed pursuant to Article 77 of the Regulation, Ms. XX, a registered professional with the Order of Nursing Professions of Pisa (hereinafter, the "Order"), complained that the professional register published by the Order on its institutional website also includes the residential address of each professional.

2. Investigative activity.

In response to a request for information made pursuant to Article 157 of the Code (see note prot. XX of XX), the Order, with note of XX (without a protocol number), stated, in particular, that:

- "the register remained published online from XX to XX";

- "at the time of publication, there were n. 3686";

- "the publication assessment was conducted by analyzing the relevant legislation, Presidential Decree 221/1950";

- "the reason for reporting the address [of residence] was the need to provide complete information to employers who needed to consult the Register and to avoid errors in any written communications with the interested party or communications to employment agencies and other public offices";

- "currently [the Order] has updated its website and the new Register of Nurses is dated XX [;] the data reported are: Sequence No. - Name - Date of Birth - Place of Birth - Registration Date - Position No.".

In response to a second request for information (see note prot. no. XX of XX), the Order, in a note dated XX (prot. no. XX), stated, in particular, that:

- "the address [subject of annotation [The] register is the one of residence and not the one where the professional performs his/her work";

- the Order "has decided to update the published list by removing the domicile of the members from the clear view."

In relation to the facts that are the subject of the complaint, the Office of the Guarantor has decided to involve the National Federation of Nursing Professions Orders (hereinafter, the "Federation") in the investigation, as it is a body of "exponential representation" to which "tasks of direction, coordination, and administrative support to the territorial Orders" are assigned (see Article 7 of Legislative Decree No. 233 of September 13, 1946). In response to a specific request for information (see note prot. No. XX of XX, also sent to the Order), the Federation, in note dated XX (prot. No. XX), stated, in particular, that:

- "The register data published on the Federation's website does not include the member's residence. as such information, in light of what is indicated in art. 6, par. 3, of the Regulation, was not deemed necessary to pursue the public interest objective of identifying the member in the relevant Register";

- "the Federation has not received any indications or communications from the Ministry of Health regarding the obligation to publish the member's residence in the Register."

With a note dated XX (ref. no. XX), the Office, based on the information acquired, the checks carried out, and the facts emerging from the preliminary investigation, notified the Association, pursuant to Art. 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the measures referred to in Art. 58, paragraph 2, of the Regulation, for the Association having recorded the information regarding the residence of professionals in the professional register and having disseminated this information online, thereby processing personal data in a manner that does not comply with the principle of "lawfulness, fairness, and transparency" and in the absence of a legal basis, in violation of Articles. 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as 2-ter of the Code.

With the same notice, the aforementioned data controller was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

In a note dated XX (ref. no. XX), the Order submitted a defense brief, declaring, in particular, that:

"The register, as required by the specific law governing the Order (Presidential Decree 221/1950, Law 675/1996, the Privacy Code (Legislative Decree 196/2003), and Presidential Decree 137/2012), is maintained by the Council of the Order or the Territorial Board and is public. It contains the records of all members, along with a record of any disciplinary measures taken against them. The territorial registers for each profession together form the single national register of members, maintained by the competent National Board (specifically, FNOPI), which receives all relevant information for updating the National Register."

"OPI Pisa ensures that the Register of its members is publicized by publishing a PDF file on its website."

“[…] after each Board of Directors meeting, the list of members is updated”;

“OPI Pisa updates two lists: the complete list containing all the personal data of members, a file internally called “Complete List,” followed by the date of the Board of Directors meeting to which it refers, for Opi's internal use only; and a second file, called “Reduced List,” also followed by the date of the Board of Directors meeting to which it refers, containing the minimum information required for publication (name, surname, date and place of birth, year of membership) or amended to remove all data not relevant to publication”;

“Only the file called “Reduced List” is published on the Order's website, updating the file relating to the Board of Directors meeting of the previous month”;

"To date, OPI has provided answers to the Guarantor, which, unfortunately, have proven to be only partially accurate. In fact, [...] only following the installation of the new Board of Directors, and thanks also to the valuable collaboration of its employees and the thorough investigations into the technical information provided by the new IT consultant, was it able to reconstruct the entire affair in a correct, detailed, and documented manner."

