The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety
A data subject filed a complaint against the controller after being fined for running a red light.
The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding — The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.
How it connects
Related across sources
Full text 60 findings
[web doc. no. 10267254] Measure of June 18, 2026 Register of Measures no. 457 of June 18, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No.
1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction By complaint filed on XX pursuant to Article 77 of the Regulation and Article 141 of the Code, Mr. XX complained of a violation of the regulations on the protection of personal data by the Municipality of Vasto (hereinafter, the "Municipality"), regarding the receipt of a report alleging infringement of Article 146 of Legislative Decree No.
"), verified by video surveillance. In In particular, it was stated that "With report no. " 2. The Investigative Activity In response to two requests for information from the Authority (respectively, protocol no. XX of XX and no. XX of XX), formulated pursuant to Article 157 of the Code, the Municipality declared, in notes dated XX and XX (respectively, Authority protocol nos. XX and XX), to which full reference is made, in particular, that: - the first-level information notice "is placed near the violation detection device. […and] it is noted that the signage is being updated throughout the municipal area, which contains information that is more consistent with European Regulation 679/2016 and up-to-date. This signage, in addition to the essential information on processing, also contains a link, via QR code, to the second-level information notice, complete with the information required pursuant to Articles 13 and 14 of the GDPR.
This information notice is available on the Municipality's website" (see note dated XX); - "In the vicinity of the traffic light violation detection device, warning signs are present, and signs have also been placed regarding the municipal video surveillance system, which also includes devices for detecting traffic code violations. but] the device through which the violation was reported to Mr. ] the cameras used for urban security purposes are not used to ascertain violations of the Highway Code. com/drive/folders/1QSyeS187E69ZLkpzpGpeP0tnAY5rmGZW” (see note of XX); - regarding the information provided in the complaint report, the Municipality stated that “the forms attached to the reports contain specific information on the processing of personal data, updated and in summary form, which links to the complete information on the Municipality's website. […] with the management of the complaint reporting service being entrusted to another company, the information on the processing of personal data is updated compared to that sent to the […complainant]” (see note of XX); - "With regard to the methods used to ensure the principle of minimization in detecting traffic light violations, it must be stated that, in accordance with the provisions of the "Provision on Video Surveillance" issued by the Italian Data Protection Authority on 8 April 2010, the device used […] records only the license plate of the vehicle subject to the violation.
The vehicle's windshield and rear window are completely obscured, rendering the driver or any passengers unrecognizable. The same applies to vehicles not subject to the violations, whose license plates are also obscured" (see note of XX); - "In the case of […complainant], a problem did indeed arise with the failure to black out the images of other vehicles involved in the filming. This was an exclusively technical error, and it was confirmed, including with the company supplying the device, that the images provided to the interested parties were blacked out of anything not necessary for the purposes of the procedure for ascertaining and contesting the violation. and] is used for the sole and exclusive purposes of detecting violations pursuant to Legislative Decree No. " With reference to the Municipality's conduct, the Office, based on the evidence acquired and the Based on the facts that emerged from the investigation, the Court notified the complainant, with a note dated XX (ref.
no. XX), pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, for having acted: - in a manner inconsistent with the principles of lawfulness, fairness, and transparency, in violation of Articles 5, paragraph 1, letter a), 12, paragraph 1, and 13 of the Regulation, by failing to provide the complainant, at the time of the ascertainment of the violation by the Highway Code, with first-level information regarding the processing of personal data carried out through the photo/video system in question and by subsequently failing to provide the data subjects with appropriate first- and second-level information; - in a manner inconsistent with the principle of data minimization, in violation of Article 5, paragraph 1, letter c), of the Regulation. Regulation; - in violation of Article 35 of the Regulation, having conducted a data protection impact assessment regarding the photo/video system in question only after the processing had begun and lacking certain necessary elements.
The Municipality, with the aforementioned document, was requested to submit written defences or documents to the Data Protection Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of 24 November 1981). With a note dated XX (ref. No. […] The general information on the signs is then clarified in the second-level information notice on the Municipality's website. It states, among the purposes of the processing, that of using the city's video surveillance system for administrative police purposes. Since administrative offenses under the Highway Code are considered voluntary behavior […] violating the provisions established by the Code itself to protect road traffic […], it is therefore clear that the regulation of Highway Code violations falls within the scope of the purposes indicated on the signs issued by the Municipality.
