Italy, Tribunal of Udine, 20 November 2023, R.G. 308/2023
Case overview
Country
Case ID
Decision date
Deciding body (English)
Deciding body (Original)
Type of body
Type of Court (material scope)
Type of jurisdiction
Type of Court (territorial scope)
Instance
Area
Outcome of the decision
Link to the full text of the decision
General Summary
The Italian Data Protection Authority sanctioned the Regional Health Agency of Friuli Venezia Giulia Region for unlawful processing of patients' data using an algorithm. Such processing was conducted based on a decision of the Friuli Venezia Giulia Region. The Regional Health Agency thus challenged the DPA decision.
The Tribunal of Udine upheld the claim stating that, even if the Regional Agency must be considered the data controller, the data processing was compliant with the GDPR.
Facts of the case
The case concerns a series of data processing carried out by several University Hospitals based on a decision of the Friuli Venezia Giulia Region.
Such a decision authorized the use of data from the University Hospital of Central Friuli's databases to implement targeted healthcare initiatives in predictive medicine, employing AI. According to it, each hospital-affiliated doctor was required to compile a unified list of patients who had COVID-19 and were concurrently affected by other conditions (comorbidity conditions). An algorithm was used to validate the list. Patient identification and inclusion in the lists were legally grounded in the general consent given by the data subjects for healthcare purposes at the hospital.
With decision No. 416 of the 15th December 2022, the Italian Data Protection Authority sanctioned the Regional Health Agency of Friuli Venezia Giulia because the processing of health data had taken place in the absence of a suitable, specific, legal basis.
Type of measure challenged
Measures, actions, remedies claimed
Individual / collective enforcement
Nature of the parties
Claimant(s)
PublicDefendant(s)
Public
Type of procedure
Reasoning of the deciding body
The Court stated that, in this case, the data controller had to be identified with the Regional Health Authority, not the University Hospital. The processing conducted by the University Hospital could be classified as secondary processing, with the legal basis found in Article 9(2)(i) of the GDPR, which permits processing necessary for reasons of public interest in public health. This legal basis was applicable considering the emergency legislation issued by the Italian government in response to the pandemic.
In particular, the Court noted that the Italian Government responded to the pandemic with two decrees: a) Decree-Law 18/2020 allowed personal data processing for public health reasons until the end of the declared emergency, encompassing measures to protect against COVID-19, provide healthcare to the infected, and manage the national healthcare service. b) Decree-Law 34/2020 aimed to strengthen healthcare services in response to the spread of the SARS-CoV-2 virus, focusing on diagnostic assessments, monitoring, and surveillance of virus circulation, along with early care for infected individuals and those in various forms of isolation.
Additionally, according to Legislative Decree No. 16/2003 (Article 2-ter), personal data processing may also be grounded in a general administrative act. Article 14 of the GDPR was not violated, as an exception to the obligation to inform the data subject applied (Article 14(5)(d) of the GDPR). The violation of Article 35 of the GDPR (Data Protection Impact Assessment) is unfounded, as the technology used does not appear to be new.
Conclusions of the deciding body
The court stated that the data controller was the Regional Health Agency, not the specific healthcare provider. Nevertheless, it affirmed that the data processing was lawful and carried out in accordance with the GDPR.
Fundamental Right(s) involved
- Right to data protection
- Right to health (inc. right to vaccination, right to access to reproductive health)
- Right to privacy