"On XX, following the Board of Directors meeting held on the same date, the OPI Pisa employee proceeded, as usual, to publish the updated Register file."

"Following the update of the Register, two lists containing the personal data of members were created, specifically one named "XX" and the other "XX.""

Unfortunately, by mistake, likely due to the similar file names of the two files, the "XX" file was published on the OPI website instead of the "reduced" file. The employee, shortly after realizing the error, promptly removed the "Complete Register" document and published the correct file, namely "XX."

The personal data indicated were not available on the OPI website nor present on the FNOPI website, and moreover, the [complainant's] report does not refer to the presence of the disputed file on the OPI Pisa website, but only to the file being found following a Google search for "Nurses Register at XX";

This could have happened because the "XX" file was indexed on Google at the time of publication;

In this case, the file deleted from the website continued to appear in Google search results, and this can happen for various reasons;

Only after OPI became aware of the presence of this page on the web […] did it have the IT technician delete it, as can be seen from the XX report;

The register, or rather, the "XX" file, remained published online for a few hours on the XX (and not, as previously erroneously indicated, from XX to XX), and was then replaced with the "XX" file, containing only the minimum personal data, such as updating the website and thus allowing consultation of the Register”;

“no significant damage is found to be suffered by the interested party [, given that, ...] the contested personal data was visible on the website for only a few hours and subsequently, during the file indexing phase, only through a specific and not generic search for the data.”

During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX (see minutes, protocol no. XX of the same date), the Order stated, in particular, that:

“indexing on search engines occurs directly by the person downloading the document or viewing the page; Consequently, the search engine scans this document and makes it available in the history of the person who viewed it”;

“the Order […] has never arranged to include the residential address among the information reported in the professional register.”

3. Outcome of the investigation.

In order to ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to respect for private life and to the protection of personal data, enshrined in Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (see Article 1 of the Regulation), any processing of personal data must, in particular, comply with the principles set out in Article 5 of the Regulation and satisfy the conditions of lawfulness set out in Article 6 thereof (see, among many decisions, Court of Justice of the European Union, judgment C-710/23, Ministerstvo zdravotnictví (Documents relating to the representative of a moral person), of 20 (xx).

In this framework, public bodies may, as a rule, process personal data if the processing is necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller" (Article 6, paragraph 1, letters c) and e), of the Regulation).

European legislation provides that "Member States may maintain or introduce more specific provisions to adapt the application of the provisions of the […] Regulation with regard to processing in accordance with paragraph 1, letters c) and e), by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing […]" (Article 6, paragraph 2, of the Regulation). In this regard, it is noted that the "dissemination" (Article 2-ter, paragraph 4, letter b), of the Code) of personal data by public bodies is permitted only under the conditions set out in Article 2-ter, paragraphs 1, 1-bis, and 3 of the Code.

More specifically, regarding the online publication of sector registers by professional associations, Article 61, paragraph 2 of the Code provides that "for the purposes of applying this Code, personal data other than those referred to in Articles 9 and 10 of the Regulation, which must be included in a professional register in accordance with the law or a regulation, may be communicated to public and private entities or disseminated, pursuant to Article 2-ter of this Code, including via electronic communications networks. The existence of measures that impact the practice of the profession in any way may also be mentioned.

The data controller is, in any case, required to comply with data protection principles, including those of "lawfulness, fairness, transparency," and "minimization," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" and "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c), of the Regulation).

That said, it is established that, on 2019, the Order published on its institutional website a version of the professional register containing the residential addresses of all registered professionals, including that of the complainant.

In this regard, the Order, during the investigation, initially asserted the lawfulness of the online dissemination of this information, on the basis that Article 3 of the Presidential Decree No. 221 of April 5, 1950, provides that "for each member, the address must be indicated," among other things. The Association therefore maintained that it acted in accordance with the aforementioned regulations, in order to avoid errors in cases of homonymy, where the years of birth of the registered professionals were close together.