- "Finally, the information notice, in addition to the administrative purposes, lists among the purposes pursued […] 'Supervision of road safety and traffic, control of vehicle circulation' while […] regarding data retention, violations of the Highway Code are explicitly mentioned. Therefore, the purpose relating to violations of the Highway Code can be considered fully identified and distinct in the signage and information […]"; - the signage "was adopted because the tools used to detect violations of the Highway Code are part of the city's video surveillance system. ” […]”; - “Regarding the difficulty in finding the information […] the QR code on the signs makes it immediately available to interested parties on the Municipality's website. ” 3. 1. Transparency towards data subjects In summary, the investigation revealed that the Municipality has equipped itself with a dedicated photo/video system for the purpose of identifying violations of the Highway Code.
and, with reference to the specific case, in accordance with this purpose, served the complainant with a notice of infringement of Article 146, paragraph 3, of the Highway Code. In general, it should be noted that public bodies may, as a rule, process personal data through video devices if the processing is necessary for compliance with a legal obligation to which the data controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 5, paragraph 1, letter a), Article 6, paragraphs 1, letter c) and e), Articles 2 and 3 of the Regulation, as well as Article 2-ter of the Code; see the "Guidelines 3/2019 on the processing of personal data through video devices," adopted by the European Data Protection Board on 29 January 2020, paragraph 41; see See also the FAQs of the Italian Data Protection Authority on video surveillance, dated December 3, 2020, web doc.
no. 9496574). Furthermore, sector legislation regulates the possibility of detecting certain violations of the Highway Code through specific video devices, subject to certain conditions (see Articles 45, 193, paragraph 4-ter, 198, 198-bis, and 201, in particular paragraphs 1-bis, letters e), f), g), g-bis), and g-ter) of the Highway Code). Even if processing is lawful, the data controller is required, in any case, to comply with data protection principles, including "lawfulness, fairness, and transparency," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (Article 5, paragraph 1, letter a), of the Regulation). In particular, in compliance with the aforementioned principle of transparency, the data controller is required to provide data subjects with accurate and complete information regarding the processing performed.
, in particular par. 7; but see already the "Provision on video surveillance" of the Guarantor of 8 April 2010, web doc. no. 1712680, in particular par. 1; lastly, see the FAQs of the Guarantor on video surveillance, Web doc. no. 9496574, no. 4; see also provisions of February 12, 2026, no. 102, Web doc. no. 10227910, December 18, 2025, no. 752, Web doc. no. 10213486, April 29, 2025, no. 244, Web doc. no. 10144974, December 19, 2024, no. 805, Web doc. no. 10107263; December 12, 2024, no. 766, Web doc. no. 10102334, January 11, 2024, no. 5, Web doc. no. 9977020; October 20, 2022, no. 341, Web doc. web no. 9831369; 28 April 2022, no. 162, web doc. no. 9777974, 7 April 2022, no. 119, web doc. no. 9773950, 16 September 2021, no. 327, web doc. no. 9705650 and 11 March 2021, no. 90, web doc. no. 9582791). , para. 114). Furthermore, the signage must also contain information that may be unexpected for the data subject.
This could include, for example, the transmission of data to third parties, particularly if located outside the EU, and the retention period. If this information is not provided, the data subject should be able to rely on real-time monitoring only (without any data recording or transmission to third parties) (Committee Guidelines, cited above, para. 115). First-level warning signs must contain a clear reference to the second-level information, for example, by indicating a website where the text of the extended notice can be found. In this case, throughout the entire investigation, the Municipality failed to substantiate, first of all, the date on which the first-level notice was posted at the site of the violation. It only provided copies of the first-level notice signs (in JPG format, dated XX), without, however, indicating the date on which they were actually posted at the site of the violation.
In this regard, it should be noted that the documentation submitted by the interested party along with the complaint, as well as the photographs recording the violation produced by the Municipality (attached to note dated XX), do not show any signage positioned near the photo/video system used to record the violation of the Highway Code against the complainant. It should also be noted that the signage submitted by the Municipality along with note dated XX, containing the information on the processing of first-level personal data, does not comply with the requirements set forth in the Regulation (seeArt. " In this regard, it is recalled that the notice must specifically indicate the specific purposes of the processing actually pursued, in order to adequately inform data subjects regarding the processing performed. In this case, however, the Municipality indicated multiple processing purposes on a single sign, even though they are pursued through different video devices.
