# Garante per la protezione dei dati personali (Italy) - 10254256

- Type: Enforcement
- Source: Garante per la protezione dei dati personali (Italy)
- Date: 2026-07-20
- Original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10254256
- Canonical: https://overview.legal/posts/144019
- Topics: Public Authority, Public Sector, Health Data, Law Enforcement, Data Controller, Types of Special Categories of Personal Data, Human Resources, Representatives, Risk Management System, Genetic Data

## Summary

Facts — The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who certified that the data subject was fit for service but had to be exempted from wearing a duty belt and could not hold fixed postures for long periods, the facility issued a service order assigning him to a specific operational unit. The service order referred to the data subject's "physical conditions", his "health needs" and the need for an "alternation of posture". The service order itself provided that a copy would be posted on the institute's noticeboard for publicity purposes. Copies were displayed on the noticeboard located in the bar/canteen area and in the TV/relax area, both accessible to all staff on duty but not to outsiders. Further copies were sent to the head of department, the services office, the coordinator of the records office and the penitentiary police secretariat, as well as to the trade unions, and the document was filed in the official collection of service orders. The data subject filed a complaint with the DPA. During the investigation, the controller argued that the reference to the alternation of posture did not disclose any sensitive data and merely justified the assignment decision to other staff. It also argued that, as an administrative act, the service order had to state the reasons of fact and law behind it under Article 3 of Law 241/1990, that its display and communication to the trade unions followed from transparency rules on administrative acts and from the National Framework Agreement for Penitentiary Police Personnel, and that the data subject had been notified of the order and had not objected at the time. The controller added that the order was replaced on the noticeboard after a short period and that all internal recipients were instructed and authorised to process personal data. Holding — First, the DPA held that the information in the service order constituted health data under Article 4(15) GDPR. The references to the data subject's physical conditions, health needs and the need to alternate his posture related unequivocally to his overall psychophysical state, even without any express diagnosis, and the order had been issued precisely to implement the measures prescribed by the occupational health physician under Article 42 of Legislative Decree 81/2008. The DPA also noted that the reference to the alternation of posture allowed anyone to infer the nature of the data subject's condition. Second, the DPA recalled that an employer may access the fitness-for-duty assessment and the working conditions prescribed by the occupational health physician, but only through staff specifically appointed and authorised to process such data. Making data available to persons who are not authorised to process it, even where they belong to the controller's own organisation, amounts to a communication of personal data that requires a legal basis under Article 2-ter of the Italian Data Protection Code and, for health data, under Article 9 GDPR. The DPA found that the display of the order on a noticeboard accessible to all staff, and its transmission to the trade unions, made the data available to colleagues and third parties who had no need to know it. Access should have been restricted, on strict proportionality grounds, to the staff responsible for actually implementing the measures in the exercise of managerial and organisational functions. Therefore, the DPA found a violation of Articles 5(1)(a), 6 and 9 GDPR and Article 2-ter of the Italian Data Protection Code. Third, the DPA rejected the controller's justification based on the duty to give reasons for an administrative act. The document remained in full in the administration's files and was accessible to anyone demonstrating a direct, concrete and current interest under Articles 22 of Law 241/1990 and Articles 59 and 60 of the Italian Data Protection Code. A generic reference to transparency rules on administrative acts was not sufficient either, since those rules do not provide for disclosure by way of noticeboard display. Fourth, the DPA held that collective agreements cannot constitute an appropriate legal basis for a communication of personal data. Collective agreements may only specify, in favour of employees, a framework already laid down by national legislation and cannot introduce a new processing operation not provided for by law. The DPA added that, even where union prerogatives do entail communications to trade unions, these must comply with the necessity principle and be accompanied by specific safeguards, all the more so where the data concern the most intimate sphere of the person. Finally, the DPA classified the gravity of the violation as medium. It considered that the case concerned a single data subject and that the order remained on the noticeboard for a very short time, but also that the conduct reflected an ordinary practice based on collective agreements. The violation was negligent, as the controller had acted in the mistaken belief that it was complying with the applicable rules. As mitigating factors, the DPA took into account the controller's full cooperation during the investigation and the absence of relevant previous violations at the facility concerned. On these grounds, the DPA fined the controller €12,000.

## Full text

[web doc. no. 10254256] Provision of April 29, 2026 Register of Provisions No. 304 of April 29, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having regard to the documentation in the file; Having regard to the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction. By complaint filed on XX, Mr. XX, serving at the Cosenza "Sergio Cosmai" prison, complaining of an alleged violation of the legislation on the protection of personal data, stated that, on XX, service order No. XX of XX was posted on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the aforementioned prison. This order contained information on his health and ordered his deployment to a specific operational unit in accordance with the doctor's prescriptions. (see, in particular, the references to the complainant's "physical condition," his "health needs," and the need for "altered posture"). The service order shows that the notice was formally posted on the noticeboard via the service order itself ("The Penal Police Secretariat will [...] post a copy on the Institute's noticeboard for publicity purposes") and that a copy of this document was also "delivered to the Unit Commander, the Services Office, the Coordinator of the Registration Office, the Public Prosecutor's Office," as well as "to the Trade Unions," and included "in the official records." 2. The preliminary investigation. Regarding the alleged facts, during the preliminary investigation, the aforementioned prison, in a note dated XX, stated, in particular, that: the competent doctor "with certification dated XX communicated the employee's fitness for service, also specifying that "...he must therefore be exempt from wearing a safety belt, and must not maintain prolonged fixed postures, favoring a sitting posture... he may be employed... in positions such as: concierge, switchboard, control room, office, or other similar positions..."; "the reference to "alternating postures," upon closer inspection, did not entail any disclosure of sensitive data, being merely a prescription from the competent doctor, necessary to justify, in the eyes of the staff, the adoption of the assignment measure"; this also considering that this measure "was adopted in excess of the available positions"; "Service Order No. XX of XX, as an administrative measure, is subject to the obligation to explain, and in part justify, the reasons in fact and in law that led the Public Administration to issue the measure (Article 3 of Law 241/1990) following a careful balancing of interests. This is all the more true given that, as in the case at hand, it concerns a personnel employment measure issued in derogation from the ordinary procedures established by decentralized bargaining. "Pursuant to current legislation regarding transparency and publicity of administrative documents, the O.D.S. in question, like all service orders pertaining to the organization of work and personnel employment, was communicated to the trade unions. and simultaneously posted on the Institute's official noticeboard, a location accessible only to staff working at the Home, excluding third parties"; "Furthermore, the Service Order was immediately notified to [… complainant], who could well have stated immediately that he did not agree with the methods of publicizing the document"; "Regarding the transmission of the aforementioned Service Order to the other parties indicated therein […], it is reiterated that such communication is dictated by clear service reasons, as well as by the aforementioned need to comply with current legislation regarding the transparency and publicity of administrative documents"; "Regarding […] "official collection," it is stated that this refers to the official collection of Service Orders, for the purpose of preserving their originals, by the Institute's General Affairs Secretariat, a sector belonging to the Secretariat Area, headed by an Organization and Relations Officer. On this point, it is specified that the persons authorized to consult [...] are the Director of the Institute