Although the Association subsequently radically changed its reconstruction of the facts and its defense, attributing the violation to a mere error committed by one of its employees, it must nevertheless be stated that this defense argument is unfounded.

The processing of personal data may find its legal basis in Article 6, paragraph 1, letter e), of the Regulation if and to the extent that it is "necessary" for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. This condition must be examined in conjunction with the principle of data minimization established in the Regulation. Article 6, paragraph 1, letter c), of the Regulation, according to which personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This is because, in accordance with Article 52, paragraph 1, of the Charter of Fundamental Rights of the European Union, the fundamental rights to respect for private life and to the protection of personal data, set out in Articles 7 and 8 of the Charter, may be subject to limitations only if they are provided for by law and respect the essence of the fundamental rights, as well as the principle of proportionality, expressly referred to in Article 6, paragraph 3, of the Regulation. In accordance with this principle, such limitations must be necessary and genuinely meet objectives of general interest recognized by the Union or the need to protect the rights and freedoms of others. They must operate only to the extent strictly necessary, and the legislation leading to the interference must provide clear and precise rules governing the scope and application of the measure in question.

In order to determine whether processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, it is necessary to verify, in particular, whether, in light of the seriousness of the interference with the fundamental rights to respect for private life and the protection of personal data caused by the processing, the processing is justified and, in particular, proportionate to the achievement of the objectives pursued. As highlighted by Council 39 of the Regulation, the requirement of necessity of processing cannot be considered satisfied when the general interest objective in question can reasonably be achieved equally effectively by other means that are less prejudicial to the fundamental rights of the data subjects, in particular the rights to respect for private life and to the protection of personal rights guaranteed by Articles 7 and 8 of the Charter, given that derogations and restrictions to these rights must be limited to what is strictly necessary (see Court of Justice of the European Union, judgments C-184/20, Vyriausioji tarnybinės etikos komisija, of 1 August 2022, paras. 73, 82, 85, 93, 94, 98, 99; C-439/19, Latvijas Republikas Saeima, of 22 June 2021, paras. 99, 105, 106, and 113).

Therefore, borrowing the aforementioned legal principles formalized by the case law of the Court of Justice of the European Union, data controllers, even in the presence of provisions of national law that contemplate the processing of personal data, must assess the actual necessity and proportionality of the processing for the purposes of pursuing the public interest objective underlying such provisions, especially in cases where, like the one at issue, the national provisions are outdated, no longer reflect the changing social context, and predate the European legal framework on data protection.

With regard to the specific case, it must be noted that the residential address of a person is not information generally known to the public and, therefore, from the perspective of anyone wishing to verify the actual registration of a person practicing a particular profession in the register, the annotation of the same in the register cannot be considered necessary to pursue the public interest purpose underlying the regulations of the professional associations regarding professional registers (see art. 61, paragraph 2, of the Code), which consists in protecting members who come into contact in various capacities with those practicing the profession, allowing verification of the actual professional qualification and registration of such individuals in the relevant register (on the regime of full publicity of professional registers, also in function of the protection of the rights of those who in various capacities have relationships with those registered in the register, see the constant and long-standing orientation of the Guarantor as per, among many, the note of 30 June 1997, in Bollettino no. 1, page 33, web doc. no. 39320; July 22, 1997, in Bulletin No. 1, p. 40, web doc. No. 39456; August 4, 1997, in Bulletin No. 1, p. 46, web doc. No. 30843; June 23, 1998, in Bulletin No. 5, p. 12, web doc. No. 39901; October 26, 1998, in Bulletin No. 6, p. 12, web doc. No. 41075).

This purpose—as confirmed by the Federation itself, which, in light of the provisions of Article 6, paragraph 3 of the Regulation, does not include information regarding residence in the national register - can, however, be pursued in equally effective but less detrimental ways to the rights and freedoms of the interested parties, namely by recording only the data relating to the name, surname, date, and place of birth of the registered professional, data also covered by the aforementioned Article 3 of Presidential Decree No. 221 of April 5, 1950. It is understood that only the provision of the tax code can resolve any cases of homonymy with the same place and date of birth.

