Skip to main content

Info


General Data Protection Regulation – EU Regulation 2016/679 (GDPR) and INFORMATION ON THE PROCESSING OF PERSONAL DATA
Applicable Legislation

The “Casa Sollievo della Sofferenza” Foundation has always placed the Patient at the core of its mission, adhering not only to the highest standards of healthcare but also to the visionary principles of its saintly Founder, Padre Pio of Pietrelcina.

Ensuring comprehensive protection for Patients, all users, and the Foundation’s internal and external collaborators is considered a fundamental prerequisite for achieving excellence in healthcare and scientific research.

Privacy, both in terms of safeguarding the Patient’s personal sphere and protecting personal data—against destruction, loss, unauthorized access, unlawful processing, or processing inconsistent with the purposes for which it was collected—is ensured by the Foundation through the implementation of all possible technical and organizational measures in compliance with applicable regulations on personal data protection, specifically the General Data Protection Regulation (EU Regulation 2016/679, GDPR) and relevant Italian legislation.

Under the GDPR, the Foundation acts as the Data Controller, meaning it is responsible for ensuring the confidentiality and security of personal data while determining the purposes and means of its processing.
The Patient is the Data Subject, whose data the Foundation is committed to protecting.
Operating as part of the National Health Service, the Foundation processes Patient data primarily to safeguard their health. Personal data is also processed to meet legal obligations, including those related to civil, accounting, and tax regulations.

For additional data processing activities—such as those related to security and asset protection, scientific research, Digital Healthcare (e.g., Online Services), or genetics—the Foundation informs the Data Subject in advance and obtains their free, specific, and explicit consent.

Personal data is handled by authorized Foundation staff, who are trained and educated through continuous professional development programs.
Data may also be processed by external entities acting on behalf of the Foundation as Data Processors. These entities are appropriately instructed and required to ensure confidentiality and data protection. Disclosure of data is strictly prohibited.

The Foundation may share personal data, including “special category data” (formerly referred to as “sensitive data”) such as health-related information, with the Data Subject and with individuals authorized by the Data Subject. Additionally, data may be shared with public or private entities legally entitled or obligated to access such information.

The Data Subject, or their legal representative, can exercise their privacy rights by writing to privacy@operapadrepio.it or privacy@pec.operapadrepio.it.
Requests from the Data Subject are managed by the General Affairs, Legal, Contracts, and Privacy Protection OU – Privacy Office, where the Data Protection Officer (DPO) is based.

 

  • Contacts
  • Privacy
  • Pubblic Relations Office - URP
  • Hospital Access Guidelines