and the Head of the Secretariat Area, while some employees assigned to the Secretariat Office are responsible [...] for the registration of Service Orders. With a note dated XX, the Office, based on the information acquired, the checks carried out, and the facts that emerged following the preliminary investigation, notified the Ministry of Justice, pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the provisions referred to in Article 58, paragraph 2, of the Regulation, on the basis that the processing of the complainant's data in the specific case—consisting of the communication of the complainant's data, contained in service order no. XX of XX, to all employees and trade unions at the aforementioned prison, as processing entirely attributable to the aforementioned Ministry—had occurred in a manner that did not comply with the principle of "lawfulness, fairness, and transparency" and in lack of an appropriate regulatory basis, in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulations and Article 2-ter of the Code. With the same notice, the aforementioned holder was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). On 20th, the Ministry filed its written defenses, declaring, in particular, that: Since, following notification of the service order in question to the complainant, the latter "did not express any complaint regarding the manner in which the document was published," the prison "was not put in a position to act promptly, possibly adopting further measures: for example, omitting certain data (which had already been minimized) received by the interested party as prejudicial to his privacy"; "the service order [… in question] was replaced by the secretariat staff after a short period of time"; "the provision regarding the sending of information to the trade unions, contained in the service order in question, falls within the mandatory information set forth in Article 4 "Participation, Information, and Examination System" and Article 5 "Prerogatives of the Trade Unions" of the National Framework Agreement for Penitentiary Police Personnel, incorporated into the Regional Decentralized Agreement and the Local Decentralized Agreements." During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX (see minutes of XX, formalized with the relevant acceptance by the data controller, transmitted on XX), the Ministry stated, in particular, that "the communication of service orders to the trade unions, as well as the posting of service orders on the prison's noticeboard, is required of the prison by the agreements in place between the Administration itself and the trade unions." 3. Outcome of the preliminary investigation. In stating that the processing of personal data carried out, in the context of the matter under examination, by the administrative staff serving at the Cosenza "Sergio Cosmai" prison is entirely attributable to the Ministry of Justice, as data controller (see, specifically, Article 16, paragraph 3, of Legislative Decree 300/1999), is the following: Following the investigation, it emerged in particular that, in accordance with the prescriptions formulated by the competent doctor, the aforementioned prison arranged for the appellant to be employed in a specific operational unit with service order no. XX of XX, which contained references to his "physical condition," his "health needs," and the need for "alternating posture." In this context, it is established, in particular, that, in the alleged implementation of specific provisions of the applicable collective agreements, a copy of this service order was posted on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the prison, closed to outsiders but accessible to all staff on duty, with the aim of ensuring publicity and transparency and "justifying, in the eyes of the personnel, the adoption of the assignment provision”, which was also taken “in excess of the available positions”; the same copy was also sent “to the Department Commander, the Services Office, the Coordinator of the Registration Office, the Public Prosecutor’s Secretariat Office”, as well as “to the Trade Unions” and inserted “in the official collection”. In this regard, it is generally noted that, pursuant to the current regulatory framework on personal data protection, public bodies, including when acting as employers, may process employees' personal data if the processing is necessary, in general, for the management of the employment relationship and for compliance with a legal obligation to which the controller is subject (Articles 6(1)(c), 9(2)(b), 9(4), and 88 of the Regulation) or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the Regulation and Article 2-ter of the Code; with reference to special categories of data, see also Articles 2-sexies and 2-septies of the Code). Such processing must, however, be based on Union or Member State law, in order to pursue an objective of public interest and be proportionate to the pursuit of that objective. The purpose of the processing must, in fact, be necessary for the performance of an obligation under applicable law or a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 6, paragraphs 2 and 3, of the Regulation and Article 2-ter of the Code). National legislation has introduced more specific provisions to adapt the application of the Regulation's provisions, more precisely determining specific requirements and other measures to ensure lawful and fair processing (Article 6, paragraph 2 of the Regulation). In this context, it has established that processing operations consisting of the "communication" of personal data are admissible where there is an appropriate legal basis (Article 2-ter of the Code). The employer, as data controller, is required in any case to comply with data protection principles, including, in particular, those of "lawfulness, fairness, and transparency," "data minimization," and "data protection by default" (Articles 5, paragraph 1, letters a) and c), and 25, paragraph 2, of the Regulation). More specifically, regarding the processing of personal data contained in the document containing the assessment of suitability expressed by the competent doctor, it should be noted first of all that, pursuant to the regulations on health and safety in the workplace, while the competent doctor, within the scope of his health surveillance activities, is the only person authorised to process data relating to workers' health and to verify their suitability for the "specific task" (Articles 25, 39, paragraph 5, and 41, paragraph 4, of Legislative Decree no. 81/2008), the employer is instead required, in particular, to ensure that employees "are not assigned to the specific work task without the required assessment of suitability" (e.g., Article 18, paragraph 1, letters g) and bb), of Legislative Decree no. 81/2008) and to implement the measures indicated by the competent doctor, assigning the worker, where possible, to equivalent or inferior duties if deemed unsuitable for the specific job, and ensuring that they receive treatment commensurate with their previous duties (Article 42 of Legislative Decree No. 81/2008). In this context, as specified by the Guarantor, the "information relating, for example, to the diagnosis or family history of the worker [cannot] be processed in any way by the employer, except to the extent of the mere assessment of suitability for the specific task and any prescriptions that the professional establishes as working conditions" (see the XX Guidance Document containing "The role of the "competent doctor" in matters of safety in the workplace, also with reference to the emergency context", web doc. n. 958536; see, in this sense, also point 3.2 of the "Guidelines on the processing of personal data of workers for the purposes of managing the employment relationship in the public sector", provision of 14 June 2007, published in the Official Journal 13 July 2007, n. 161 and in www.garanteprivacy.it, web doc. n. 1417809, for which the employer "can access the assessment of the worker's suitability for performing certain tasks, rather than the specific pathologies identified"). It follows, therefore, that, within the sectoral regulatory framework outlined above, the employer must be able to access information relating to the assessment of employees' suitability for the specific task and, in particular, any prescriptions defined by the competent doctor as working conditions. Access to such information must, however, take place, within the organizational context of the employee's Administration, exclusively through the personnel assigned and specifically authorized to process it, also taking into account the particularly sensitive nature of the data in question, which undoubtedly falls within the category of "health data" pursuant to Articles 4, no. 15, and 9 of the Regulation (see also recital 35 of the Regulation). From this perspective, with regard to the specific case, it should first be noted that the information contained in service order no. XX of XX – in particular, references to the data subject's need for "alternating posture," his "physical condition," and his "health needs" – constitute data relating to health, unequivocally referring to the dimension of his overall psychophysical state, even regardless of the express and specific indication of a diagnosis (see, in this regard, provision of January 16, 2026, no. 1, web doc. no. 10220288, and the provisions cited therein; see also ECJ judgment C-667/21, Krankenversicherung Nordrhein, of December 21, 2023, para. 41). This is contrary to what the data controller claimed during the investigation, especially given the fact that this service order was adopted by the prison precisely in implementation of the measures indicated by the competent doctor in exercising the prerogatives granted to him by