" This same generic period is also mentioned in the second-level information notice; - It does not fully address the rights of data subjects and how to exercise them, with reference being made only to Articles 11–15 of the Regulation, rather than Articles 15 et seq. of the Regulation. ] in the second-level information notice," cannot be accepted. This is because such information, particularly the methods for exercising data subjects' rights, is among the most important elements that must be immediately communicated to data subjects from the first level of information. Regarding the "second-level" information notice regarding the processing carried out through the aforementioned video surveillance system, according to the Authority's initial findings on 2019, it was not easily available on the Municipality's institutional website. it/it/privacy) was found, first and foremost. com/drive/folders/1QSyeS187E69ZLkpzpGpeP0tnAY5rmGZW), but there was no information regarding data processing through video surveillance systems.
pdf). " Furthermore, the document did not specify the retention period for images collected for administrative purposes, stating only that "Images for urban security purposes are retained for a period not exceeding 7 days, subject to further retention requirements in the event of specific requests from law enforcement or judicial authorities. " Considering this, it is noted that the Municipality, during the investigation, failed to make the appropriate adjustments. As subsequently confirmed by the Authority on 2019, the same information—unsuitable—is still present on the institutional website and can be found using the same paths described above. it/it/documenti_pubblici/trattamento-dati-relativo-al-servizio-di-videosorveglianza, this search method is not intuitive for interested parties as a first-line search, especially given the generic name that refers to all video surveillance processing and not just the system for detecting violations of the Highway Code.
" This section, in addition to outdated references to personal data protection legislation (see "Article 13, Legislative Decree No. 196 of June 30, 2003"), does not indicate how to exercise the rights granted to data subjects pursuant to Articles 15 to 22 of the Regulation, nor does it specify where the extended information containing the additional and complete elements required by Articles 13 and 14 of the Regulation can be found. complainant], without, however, providing the Authority with documentary evidence relating to the updated information during the investigation. On this point, it is recalled that, more generally, with regard to the information provided to data subjects regarding the processing of personal data related to the activities under their jurisdiction—in this case, the local police service—in light of the aforementioned principle of transparency pursuant to Article 5, paragraph 1, letter a) of the Regulation, the data controller must take appropriate measures to provide the data subject with all the information referred to in Articles 13 (where personal data are collected from the data subject) and 14 (where the personal data have not been obtained from the data subject) of the Regulation in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (Article 12, paragraph 1, of the Regulation).
" […]” (see “Guidelines on transparency under Regulation 2016/679” of the Article 29 Data Protection Working Party of 29 November 2017, as amended and last adopted on 11 April 2018 and endorsed by the European Data Protection Board on 25 May 2018, point 38). In addition, in the case of data controllers with a digital/online presence, “an appropriate measure” to provide information for the purposes of transparency is to provide it through an electronic privacy statement/notice. Depending on the circumstances of data collection and processing, the data controller may, however, need to use other methods and forms in addition to this method […],” thus combining, in this layered approach, distinct methods and ensuring, in any case, “that the most important information […] is always transmitted in the first method used to communicate with the data subject […]” (see Guidelines, cited above, point 40, and, most recently, Order No.
165 of March 27, 2025, web doc. No. 10201385). For the reasons set out above, it is established that the Municipality failed to provide the complainant, at the time of ascertaining the violation of the Highway Code, with first-level information regarding the processing of personal data carried out through the photo/video system in question, as well as with adequate information regarding the processing carried out by the Municipality's local police force, and subsequently failed to provide the data subjects with adequate first- and second-level information. in relation to the photo/video devices in question, in violation of Articles 5, paragraph 1, letter a), 12, paragraph 1, and 13 of the Regulation. 2. " On this point, the "Provision on Video Surveillance" issued by the Italian Data Protection Authority on 8 April 2010 (web doc. no. 1). In this regard, it should be noted that the Ministerial Decree also provides: April 11, 2024, concerning the "Methods for the placement and use of technical control devices or means for the remote detection of violations of the rules of conduct referred to in Article 142 of Legislative Decree 285 of 1992," provides that "in order to allow the vehicle owner who, pursuant to Article 25 of Law No.