On the other hand, neither the Order nor the Federation record in the professional register the information relating to "paternity," which is still formally required by Article 3 of Presidential Decree No. 221 of April 5, 1950. 221, having disapplied this provision due to its evident anachronism and its manifest irrelevance to the pursuit of the objective of protecting members in their relationships with those who practice nursing.

The recording of personal data relating to residence in the register, in addition to being useless for the purposes of pursuing the aforementioned public interest objective, also entails the online dissemination of such information (see Article 61, paragraph 2, of the Code), unjustifiably exposing the professionals concerned to potential personal risks. In certain contexts—for example, consider cases of stalking or the increasing incidences of assault on healthcare professionals—this may also compromise their physical safety. The online dissemination of personal data “ends up [, in fact,] making such personal data freely accessible on the Internet to the general public as a whole and, consequently, to a potentially unlimited number of people” (see judgment C-184/20, cit., par. 102), with the consequent exposure of the interested parties also to potential risks (ibidem, par. 104), thus constituting a substantial interference in the right to the protection of personal data, in light of which the necessity and proportionality of the processing must be carefully weighed, within the context of a balance between, on the one hand, the public interest pursued and which would justify such an interference and, on the other, the right to the protection of personal data of the interested parties (see ibidem, pars. 110 and 111; see also, lastly, provision of 26 September 2024, no. 588, web doc. no. 10076453, where it is highlighted that the publication of Online personal data, unlike traditional forms of advertising, constitutes a particularly invasive form of data dissemination, as it allows anyone, even through common search engines, to indiscriminately retrieve a substantial amount of information in real time.

Having clarified this, it should be noted that, as mentioned above, the Order, only in its defense brief, after having allegedly conducted further and more in-depth investigations once the new Board of Directors had taken office, declared, also assuming liability pursuant to Article 168 of the Code, that the online dissemination of information regarding the residential address occurred as a result of a mere clerical error committed by one of its employees, who had unwittingly published on the Order's institutional website a version of the register prepared for internal use by the organization, which contained the private residential addresses of members.

According to the Order, this internal-use version of the register was published on the institutional website only "for a few hours on the 20th."

Subsequently, "the file, deleted from the website, continued to appear in Google search results" for reasons that the Order has not definitively ascertained ("this could happen for various reasons"), so much so that the Order, during the hearing, also alluded to the possibility that the file in question had been consulted by the complainant on the date of filing the complaint because it was stored in the cache of her browser.

This hypothesis, however, is not supported by the documentation in the case file. The Order, in fact, produced a screenshot extracted from an online tool—presumably made available by Google to monitor the status of removal requests—which shows that the removal request for two URLs specifically related to the Institution's institutional website, including the one corresponding to the page "https://www.opipisa.it/...", was only formalized on XX.

Therefore, although the Order declared, again assuming responsibility pursuant to Article 168 of the Code, that the document in question had been removed from its website a few hours after its publication, it is nevertheless established that the Order did not promptly take action to prevent online consultation of the same document via the version stored in the so-called search engine cache. Consequently, the version of the register containing the residential addresses of registered professionals, although no longer published on the Order's institutional website, remained accessible, for an extended period of time, to anyone who queried a search engine with relevant keywords.

In light of all the foregoing considerations, it must be concluded that, from 2019 and at least until 2020, the Order has disseminated online the personal data of the complainant and other professionals registered with it, relating to their residential address, in a manner that does not comply with the principles of "lawfulness, fairness, and transparency" and in the absence of a legal basis, in violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as Article 2-ter of the Code.

4. Conclusions.

In light of the above considerations, it is found that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 2-ter of the Code – are inaccurate. 168 of the Code, although worthy of consideration, do not allow for overcoming the objections notified by the Office with the act initiating the proceeding and are insufficient to allow the archiving of the present proceeding, since, moreover, none of the cases envisaged by art. 11 of the Guarantor Regulation no. 1/2019 apply.