the regulatory framework regarding health and safety in the workplace (Article 42 of Legislative Decree No. 81/2008), as clearly highlighted in the service order itself. Considering the above, it is stated that employees' personal data, including data relating to their health, cannot, as a rule, be disclosed to those who do not need to process them due to their assigned duties and specific role within the data controller's organization and who, consequently, have not been expressly "authorized" to process them (see Articles 4, No. 10, 28, paragraph 3, letter b), 29, and 32, paragraph 4, of the Regulation, as well as Article 11, paragraph 1, of the GDPR. 2-quaterdecies of the Code). This is because, as the Garante has repeatedly stated, making data available to individuals who, even if they are part of the data controller's organization, are not "authorized" to process it by virtue of the functions they perform within that organization, may give rise, also taking into account the definition of "third party" contained in Article 4, paragraph 1, no. 10, of the Regulation, to an unlawful "communication" of personal data as it lacks an appropriate legal basis (see Article 2-ter, paragraphs 1 and 3, of the Code and, in the event that the data being communicated belongs to special categories, Article 9 of the Regulation). As the Italian Data Protection Authority has repeatedly stated, making data available to parties who do not need to process it under applicable law or who, even though they are part of the data controller's organization, are not "authorized" to process it due to the functions performed within that organization and the controller's specific organizational choices, may give rise, also taking into account the definition of "third party" contained in Article 4, paragraph 1, no. 10, of the Regulation, to an unlawful "communication" of personal data as it lacks an appropriate legal basis (see Article 2-ter, paragraphs 1 and 3, of the Code and, in the event that the data being communicated belongs to special categories, Article 9, paragraph 2, letter b), of the Regulation). Furthermore, especially in cases where the employer is required to process, for purposes of managing the employment relationship, information pertaining to the health of workers, the employer is required to observe "special precautions," taking care, among other things, to avoid any unnecessary and unjustified access to the data by unauthorized persons (see paragraph 8 of the aforementioned Guidelines). Conversely, no violation of personal data protection regulations can be found in cases where individuals with specific tasks or responsibilities gain access to personal data of data subjects when, based on the organizational and technical decisions of the data controller, this is specifically necessary for the performance of their assigned duties. These principles have been applied by the Guarantor with a consolidated approach, in relation to different situations, in numerous specific cases (see, with particular regard to the posting on notice boards of documents containing workers' personal data, provision of 27 May 2021, no. 214, web doc. no. 9689234, and provisions referred to therein; see also, more generally, among the many, provisions of 16 January 2026, no. 1, web doc. no. 10220288; 27 February 2025, no. 101, web doc. no. 10123227; 27 February 2025, no. 92, web doc. no. 10114763; 3 February 2025, no. 70, web doc. no. 10118395; January 30, 2025, no. 36, web doc. no. 10112750; September 26, 2024, no. 606, web doc. no. 10068155; June 1, 2023, no. 223, web doc. no. 9916798; March 23, 2023, no. 82, web doc. no. 9885151; February 23, 2023, no. 43, web doc. no. 9868646; September 16, 2021, no. 322, web doc. no. 9711517; May 27, 2021, no. 214, web doc. 9689234; June 18, 2020, no. 105, web doc. no. 9444865; March 24, 2022, no. 98, web doc. no. 976305; February 11, 2021, no. 50, web doc. no. 9562866; July 31, 2014, no. 392, web doc. no. 3399423; October 3, 2013, no. 431, web doc. 2747867; May 8, 2013, no. 232, web doc. no. 2501216; October 18, 2012, no. 296, web doc. nos. 2174351 and 297, web doc. no. 2174582). With regard to the specific case, we note, first of all, that, in light of the declarations made by the data controller pursuant to Article 168 of the Code, the complainant's personal data, contained within the aforementioned service order and also relating to his health, were made available to the Department Commander, the Services Office, the Coordinator of the assigned operational unit, and the Public Prosecutor's Office for "service reasons" and, specifically, "for the execution and consequent obligations," as these individuals are "all [...] trained and authorized to process personal data" (see note of XX). We also note that "the individuals authorized to consult the Service Orders stored in the House's official collection [...] are also responsible for recording the Service Orders" (see note of XX). However, with regard to the posting of the aforementioned service order on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the prison, accessible to all staff on duty, and its transmission to the trade unions, no specific evidence emerged from the documents proving the legitimacy of the resulting "communication" of the complainant's personal data. Specifically, no suitable reasons were identified that, also considering the roles and functions performed by the aforementioned recipients within the prison's organizational structure, could justify the processing of the data contained therein by all the employees on duty, therefore colleagues of the complainant, and by the trade unions, the "recipients" of the aforementioned data and unauthorized "third parties" (see Article 4, paragraphs 9 and 10, of the Regulation). Indeed, it must be considered that the information relating to the measures prescribed to the complainant by the competent doctor in the specific case could not have been known indiscriminately by all the staff of the prison, since access to such information must be reserved, in a perspective of rigorous proportionality, only to the staff responsible for its concrete implementation in the exercise of the employer's managerial and organizational prerogatives, with particular regard to the planning and distribution of work as well as the management and allocation of human resources (art. 42 of Legislative Decree no. 81/2008; see in this regard, for similar considerations, the aforementioned provision of 27 May 2021, no. 214, web doc. no. 9689234; see also, in relation to the hypothesis in which, for reasons of work organization, for example in the context of the preparation of service shifts, it is made available to subjects other than the interested party - such as others Colleagues - data relating to attendance and absence from work, Provision containing the requirements relating to the processing of special categories of data, pursuant to Article 21, paragraph 1 of Legislative Decree No. 101 of August 10, 2018, No. 146 of June 5, 2019, web doc. No. 9124510, see Annex 1, paragraph 1.5, letter d), which provides that the employer must not specify, even through acronyms or abbreviations, the reasons for absence from which it is possible to infer the knowledge of special categories of personal data, especially if of a health-related nature. From this perspective, contrary to what the owner claimed during the preliminary investigation, it cannot be considered that the explicit references to the measures prescribed to the complainant by the competent doctor, contained within the service order in question, were necessary in order to ensure, also "in the eyes of the staff", adequate justification for such a measure, which was also adopted "in excess of the available administrative positions" (see note of XX); In any case, this document remains in the Administration's records in its entirety and is accessible—when the specific requirements are met, also taking into account the rank of the data subject's rights, as required by law to ensure transparency and participation in administrative proceedings—to anyone who demonstrates a direct, concrete, and current interest, corresponding to a legally protected situation and connected to the document to which access is requested (Articles 22 et seq., Law No. 241 of 7 August 1990; Articles 59 and 60 of the Code, which specifically state that "when the processing concerns genetic data, data relating to health, sex life, or sexual orientation of a person, the processing is permitted if the legally relevant situation sought to be protected by the request for access to administrative documents is at least as important as the data subject's rights, or consists of a personality right or another fundamental right or freedom"). Nor are the reasons advanced during the investigation by the data controller regarding the stated need to ensure the publicity and transparency of such organizational arrangements in this context relevant. A generic reference to the "current legislation on transparency and publicity of administrative acts" (see note of XX) cannot be considered sufficient for this purpose. This legislation, however, does not provide for forms of document disclosure such as those implemented in this case by posting notices on noticeboards. Furthermore, the alleged implementation of collective agreements applicable to prison administration cannot be invoked in this regard, given that, as highlighted above, the "communication" of personal data (Article 2-ter, paragraph 4, letter a), of the Code) can be considered permitted by data protection legislation, for the fulfillment of obligations and the exercise of rights in the field of employment law, only in the presence of an appropriate legal basis as provided for by Article 2-ter, paragraph 4, letter a), of the