241 of August 7, 1990, has a legitimate interest in identifying the actual perpetrator of the violation and in obtaining any useful information from the competent authority, viewing of the photographic or video documentation must be made available upon request by the recipient of the report, in compliance with the rules on access to processed personal data. 4). This measure is also recommended for video devices used to detect other traffic violations. " Indeed, the documentation submitted by the data subject along with the complaint shows that license plates other than the complainant's were not obscured. In light of the foregoing considerations, it is therefore established that the Municipality, by failing to obscure the images during the investigation carried out against the complainant, acted in violation of the data minimization principle pursuant to Article 5, paragraph 1, letter c) of the Regulation.
3. Impact Assessment In the event of high risks to data subjects—for example, resulting from the use of new technologies—the data controller must conduct a data protection impact assessment, in order to adopt, in particular, appropriate measures to address such risks, consulting the Garante in advance, where the conditions are met (see Articles 35 and 36, paragraph 1, of the Regulation). A data protection impact assessment is always required when the processing involves "systematic monitoring on a large scale of a publicly accessible area" (see Article 35, paragraph 3, letter c), of the Regulation) and must be conducted by the controller before proceeding with the processing (Article 35, paragraph 1, of the Regulation). From the documents submitted during the investigation, it appears that the Municipality prepared the data protection impact assessment only after the processing of personal data had begun, in violation of Article 35 of the Regulation.
With reference to the case at hand, the Municipality submitted a data protection impact assessment approved by the City Council only on XX (see "MINUTES OF RESOLUTION OF THE CITY COUNCIL NO. 250 OF XX", attached to the note of XX). The aforementioned assessment has no specific date, as it was not signed, and, furthermore, it lacks the opinion of the Data Protection Officer (Articles 37 and 39, paragraph 1, letters a) and c), and paragraph 2 of the Regulation). In any case, it is noted that, since the complainant's violation of the Highway Code was detected in the month of XX using the photo/video system already in operation, the impact assessment appears to have been conducted after the start of the processing. Finally, it is noted that, while acknowledging the Municipality's statement regarding the fact that "a single document was prepared, referring to the devices included in the city's video surveillance system […examining] a set of similar processing operations that present similar high risks, also pursuant to Article 35, paragraph 1 of the GDPR," this does not imply a generic assessment of the individual processing operations performed; specific information must instead be provided for an effective analysis of the relevant risks.
" In light of the foregoing considerations, the Municipality has therefore been found to have violated Article 35 of the Regulation, which requires data controllers to conduct a comprehensive impact assessment of all relevant elements before initiating processing, also considering that this tool is suitable for demonstrating the data controller's accountability for the processing performed. 4. Conclusions In light of the above assessments, it is noted that the statements made by the Municipality during the investigation – the veracity of which may be held accountable pursuant to Article 168 of the Code – while worthy of consideration, do not address the concerns notified by the Office in the initiation of the proceedings and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Guarantor Regulation No. 1/2019, as none of the cases envisaged in Article 11 therein apply.
The Office's preliminary assessments are therefore confirmed, and the processing of personal data by the Municipality is found to be unlawful, having violated Articles 5, paragraph 1, letters a) and c), 12, paragraph 1, 13, and 35 of the Regulation. Violation of the aforementioned provisions gives rise to the administrative sanctions provided for in Article 83, paragraphs 4 and 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code. 5. Corrective measures (Article 58, paragraph 2, letter d), of the Regulation) Article 58, paragraph 2, of the Regulation grants the Garante the power to "order the controller or processor to bring processing operations into conformity with the provisions of this Regulation, where appropriate, in a specific manner and within a specific period" (letter d).
2 above, the first- and second-level information notices for the processing in question are still inadequate; furthermore, the second-level information notices are not easily accessible to data subjects. ). Pursuant to Articles 58, paragraph 1, letter d), a) of the Regulation and 157 of the Code, the Municipality must also communicate to this Authority, providing adequately documented feedback, within thirty days of notification of this provision, the initiatives undertaken to implement the above order pursuant to the aforementioned art. 58, paragraph 2, letter d), as well as any measures implemented to ensure compliance of the processing with the legislation on the protection of personal data. 6. " Within this framework, "the [Garante] Panel adopts the injunction order, which also orders the application of the additional administrative sanction, including its publication, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante's Regulation No.
