![]() |
A doctor was sanctioned for sharing photos of a cosmetic procedure on social media, in breach of personal-data-protection rules. Privacy protection, as is now well known, is guaranteed not only by the so-called Privacy Code but also by Regulation (EU) 2016/679, better known as the GDPR (General Data Protection Regulation). The GDPR sets out a general framework for the protection of personal data, requiring anyone processing sensitive information to adopt appropriate measures to ensure the security of the individuals concerned. "Processing" refers to any operation or set of operations which, whether or not by automated means, involves personal data. "Personal data" refers to any information relating to an identified or identifiable natural person. In addition to the general category of personal data, Article 9 of the GDPR identifies certain special categories of personal data, such as health data, the processing of which is prohibited by its very nature, save for cases specifically provided for by law. An interesting and topical case of GDPR application concerns the sanction imposed on a surgeon for publishing on social media photos of a facelift performed on a patient. The patient lodged a complaint with the Italian Data Protection Authority, complaining of the unauthorised disclosure of before-and-after images of a cosmetic procedure by the surgeon. The photographs bore the doctor's logo and clearly showed the patient's face, without her consent to disclosure. Following its investigation, the Data Protection Authority found the processing of the patient's data to be unlawful, as it breached the GDPR. Publishing the patient's images on Instagram, without a suitable legal basis for such use, amounted to an unauthorised disclosure of special-category data, also breaching Article 2-septies, paragraph 8, of the Privacy Code, which prohibits the disclosure of health, genetic and biometric data. The Data Protection Authority also stressed that it had reiterated in several similar decisions that "the publication of information concerning illness, disability or other health conditions is not permitted, and that public-facing documents must avoid processing data that is 'excessive' or 'not relevant' to the purposes of the processing". Where this is unavoidable, such information must be redacted. The Authority therefore decided to impose an administrative fine of €20,000 on the doctor for breaching Articles 5 and 9 of the GDPR, as well as Article 2-septies, paragraph 8, of the Privacy Code. The case highlights just how fundamental the protection of privacy is and, especially in the healthcare sector, an inviolable right. All those who process data and, in particular, healthcare professionals, must be aware of the legal implications of processing special-category data and of the need to adequately protect patient privacy, complying at all times with personal-data-protection rules. Before publishing images of patients on social media, it is necessary to provide the patient with a clear and precise notice of the purposes of the processing, as well as to obtain their explicit and specific consent; moreover, the patient must be able to withdraw their consent at any time pursuant to Article 7(3) GDPR. Ultimately, this case reminds us that compliance with privacy rules is not an option, but a legal as well as an ethical obligation. Copyright Leexè 2026 | riproduzione riservata |
Data protection
Privacy breach: the unauthorised publication of a patient's images.
Area of expertise
Data Protection.
GDPR, data breaches, DPO, DPIA and privacy compliance: dedicated advice for businesses and organisations.
GO