Code. 2-ter, paragraphs 1 and 3, of the Code. In this context, in particular, the legal basis for processing must be "appropriate," also in light of the structure of the Member State's "constitutional order" (see recital 41 of the Regulation and also Constitutional Court ruling no. 271/2005, according to which the regulation of personal data protection falls within the exclusive jurisdiction of the State, referred to as "civil law"), and it must meet specific requirements, both in terms of the quality of the source, necessary content, and appropriate and specific measures to protect the rights and freedoms of data subjects, and in terms of the proportionality of the regulatory intervention with respect to the intended purposes (Article 6, paragraphs 2 and 3, letter b), of the Regulation). In this sense, within the European framework of data protection regulation, in the interests of legal certainty and the principle of non-discrimination, and in line with what was recently reiterated by the Italian Data Protection Authority, in the absence of a regulatory provision that satisfies the aforementioned requirements for an appropriate legal basis, differentiated levels of personal data protection would not be permitted at the territorial level or within individual administrations, or between different public workplaces, and between these and private workplaces. These principles have been reaffirmed by the Guarantor, even recently, in numerous provisions (see, in particular, among others, provision no. 287 of 6 July 2023, web doc. no. 9920145, which confirmed the unsuitability of the provisions contained within collective agreements to innovate the legal system in terms of the processing of personal data; provision no. 125 of 13 April 2023, web doc. no. 9907846, which, more specifically, clarified that collective agreements must limit themselves to detailing for the benefit of the employees concerned the regulatory framework already established at the national level and cannot provide for or justify in any way the introduction of a new processing not provided for by national legislation; see also, for similar considerations in relation to the introduction by regional ordinance of the processing of employees' personal data in the emergency context due to the spread of the Covid-19 virus, provision no. of 22 July 2021, no. 273, web doc. no. 9683814). In particular, national and supplementary collective agreements may contain specific and detailed provisions within the limits and scope assigned to them by law or regulation (see recital 41 and Article 88 of the Regulation; see Recommendation of 1 April 2015, CM/Rec(2015)5, on the processing of personal data in the employment context, paragraph 7: "In accordance with national laws and practices or provisions contained in collective agreements, personal data may be communicated to employee representatives only to the extent that such data are necessary to enable them to adequately represent the interests of employees or if such data are necessary for the fulfillment and monitoring of obligations set out in collective agreements"). Pursuant to industry regulations, collective bargaining only regulates certain aspects of the employment relationship (for example, see Article 40 of Legislative Decree No. 165/2001, which mentions performance evaluation for the purpose of awarding additional compensation), which are already expressly identified by law, requiring this to occur "within the limits established by law" (Article 40 of Legislative Decree 165/2001). It should also be noted that, specifically with regard to the disclosure of personal data to trade unions, even with regard to data not belonging to special categories, the Authority has provided clarifications to the Agency for the Negotiation Representation of Public Administrations - ARAN, the Ministry of Education, and the State Attorney's Office regarding the legitimacy of requests made by trade unions pursuant to a national collective agreement of the so-called "contractual agreement". "school sector", to know the additional compensation paid to school employees, highlighting in that case, in particular, that the aforementioned collective agreement did not constitute an appropriate legal basis and that, "in the absence of a regulatory provision that satisfies the requirements set forth by data protection legislation," personal data relating to workers cannot be lawfully communicated to trade unions (see note prot. no. XX of XX). This position of the Guarantor on this point was subsequently confirmed by the Council of State, which - in expressly referring to the aforementioned note prot. no. XX of XX - specified that "the provision of personal data to trade unions entails a "communication" and that collective agreements can integrate the regulatory provisions to allow trade unions to adequately represent the interests of employees, or when it is necessary to fulfill the obligations set forth in the same agreements" (see State Council Section VII, Sentence 9 August 2022, no. 7064) within the framework of the purposes and conditions established by the applicable legislation (this occurs, for example, in the case of serious subjective conditions of workers or their family members in the presence of which the employer may grant, also on the basis of collective agreements, the performance of work in a smart working manner, see Law 53/2000 and Ministerial Decree 278/2000). In any case, always with specific regard to the communication of the data in question to trade unions, the Garante has traditionally identified the conditions governing the flow of personal data from employer administrations to trade unions, emphasizing that, even in the presence of specific provisions establishing trade union prerogatives that require the communication of information to such organizations, such communication must be carried out in compliance with the principle of necessity, with specific measures to protect the data subjects being implemented within this framework (see point 2.3 of the Guidelines cited several times above), especially if, as in the case at hand, the personal data being processed relates to the most intimate sphere of the individual and his or her dignity. Given the above, it appears that the processing in question—consisting of the communication of the complainant's data, contained in service order no. XX of XX, including those relating to his health, the generality of employees, and trade union organizations, at the Cosenza "Sergio Cosmai" prison, as processing activities are entirely attributable to the Ministry of Justice—occurred in a manner that does not comply with the principles of "lawfulness, fairness, and transparency" and in the absence of an appropriate regulatory basis, in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code. 4. Conclusions. In light of the above considerations, it is found that the statements made by the data controller during the investigation—the veracity of which may be held accountable pursuant to Article 168 of the Code, although worthy of consideration, do not overcome the concerns notified by the Office with the notice initiating the proceedings and are insufficient to allow the dismissal of this proceeding, given that none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply. The Office's preliminary assessments are therefore confirmed and the Ministry of Justice's processing of personal data is found to be unlawful, having processed the complainant's personal data in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single conduct (the same processing or related processing), Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Given that, in this case, the most serious violations, relating to Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code, are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000. In this context, considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are not met. 5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code). The Guarantor, pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code, with regard to the application of the additional administrative sanction, pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019). In this regard, taking into account Article 83, paragraph 3 of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. The aforementioned administrative pecuniary sanction imposed, depending on the circumstances of each individual case, must be determined in amount, taking into due consideration the factors set forth in Article 83, paragraph 2, of the Regulation. Considering that: The incident in question involved only one interested party, while it must also be noted that, according to the information provided, it constitutes an expression of ordinary practice, as evidenced by the documents showing that service order no. XX of XX was posted on the noticeboard and communicated to the trade unions in implementation of specific provisions of collective agreements; In any case, the documentation in the file shows that in this case, the service order remained posted on the noticeboard for a particularly short period of time (Article 83, paragraph 2, letter a), of the Regulations); Considering all the circumstances of the specific case, the violation is negligent, as the processing was carried out in the mistaken belief that it was acting in accordance with the applicable law (Article 83, paragraph 2, letter b), of the Regulations); The information processed in this case, relating to the data subject's health (see Article 9 of the Regulation), does not provide evidence of the data subject's diagnosis, despite the fact that the information contained in the service order and the measures prescribed by the competent physician constitute, by their very nature, health data and also allow anyone to deduce the nature of the ailments suffered by the complainant (see in particular the reference to "altered posture"; see Article 83, paragraph 2, letter g), of the Regulation). In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of 24 May 2023, point 60). Given the above, taking into account the complex and multifaceted organizational structure of the Penitentiary Administration, which is headed by the Ministry, it is believed that, for the purposes of quantifying the fine, the following circumstances must be taken into consideration: The prison manager offered full cooperation with the Authority during the investigation (Article 83, paragraph 2, letter f), of the Regulation); There are no previous relevant violations within the Cosenza "Sergio Cosmai" prison, within the territorial branches of the Ministry of Justice, the data controller (Article 83, paragraph 2, letter e), of the Regulation). Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the fine at €12,000.00 (twelve thousand/00) for the violation of Articles 5, paragraph 1, letter e), and 5, paragraph 1, letter f). a), 6, and 9 of the Regulation, and 2-ter of the Code, as an administrative pecuniary sanction deemed, pursuant to Art. 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. It is also believed that, pursuant to Art. 166, paragraph 7, of the Code and Art. 16, paragraph 1, of the Regulation of the Italian Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is because the communication, made in the absence of an appropriate legal basis, nevertheless concerned data relating to the health of a worker. Finally, it is noted that the conditions set forth in Art. 17 of Regulation No. 1/2019 are met. NOW CONSIDERING ALL THE FOREGOING, THE GUARANTOR declares, pursuant to Art. 57, paragraph 1, letter a) of the Italian Data Protection Authority (Garante), f) of the Regulation, the unlawfulness of the processing carried out by the Ministry of Justice for violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code, within the time limits set out in the grounds; ORDERS the Ministry of Justice, represented by its legal representative pro tempore, with registered office at Via Arenula, 70 - 00186 Rome (RM), Tax Code 80184430587, to pay the sum of €12,000.00 (twelve thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDER that the aforementioned Ministry, in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, pay the sum of €12,000.00 (twelve thousand/00) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this provision on the Authority's website; - pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, April 29, 2026 THE PRESIDENT Stanzione THE REPORTER Stanzione THE SECRETARY GENERAL Montuori [web doc. no. 10254256] Measure of April 29, 2026 Register of Measures no. 304 of April 29, 2026 THE DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "Regulation"); HAVING REGARD TO Legislative Decree no. 196 of 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having regard to the documentation in the file; Having regard to the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction. By complaint filed on XX, Mr. XX, serving at the Cosenza "Sergio Cosmai" prison, complaining of an alleged violation of the legislation on the protection of personal data, stated that, on XX, service order No. XX of XX was posted on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the aforementioned prison. This order contained information on his health and ordered his deployment to a specific operational unit in accordance with the doctor's prescriptions. (see, in particular, the references to the complainant's "physical condition," his "health needs," and the need for "altered posture"). The service order shows that the notice was formally posted on the noticeboard via the service order itself ("The Penal Police Secretariat will [...] post a copy on the Institute's noticeboard for publicity purposes") and that a copy of this document was also "delivered to the Unit Commander, the Services Office, the Coordinator of the Registration Office, the Public Prosecutor's Office," as well as "to the Trade Unions," and included "in the official records." 2. The preliminary investigation. Regarding the alleged facts, during the preliminary investigation, the aforementioned prison, in a note dated XX, stated, in particular, that: the competent doctor "with certification dated XX communicated the employee's fitness for service, also specifying that "...he must therefore be exempt from wearing a safety belt, and must not maintain prolonged fixed postures, favoring a sitting posture... he may be employed... in positions such as: concierge, switchboard, control room, office, or other similar positions..."; "the reference to "alternating postures," upon closer inspection, did not entail any disclosure of sensitive data, being merely a prescription from the competent doctor, necessary to justify, in the eyes of the staff, the adoption of the assignment measure"; this also considering that this measure "was adopted in excess of the available positions"; "Service Order No. XX of XX, as an administrative measure, is subject to the obligation to explain, and in part justify, the reasons in fact and in law that led the Public Administration to issue the measure (Article 3 of Law 241/1990) following a careful balancing of interests. This is all the more true given that, as in the case at hand, it concerns a personnel employment measure issued in derogation from the ordinary procedures established by decentralized bargaining. "Pursuant to current legislation regarding transparency and publicity of administrative documents, the O.D.S. in question, like all service orders pertaining to the organization of work and personnel employment, was communicated to the trade unions. and simultaneously posted on the Institute's official noticeboard, a location accessible only to staff working at the Home, excluding third parties"; "Furthermore, the Service Order was immediately notified to [… complainant], who could well have stated immediately that he did not agree with the methods of publicizing the document"; "Regarding the transmission of the aforementioned Service Order to the other parties indicated therein […], it is reiterated that such communication is dictated by clear service reasons, as well as by the aforementioned need to comply with current legislation regarding the transparency and publicity of administrative documents"; "Regarding […] "official collection," it is stated that this refers to the official collection of Service Orders, for the purpose of preserving their originals, by the Institute's General Affairs Secretariat, a sector belonging to the Secretariat Area, headed by an Organization and Relations Officer. On this point, it is specified that the persons authorized to consult [...] are the Director of the Institute and the Head of the Secretariat Area, while some employees assigned to the Secretariat Office are responsible [...] for the registration of Service Orders. With a note dated XX, the Office, based on the information acquired, the checks carried out, and the facts that emerged following the preliminary investigation, notified the Ministry of Justice, pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the provisions referred to in Article 58, paragraph 2, of the Regulation, on the basis that the processing of the complainant's data in the specific case—consisting of the communication of the complainant's data, contained in service order no. XX of XX, to all employees and trade unions at the aforementioned prison, as processing entirely attributable to the aforementioned Ministry—had occurred in a manner that did not comply with the principle of "lawfulness, fairness, and transparency" and in lack of an appropriate regulatory basis, in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulations and Article 2-ter of the Code. With the same notice, the aforementioned holder was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). On 20th, the Ministry filed its written defenses, declaring, in particular, that: Since, following notification of the service order in question to the complainant, the latter "did not express any complaint regarding the manner in which the document was published," the prison "was not put in a position to act promptly, possibly adopting further measures: for example, omitting certain data (which had already been minimized) received by the interested party as prejudicial to his privacy"; "the service order [… in question] was replaced by the secretariat staff after a short period of time"; "the provision regarding the sending of information to the trade unions, contained in the service order in question, falls within the mandatory information set forth in Article 4 "Participation, Information, and Examination System" and Article 5 "Prerogatives of the Trade Unions" of the National Framework Agreement for Penitentiary Police Personnel, incorporated into the Regional Decentralized Agreement and the Local Decentralized Agreements." During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on XX (see minutes of XX, formalized with the relevant acceptance by the data controller, transmitted on XX), the Ministry stated, in particular, that "the communication of service orders to the trade unions, as well as the posting of service orders on the prison's noticeboard, is required of the prison by the agreements in place between the Administration itself and the trade unions." 