The Office's preliminary assessments are therefore confirmed, and the processing of personal data by the Association is found to be unlawful, having processed the personal data of the complainant and other members of the Association in violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulation, as well as Article 2-ter of the Code.

Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing or related processing), Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Considering that, in the present case, violations of all the aforementioned provisions of the Regulation and the Code are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 2-ter of the Code. 166, paragraph 2, of the Code, the total amount of the fine is to be quantified up to €20,000,000.

In this context, considering, in any case, that the conduct has exhausted its effects, and given that the version of the register containing the residential addresses is no longer available online, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letters i) and 83 of the Regulation as well as Article 166, paragraph 7, of the Code, 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante Regulation No. 1/2019).

In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the pecuniary administrative sanction provided for in Article 83, paragraph 5, of the Regulation.

The aforementioned administrative fine imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

the violation involved personal data relating to a large number of data subjects (3,606 professionals, as evidenced by the copy of the register found online by the complainant and attached to the complaint) and lasted for an extended period of time, namely at least from 2015 to 2016, even though, after 2016, the version of the register containing the addresses of residence was only accessible through search engines (Article 83, paragraph 2, letter a), of the Regulation);

the violation is negligent (Article 83, paragraph 2, letter b), of the Regulation);

although the processing did not involve data belonging to the special categories referred to in Article 83, paragraph 2, letter c), of the Regulation; 9 of the Regulation, as highlighted above, resulted in the online dissemination of sensitive information, namely the residential address of members. This exposed them not only to the general risk of fraud and identity theft that can always arise from the online dissemination of personal data, but also to potential specific risks to their safety, given the specific working and professional context in which they operate and the increasing incidents of aggression against healthcare professionals (see Article 83, paragraph 2, letter g), of the Regulation).

In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of 24 May 2023, point 60).

Given the above, considering that the data controller is a small public body operating on a provincial basis, with approximately 3,600 members, it is believed that the following circumstances should be taken into consideration when assessing the fine:

The Order offered poor cooperation with the Authority during the investigation, given that it initially asserted the lawfulness of the processing and, only in its defense brief, attributed the violation to mere human error. This has consequently aggravated the Authority's administrative efforts to ascertain the facts. In this regard, it is entirely irrelevant that, as the Authority stated, only with the appointment of the new Board of Directors was it possible to conduct a thorough investigation into the matters under complaint. Furthermore, the Order has not contributed sufficiently to the technical reconstruction of the reasons why the version of the register not intended for publication remained accessible through search engines (Article 83, paragraph 2, letter f), of the Regulations);

There are no previous relevant violations committed by the Order (Article 83, paragraph 2, letter e), of the Regulations).

Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the fine at €16,000 (sixteen thousand) for the violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter e), and paragraphs 2 and 3 of the Regulations, as well as Article 2-ter of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulations, to be effective, proportionate, and dissuasive.

It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority Regulation No. 1/2019, this chapter containing the injunction order should be published on the Data Protection Authority's website. This is in consideration of the fact that, as highlighted above, the violation continued over an extended period of time and affected numerous data subjects, exposing them to potential risks arising from the dissemination of information regarding their residence.

Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met.

NOW, THE GUARANTOR

declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Order of Nursing Professions of Pisa due to violation of Articles 5, paragraph 1, letter a), 6, paragraph 1, letter c), and 7, paragraph 2, of the Regulation. 1, letter e), and paragraphs 2 and 3 of the Regulations, as well as 2-ter of the Code, within the time limits set forth in the reasons;

ORDERS

the Order of Nursing Professions of Pisa, represented by its legal representative pro tempore, with registered office at Via P. Metastasio, 17 - 56017 San Giuliano Terme (PI), Tax Code 80006830501, to pay the sum of €16,000 (sixteen thousand) as an administrative fine for the violations indicated in the reasons. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

the aforementioned Order, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €16,000 (sixteen thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

- pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this order on the Authority's website;

- pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, October 9, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Fanizza