1/2019). Given that the Municipality's violation of the above provisions occurred as a result of conduct that can be considered unitary (the same processing or related processing, as they are inherent to the same photo/video system), Article 83, paragraph 1, applies. 3 of the Regulation, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Given that, in this case, the most serious violations, relating to Articles 5, 12, and 13 of the Regulation, are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction shall be up to €20,000,000 (twenty million). The aforementioned administrative pecuniary sanction imposed, based on the circumstances of each individual case, must be determined in amount taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation.
With specific regard to the nature and severity of the violation (Article 83, paragraph 2, letter a) of the Regulation), it must be considered that the Municipality, in particular, failed to provide adequate information to data subjects regarding the processing of personal data carried out through the implemented data collection system, failed to conduct a timely impact assessment of the aforementioned system, and used the photo/video system in question to investigate the complainant without adopting adequate data minimization measures. Furthermore, the following must be considered: - the negligent nature of the violation (Article 83, paragraph 2, letter b) of the Regulation); - that the processing in question does not concern special categories of data (Article 83, paragraph 2, letter g). In light of these circumstances, it is believed that, in this case, the severity of the violation committed by the data controller can be considered medium (see European Data Protection Board, "Guidelines 04/2022 on the calculation of administrative fines under the GDPR" of 23 May 2023, point 60).
That said, it is believed that, for the purposes of quantifying the fine, the fact that the data controller is a municipality of modest size and that there are no previous relevant violations committed by the data controller should be considered favorable (Article 83, paragraph 2, letter e), of the Regulation). However, the limited degree of cooperation demonstrated by the data controller with the supervisory authority in addressing the violation and mitigating its possible negative effects should be considered unfavorably for the Municipality (Article 83, paragraph 2, letter f), of the Regulation). 00 (five thousand/00) for violation of Articles 5, paragraph 1, letters a) and c), 12, paragraph 1, 13, and 35 of the Regulation, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No.
1/2019, this chapter containing the injunction order should be published on the Guarantor's website. This is in consideration of the specific circumstances of the specific case, particularly the Municipality's failure to comply with the principle of transparency, pursuant to Article 83, paragraph 1, of the Regulation. 5, paragraph 1, letter a) of the Regulation, by failing to provide adequate information to data subjects and by failing to minimize the data, pursuant to Article 5, paragraph 1, letter c), of the Regulation, by failing, with reference to the investigation carried out against the complainant, to adopt measures aimed at ensuring the adequate obscuring of subjects and/or information not involved in the detected infringement. Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met. NOW, CONSIDERING ALL THE ABOVE, THE AUTHORITY pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, finds the processing carried out by the Municipality of Vasto as set out in the grounds unlawful, due to the violation of Articles 5, paragraph 1, letters a) and c), 12, paragraph 1, and 13, of the Regulation.
00 (five thousand/00) as an administrative fine for the violations indicated in the grounds. 00 (five thousand/00) in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. ); - pursuant to Articles 58, paragraph 1, letter b) of the GDPR, a) of the Regulation and Article 157 of the Code, to communicate to this Authority, providing adequately documented feedback, within thirty days of notification of this order, the initiatives undertaken to implement the above order pursuant to the aforementioned Article 58, paragraph 2, letter d), as well as any measures implemented to ensure compliance with the legislation on the protection of personal data.
ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Data Protection Authority no. 1/2019, the publication of the injunction order on the website of the Data Protection Authority; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Regulation of the Data Protection Authority no. 1/2019, the publication of this order on the website of the Data Protection Authority; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Regulation of the Data Protection Authority no. 17 of the Guarantor Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, provided for by Art. 57, paragraph 1, letter u), of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.
Rome, June 18, 2026 THE PRESIDENT Stanzione THE REPORTER Stanzione THE SECRETARY GENERAL Montuori [web doc. No. 10267254] Provision of June 18, 2026 Register of Provisions No. 457 of June 18, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree No. 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No.
1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction By complaint filed on XX pursuant to Article 77 of the Regulation and Article 141 of the Code, Mr. XX complained of a violation of the regulations on the protection of personal data by the Municipality of Vasto (hereinafter, the "Municipality"), regarding the receipt of a report alleging infringement of Article 146 of Legislative Decree No.