3. Outcome of the preliminary investigation. In stating that the processing of personal data carried out, in the context of the matter under examination, by the administrative staff serving at the Cosenza "Sergio Cosmai" prison is entirely attributable to the Ministry of Justice, as data controller (see, specifically, Article 16, paragraph 3, of Legislative Decree 300/1999), is the following: Following the investigation, it emerged in particular that, in accordance with the prescriptions formulated by the competent doctor, the aforementioned prison arranged for the appellant to be employed in a specific operational unit with service order no. XX of XX, which contained references to his "physical condition," his "health needs," and the need for "alternating posture." In this context, it is established, in particular, that, in the alleged implementation of specific provisions of the applicable collective agreements, a copy of this service order was posted on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the prison, closed to outsiders but accessible to all staff on duty, with the aim of ensuring publicity and transparency and "justifying, in the eyes of the personnel, the adoption of the assignment provision”, which was also taken “in excess of the available positions”; the same copy was also sent “to the Department Commander, the Services Office, the Coordinator of the Registration Office, the Public Prosecutor’s Secretariat Office”, as well as “to the Trade Unions” and inserted “in the official collection”. In this regard, it is generally noted that, pursuant to the current regulatory framework on personal data protection, public bodies, including when acting as employers, may process employees' personal data if the processing is necessary, in general, for the management of the employment relationship and for compliance with a legal obligation to which the controller is subject (Articles 6(1)(c), 9(2)(b), 9(4), and 88 of the Regulation) or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the Regulation and Article 2-ter of the Code; with reference to special categories of data, see also Articles 2-sexies and 2-septies of the Code). Such processing must, however, be based on Union or Member State law, in order to pursue an objective of public interest and be proportionate to the pursuit of that objective. The purpose of the processing must, in fact, be necessary for the performance of an obligation under applicable law or a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 6, paragraphs 2 and 3, of the Regulation and Article 2-ter of the Code). National legislation has introduced more specific provisions to adapt the application of the Regulation's provisions, more precisely determining specific requirements and other measures to ensure lawful and fair processing (Article 6, paragraph 2 of the Regulation). In this context, it has established that processing operations consisting of the "communication" of personal data are admissible where there is an appropriate legal basis (Article 2-ter of the Code). The employer, as data controller, is required in any case to comply with data protection principles, including, in particular, those of "lawfulness, fairness, and transparency," "data minimization," and "data protection by default" (Articles 5, paragraph 1, letters a) and c), and 25, paragraph 2, of the Regulation). More specifically, regarding the processing of personal data contained in the document containing the assessment of suitability expressed by the competent doctor, it should be noted first of all that, pursuant to the regulations on health and safety in the workplace, while the competent doctor, within the scope of his health surveillance activities, is the only person authorised to process data relating to workers' health and to verify their suitability for the "specific task" (Articles 25, 39, paragraph 5, and 41, paragraph 4, of Legislative Decree no. 81/2008), the employer is instead required, in particular, to ensure that employees "are not assigned to the specific work task without the required assessment of suitability" (e.g., Article 18, paragraph 1, letters g) and bb), of Legislative Decree no. 81/2008) and to implement the measures indicated by the competent doctor, assigning the worker, where possible, to equivalent or inferior duties if deemed unsuitable for the specific job, and ensuring that they receive treatment commensurate with their previous duties (Article 42 of Legislative Decree No. 81/2008). In this context, as specified by the Guarantor, the "information relating, for example, to the diagnosis or family history of the worker [cannot] be processed in any way by the employer, except to the extent of the mere assessment of suitability for the specific task and any prescriptions that the professional establishes as working conditions" (see the XX Guidance Document containing "The role of the "competent doctor" in matters of safety in the workplace, also with reference to the emergency context", web doc. n. 958536; see, in this sense, also point 3.2 of the "Guidelines on the processing of personal data of workers for the purposes of managing the employment relationship in the public sector", provision of 14 June 2007, published in the Official Journal 13 July 2007, n. 161 and in www.garanteprivacy.it, web doc. n. 1417809, for which the employer "can access the assessment of the worker's suitability for performing certain tasks, rather than the specific pathologies identified"). It follows, therefore, that, within the sectoral regulatory framework outlined above, the employer must be able to access information relating to the assessment of employees' suitability for the specific task and, in particular, any prescriptions defined by the competent doctor as working conditions. Access to such information must, however, take place, within the organizational context of the employee's Administration, exclusively through the personnel assigned and specifically authorized to process it, also taking into account the particularly sensitive nature of the data in question, which undoubtedly falls within the category of "health data" pursuant to Articles 4, no. 15, and 9 of the Regulation (see also recital 35 of the Regulation). From this perspective, with regard to the specific case, it should first be noted that the information contained in service order no. XX of XX – in particular, references to the data subject's need for "alternating posture," his "physical condition," and his "health needs" – constitute data relating to health, unequivocally referring to the dimension of his overall psychophysical state, even regardless of the express and specific indication of a diagnosis (see, in this regard, provision of January 16, 2026, no. 1, web doc. no. 10220288, and the provisions cited therein; see also ECJ judgment C-667/21, Krankenversicherung Nordrhein, of December 21, 2023, para. 41). This is contrary to what the data controller claimed during the investigation, especially given the fact that this service order was adopted by the prison precisely in implementation of the measures indicated by the competent doctor in exercising the prerogatives granted to him by the regulatory framework regarding health and safety in the workplace (Article 42 of Legislative Decree No. 81/2008), as clearly highlighted in the service order itself. Considering the above, it is stated that employees' personal data, including data relating to their health, cannot, as a rule, be disclosed to those who do not need to process them due to their assigned duties and specific role within the data controller's organization and who, consequently, have not been expressly "authorized" to process them (see Articles 4, No. 10, 28, paragraph 3, letter b), 29, and 32, paragraph 4, of the Regulation, as well as Article 11, paragraph 1, of the GDPR. 2-quaterdecies of the Code). This is because, as the Garante has repeatedly stated, making data available to individuals who, even if they are part of the data controller's organization, are not "authorized" to process it by virtue of the functions they perform within that organization, may give rise, also taking into account the definition of "third party" contained in Article 4, paragraph 1, no. 10, of the Regulation, to an unlawful "communication" of personal data as it lacks an appropriate legal basis (see Article 2-ter, paragraphs 1 and 3, of the Code and, in the event that the data being communicated belongs to special categories, Article 9 of the Regulation). As the Italian Data Protection Authority has repeatedly stated, making data available to parties who do not need to process it under applicable law or who, even though they are part of the data controller's organization, are not "authorized" to process it due to the functions performed within that organization and the controller's specific organizational choices, may give rise, also taking into account the definition of "third party" contained in Article 4, paragraph 1, no. 10, of the Regulation, to an unlawful "communication" of personal data as it lacks an appropriate legal basis (see Article 2-ter, paragraphs 1 and 3, of the Code and, in the event that the data being communicated belongs to special categories, Article 9, paragraph 2, letter b), of the Regulation). Furthermore, especially in cases where the employer is required to process, for purposes of managing the employment relationship, information pertaining to the health of workers, the employer is required to observe "special precautions," taking care, among other things, to avoid any unnecessary and unjustified access to the data by unauthorized persons (see paragraph 8 of the aforementioned Guidelines). Conversely, no violation of personal data protection regulations can be found in cases where individuals with specific tasks or responsibilities gain access to personal data of data subjects when, based on the organizational and technical decisions of the data controller, this is specifically necessary for the performance of their assigned duties. These principles have been applied by the Guarantor with a consolidated approach, in relation to different