"), verified by video surveillance. In particular, it was stated that "With report no. " 2. The Investigative Activity In response to two requests for information from the Authority (ref. no. XX of XX and no. XX of XX, respectively), formulated pursuant to Article 157 of the Code, the Municipality declared, with notes dated XX and XX (Authority report nos. XX and XX, respectively), to which reference is made in full, in particular that: - The first-level information notice "is placed near the device that detects traffic violations. […and] it is noted that signage is being updated throughout the municipality, which contains information that is more consistent with European Regulation 679/2016 and updated. This signage, in addition to the essential information on processing, also contains a link, via QR code, to the second-level information notice, complete with the information required pursuant to Articles 13 and 14 of the GDPR.
This notice is available on the Municipality's website" (see note of XX); - "near the device that detects traffic light violations, there is warning signage regarding the device itself, and signage has also been placed regarding the municipal video surveillance system, which also includes devices for detecting traffic violations. […]” (see note by XX); - “there is also another camera, used for urban security purposes, near the device for detecting traffic light violations, […] but the device through which Mr. XX was charged with the violation is used solely and exclusively for violations of the Highway Code and […] the cameras used for urban security purposes are not used to detect violations of the Highway Code. With reference to the information, please refer to the general information on the video surveillance system […], given that the devices are included in the city video surveillance system pursuant to the current Municipal Regulations; the information includes reference to administrative police purposes and indicates the terms for retaining the images for the purpose of investigating violations of the Highway Code; This information, in its latest version, has been published and available on the website of the Municipality of Vasto since day XX and has been updated over time […].
" […] with the management of the Reporting Service entrusted to another company, the information on the processing of personal data is updated compared to that sent to the […complainant]” (see note of XX); - “With regard to the methods used to ensure the principle of minimization in the detection of traffic light violations, it must be stated that, in accordance with the provisions of the “Provision on Video Surveillance” of the Italian Data Protection Authority of 8 April 2010, the device used […] records only the license plate of the vehicle subject to the violation. The vehicle's windshield and rear window are completely obscured, and in any case, the driver or any passengers are unrecognizable. The same applies to vehicles not subject to the violations, whose license plates are also obscured” (see note of XX); - “in the case of the […complainant], a problem did indeed arise relating to the failure to obscure the images of other vehicles involved in the recording.
This was a purely technical error, and it was confirmed, including with the company supplying the device, that the images provided to the interested parties are obscured of anything not necessary for the purposes of the procedure for ascertaining and reporting the violation. and] is used for the sole and exclusive purposes of ascertaining the violations referred to in Legislative Decree no. " With regard to the Municipality's conduct, the Office, based on the information acquired and the facts that emerged from the investigation, notified the Municipality, with note of XX (ref. no. XX), pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation for having acted: - in a manner that did not comply with the principles of lawfulness, fairness, and transparency, in violation of Articles 5, paragraph 1, letter b) and c) of the Italian Civil Code; a), 12, paragraph 1, and 13 of the Regulation, by failing to provide the complainant, at the time the violation of the Highway Code was established, with first-level information regarding the processing of personal data carried out through the photo/video system in question and by subsequently failing to provide the data subjects with adequate first- and second-level information; - in a manner inconsistent with the principle of data minimization, in violation of Article 5, paragraph 1, letter c), of the Regulation; - in violation of Article 35 of the Regulation, by conducting a data protection impact assessment regarding the photo/video system in question only after the processing had started and lacking certain necessary elements.
The Municipality, with the aforementioned document, was invited to submit written defenses or documents to the Guarantor or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). In a note dated XX (ref. no. XX), to which reference is made in full, the Municipality, which did not request a hearing, stated, in particular, that: - "Violations of the Highway Code, in the first-level notice, are identified within a general context that pertains to road safety and police needs. […] The general indication on the signs is then clarified in the second-level notice, available on the Municipality's website. It states, among the purposes of the processing, that of using the city's video surveillance system for administrative police purposes. " - "Finally, the notice, in addition to the administrative purposes, lists among the purposes pursued […] 'Monitoring of road safety and traffic, control of vehicle circulation' while […] regarding data retention, violations of the Highway Code are explicitly mentioned.