situations, in numerous specific cases (see, with particular regard to the posting on notice boards of documents containing workers' personal data, provision of 27 May 2021, no. 214, web doc. no. 9689234, and provisions referred to therein; see also, more generally, among the many, provisions of 16 January 2026, no. 1, web doc. no. 10220288; 27 February 2025, no. 101, web doc. no. 10123227; 27 February 2025, no. 92, web doc. no. 10114763; 3 February 2025, no. 70, web doc. no. 10118395; January 30, 2025, no. 36, web doc. no. 10112750; September 26, 2024, no. 606, web doc. no. 10068155; June 1, 2023, no. 223, web doc. no. 9916798; March 23, 2023, no. 82, web doc. no. 9885151; February 23, 2023, no. 43, web doc. no. 9868646; September 16, 2021, no. 322, web doc. no. 9711517; May 27, 2021, no. 214, web doc. 9689234; June 18, 2020, no. 105, web doc. no. 9444865; March 24, 2022, no. 98, web doc. no. 976305; February 11, 2021, no. 50, web doc. no. 9562866; July 31, 2014, no. 392, web doc. no. 3399423; October 3, 2013, no. 431, web doc. 2747867; May 8, 2013, no. 232, web doc. no. 2501216; October 18, 2012, no. 296, web doc. nos. 2174351 and 297, web doc. no. 2174582). With regard to the specific case, we note, first of all, that, in light of the declarations made by the data controller pursuant to Article 168 of the Code, the complainant's personal data, contained within the aforementioned service order and also relating to his health, were made available to the Department Commander, the Services Office, the Coordinator of the assigned operational unit, and the Public Prosecutor's Office for "service reasons" and, specifically, "for the execution and consequent obligations," as these individuals are "all [...] trained and authorized to process personal data" (see note of XX). We also note that "the individuals authorized to consult the Service Orders stored in the House's official collection [...] are also responsible for recording the Service Orders" (see note of XX). However, with regard to the posting of the aforementioned service order on the noticeboard located in the bar/canteen area and in the TV/relaxation area of the prison, accessible to all staff on duty, and its transmission to the trade unions, no specific evidence emerged from the documents proving the legitimacy of the resulting "communication" of the complainant's personal data. Specifically, no suitable reasons were identified that, also considering the roles and functions performed by the aforementioned recipients within the prison's organizational structure, could justify the processing of the data contained therein by all the employees on duty, therefore colleagues of the complainant, and by the trade unions, the "recipients" of the aforementioned data and unauthorized "third parties" (see Article 4, paragraphs 9 and 10, of the Regulation). Indeed, it must be considered that the information relating to the measures prescribed to the complainant by the competent doctor in the specific case could not have been known indiscriminately by all the staff of the prison, since access to such information must be reserved, in a perspective of rigorous proportionality, only to the staff responsible for its concrete implementation in the exercise of the employer's managerial and organizational prerogatives, with particular regard to the planning and distribution of work as well as the management and allocation of human resources (art. 42 of Legislative Decree no. 81/2008; see in this regard, for similar considerations, the aforementioned provision of 27 May 2021, no. 214, web doc. no. 9689234; see also, in relation to the hypothesis in which, for reasons of work organization, for example in the context of the preparation of service shifts, it is made available to subjects other than the interested party - such as others Colleagues - data relating to attendance and absence from work, Provision containing the requirements relating to the processing of special categories of data, pursuant to Article 21, paragraph 1 of Legislative Decree No. 101 of August 10, 2018, No. 146 of June 5, 2019, web doc. No. 9124510, see Annex 1, paragraph 1.5, letter d), which provides that the employer must not specify, even through acronyms or abbreviations, the reasons for absence from which it is possible to infer the knowledge of special categories of personal data, especially if of a health-related nature. From this perspective, contrary to what the owner claimed during the preliminary investigation, it cannot be considered that the explicit references to the measures prescribed to the complainant by the competent doctor, contained within the service order in question, were necessary in order to ensure, also "in the eyes of the staff", adequate justification for such a measure, which was also adopted "in excess of the available administrative positions" (see note of XX); In any case, this document remains in the Administration's records in its entirety and is accessible—when the specific requirements are met, also taking into account the rank of the data subject's rights, as required by law to ensure transparency and participation in administrative proceedings—to anyone who demonstrates a direct, concrete, and current interest, corresponding to a legally protected situation and connected to the document to which access is requested (Articles 22 et seq., Law No. 241 of 7 August 1990; Articles 59 and 60 of the Code, which specifically state that "when the processing concerns genetic data, data relating to health, sex life, or sexual orientation of a person, the processing is permitted if the legally relevant situation sought to be protected by the request for access to administrative documents is at least as important as the data subject's rights, or consists of a personality right or another fundamental right or freedom"). Nor are the reasons advanced during the investigation by the data controller regarding the stated need to ensure the publicity and transparency of such organizational arrangements in this context relevant. A generic reference to the "current legislation on transparency and publicity of administrative acts" (see note of XX) cannot be considered sufficient for this purpose. This legislation, however, does not provide for forms of document disclosure such as those implemented in this case by posting notices on noticeboards. Furthermore, the alleged implementation of collective agreements applicable to prison administration cannot be invoked in this regard, given that, as highlighted above, the "communication" of personal data (Article 2-ter, paragraph 4, letter a), of the Code) can be considered permitted by data protection legislation, for the fulfillment of obligations and the exercise of rights in the field of employment law, only in the presence of an appropriate legal basis as provided for by Article 2-ter, paragraph 4, letter a), of the Code. 2-ter, paragraphs 1 and 3, of the Code. In this context, in particular, the legal basis for processing must be "appropriate," also in light of the structure of the Member State's "constitutional order" (see recital 41 of the Regulation and also Constitutional Court ruling no. 271/2005, according to which the regulation of personal data protection falls within the exclusive jurisdiction of the State, referred to as "civil law"), and it must meet specific requirements, both in terms of the quality of the source, necessary content, and appropriate and specific measures to protect the rights and freedoms of data subjects, and in terms of the proportionality of the regulatory intervention with respect to the intended purposes (Article 6, paragraphs 2 and 3, letter b), of the Regulation). In this sense, within the European framework of data protection regulation, in the interests of legal certainty and the principle of non-discrimination, and in line with what was recently reiterated by the Italian Data Protection Authority, in the absence of a regulatory provision that satisfies the aforementioned requirements for an appropriate legal basis, differentiated levels of personal data protection would not be permitted at the territorial level or within individual administrations, or between different public workplaces, and between these and private workplaces. These principles have been reaffirmed by the Guarantor, even recently, in numerous provisions (see, in particular, among others, provision no. 287 of 6 July 2023, web doc. no. 9920145, which confirmed the unsuitability of the provisions contained within collective agreements to innovate the legal system in terms of the processing of personal data; provision no. 125 of 13 April 2023, web doc. no. 9907846, which, more specifically, clarified that collective agreements must limit themselves to detailing for the benefit of the employees concerned the regulatory framework already established at the national level and cannot provide for or justify in any way the introduction of a new processing not provided for by national legislation; see also, for similar considerations in relation to the introduction by regional ordinance of the processing of employees' personal data in the emergency context due to the spread of the Covid-19 virus, provision no. of 22 July 2021, no. 273, web doc. no. 9683814). In particular, national and supplementary collective agreements may contain specific and detailed provisions within the limits and scope assigned to them by law or regulation (see recital 41 and Article 88 of the Regulation; see Recommendation of 1 April 2015, CM/Rec(2015)5, on the processing of personal data in the employment context, paragraph 7: "In accordance with national laws and practices or provisions contained in collective agreements, personal data may be communicated to employee representatives only to the extent that such data are necessary to enable them to adequately represent the interests of employees or if such data are necessary for the fulfillment and monitoring of obligations set out in collective agreements"). Pursuant to industry regulations, collective bargaining only regulates certain aspects of the employment relationship (for example, see Article 40 of Legislative Decree No. 165/2001, which mentions performance evaluation for the purpose of awarding additional compensation), which are already expressly identified by law, requiring this to occur "within the limits established by law" (Article 40 of Legislative Decree 165/2001). It should also be noted that, specifically with regard to the disclosure of personal data to trade unions, even with regard to data not belonging to special categories, the Authority has provided clarifications to the Agency for the Negotiation Representation of Public Administrations - ARAN, the Ministry of Education, and the State Attorney's Office regarding the legitimacy of requests made by trade unions pursuant to a national collective agreement of the so-called "contractual agreement". "school sector", to know the additional compensation paid to school employees, highlighting in that case, in particular, that the aforementioned collective agreement did not constitute an appropriate legal basis and that, "in the absence of a regulatory provision that satisfies the requirements set forth by data protection legislation," personal data relating to workers cannot be lawfully communicated to trade unions (see note prot. no. XX of XX). This position of the Guarantor on this point was subsequently confirmed by the Council of State, which - in expressly referring to the aforementioned note prot. no. XX of XX - specified that "the provision of personal data to trade unions entails a "communication" and that collective agreements can integrate the regulatory provisions to allow trade unions to adequately represent the interests of employees, or when it is necessary to fulfill the obligations set forth in the same agreements" (see State Council Section VII, Sentence 9 August 2022, no. 7064) within the framework of the purposes and conditions established by the applicable legislation (this occurs, for example, in the case of serious subjective conditions of workers or their family members in the presence of which the employer may grant, also on the basis of collective agreements, the performance of work in a smart working manner, see Law 53/2000 and Ministerial Decree 278/2000). In any case, always with specific regard to the communication of the data in question to trade unions, the Garante has traditionally identified the conditions governing the flow of personal data from employer administrations to trade unions, emphasizing that, even in the presence of specific provisions establishing trade union prerogatives that require the communication of information to such organizations, such communication must be carried out in compliance with the principle of necessity, with specific measures to protect the data subjects being implemented within this framework (see point 2.3 of the Guidelines cited several times above), especially if, as in the case at hand, the personal data being processed relates to the most intimate sphere of the individual and his or her dignity. Given the above, it appears that the processing in question—consisting of the communication of the complainant's data, contained in service order no. XX of XX, including those relating to his health, the generality of employees, and trade union organizations, at the Cosenza "Sergio Cosmai" prison, as processing activities are entirely attributable to the Ministry of Justice—occurred in a manner that does not comply with the principles of "lawfulness, fairness, and transparency" and in the absence of an appropriate regulatory basis, in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code. 4. Conclusions. In light of the above considerations, it is found that the statements made by the data controller during the investigation—the veracity of which may be held accountable pursuant to Article 168 of the Code, although worthy of consideration, do not overcome the concerns notified by the Office with the notice initiating the proceedings and are insufficient to allow the dismissal of this proceeding, given that none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply. The Office's preliminary assessments are therefore confirmed and the Ministry of Justice's processing of personal data is found to be unlawful, having processed the complainant's personal data in violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code. Given that the violation of the aforementioned provisions occurred as a result of a single conduct (the same processing or related processing), Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Given that, in this case, the most serious violations, relating to Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code, are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000. In this context, considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are not met. 5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code). The Guarantor, pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code, with regard to the application of the additional administrative sanction, pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019). In this regard, taking into account Article 83, paragraph 3 of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. The aforementioned administrative pecuniary sanction imposed, depending on the circumstances of each individual case, must be determined in amount, taking into due consideration the factors set forth in Article 83, paragraph 2, of the Regulation. Considering that: The incident in question involved only one interested party, while it must also be noted that, according to the information provided, it constitutes an expression of ordinary practice, as evidenced by the documents showing that service order no. XX of XX was posted on the noticeboard and communicated to the trade unions in implementation of specific provisions of collective agreements; In any case, the documentation in the file shows that in this case, the service order remained posted on the noticeboard for a particularly short period of time (Article 83, paragraph 2, letter a), of the Regulations); Considering all the circumstances of the specific case, the violation is negligent, as the processing was carried out in the mistaken belief that it was acting in accordance with the applicable law (Article 83, paragraph 2, letter b), of the Regulations); The information processed in this case, relating to the data subject's health (see Article 9 of the Regulation), does not provide evidence of the data subject's diagnosis, despite the fact that the information contained in the service order and the measures prescribed by the competent physician constitute, by their very nature, health data and also allow anyone to deduce the nature of the ailments suffered by the complainant (see in particular the reference to "altered posture"; see Article 83, paragraph 2, letter g), of the Regulation). In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR" of 24 May 2023, point 60). Given the above, taking into account the complex and multifaceted organizational structure of the Penitentiary Administration, which is headed by the Ministry, it is believed that, for the purposes of quantifying the fine, the following circumstances must be taken into consideration: The prison manager offered full cooperation with the Authority during the investigation (Article 83, paragraph 2, letter f), of the Regulation); There are no previous relevant violations within the Cosenza "Sergio Cosmai" prison, within the territorial branches of the Ministry of Justice, the data controller (Article 83, paragraph 2, letter e), of the Regulation). Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the fine at €12,000.00 (twelve thousand/00) for the violation of Articles 5, paragraph 1, letter e), and 5, paragraph 1, letter f). a), 6, and 9 of the Regulation, and 2-ter of the Code, as an administrative pecuniary sanction deemed, pursuant to Art. 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. It is also believed that, pursuant to Art. 166, paragraph 7, of the Code and Art. 16, paragraph 1, of the Regulation of the Italian Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is because the communication, made in the absence of an appropriate legal basis, nevertheless concerned data relating to the health of a worker. Finally, it is noted that the conditions set forth in Art. 17 of Regulation No. 1/2019 are met. NOW CONSIDERING ALL THE FOREGOING, THE GUARANTOR declares, pursuant to Art. 57, paragraph 1, letter a) of the Italian Data Protection Authority (Garante), f) of the Regulation, the unlawfulness of the processing carried out by the Ministry of Justice for violation of Articles 5, paragraph 1, letter a), 6, and 9 of the Regulation and Article 2-ter of the Code, within the time limits set out in the grounds; ORDERS the Ministry of Justice, represented by its legal representative pro tempore, with registered office at Via Arenula, 70 - 00186 Rome (RM), Tax Code 80184430587, to pay the sum of €12,000.00 (twelve thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDER that the aforementioned Ministry, in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, pay the sum of €12,000.00 (twelve thousand/00) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this provision on the Authority's website; - pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, April 29, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Stanzione THE SECRETARY GENERAL Montuori

---
Generated by overview.legal · https://overview.legal/posts/144019 · 2026-07-21