Therefore, the purpose relating to violations of the Highway Code can be considered fully identified and distinct in the signage and the notice […]"; - the signage "was adopted since the tools used to detect violations of the Highway Code are part of the city's video surveillance system. Furthermore, the information is available in a dedicated section, easily accessible through the most common search engines by searching for "Vasto video surveillance information" […and] is also included in a section of the municipal website reserved for the local police, which contains information pertaining to its organization […] and where the forms can be found […]"; - "on the signage […] it is clear that there is a clear link to the municipal website, including the local police page, to obtain all the necessary information, in addition to the QR Code […]"; - "regarding the incorrect indication of the data subject's rights, […] the second-level information specifies the necessary references consistent with the GDPR provisions, while the signage refers to Article 11 on processing that does not require identification and then to Chapter III of the Regulation […] in which Articles Articles 12 to 15 indicate the transparency requirements for the information to be provided, including with reference to the rights of data subjects […] as explicitly stated […] in the second-level information notice; - regarding the impact assessment, in the latest version, a single document was created, referring to the devices included in the city's video surveillance system […examining] a set of similar processing operations that present similar high risks, also pursuant to Article 35, paragraph 1 of the GDPR.
3. 1. Transparency towards data subjects In summary, the outcome of the investigation revealed that the Municipality has equipped itself with a specific photo/video system for the purpose of ascertaining violations of the Highway Code and, with reference to the specific case, in accordance with this purpose, it served the complainant with a report for violation of Article 146, paragraph 3, of the Highway Code. In general, it should be noted that public bodies may, as a rule, process personal data through video devices if the processing is necessary for compliance with a legal obligation to which the data controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 5(1)(a), Article 6(1)(c) and (e), Articles 2 and 3 of the Regulation, as well as Article 2-ter of the Code; see "Guidelines 3/2019 on the processing of personal data through video devices," adopted by the European Data Protection Board on January 29, 2020, paragraph 41; see also the FAQs of the Italian Data Protection Authority on video surveillance, dated December 3, 2020, web doc.
No. 9496574). Furthermore, sector-specific legislation governs the possibility of detecting certain violations of the Highway Code. through dedicated video devices, in compliance with certain conditions (see Articles 45, 193, paragraph 4-ter, 198, 198-bis, 201, in particular paragraphs 1-bis, letters e), f), g), g-bis), and g-ter) of the Highway Code). Even if the processing is lawful, the data controller is required, in any case, to comply with data protection principles, including "lawfulness, fairness, and transparency," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (Article 5, paragraph 1, letter a), of the Regulation). In particular, in compliance with the aforementioned principle of transparency, the data controller is required to provide data subjects with accurate and complete information regarding the processing carried out.
, in particular par. 7; but see already the "Provision on video surveillance" of the Guarantor of 8 April 2010, web doc. no. 1712680, in particular par. 1; lastly, see the FAQs of the Guarantor on video surveillance, Web doc. no. 9496574, no. 4; see also provisions of February 12, 2026, no. 102, Web doc. no. 10227910, December 18, 2025, no. 752, Web doc. no. 10213486, April 29, 2025, no. 244, Web doc. no. 10144974, December 19, 2024, no. 805, Web doc. no. 10107263; December 12, 2024, no. 766, Web doc. no. 10102334, January 11, 2024, no. 5, Web doc. no. 9977020; October 20, 2022, no. 341, Web doc. web no. 9831369; 28 April 2022, no. 162, web doc. no. 9777974, 7 April 2022, no. 119, web doc. no. 9773950, 16 September 2021, no. 327, web doc. no. 9705650 and 11 March 2021, no. 90, web doc. no. 9582791). , para. 114). Furthermore, the signage must also contain information that may be unexpected for the data subject.
This could include, for example, the transmission of data to third parties, particularly if located outside the EU, and the retention period. If this information is not provided, the data subject should be able to rely on real-time monitoring only (without any data recording or transmission to third parties) (Committee Guidelines, cited above, para. 115). First-level warning signs must contain a clear reference to the second-level information, for example, by indicating a website where the text of the extended notice can be found. In this case, throughout the entire investigation, the Municipality failed to substantiate, first of all, the date on which the first-level notice was posted at the site of the violation. It only provided copies of the first-level notice signs (in JPG format, dated XX), without, however, indicating the date on which they were actually posted at the site of the violation.
In this regard, it should be noted that the documentation submitted by the interested party in conjunction with the complaint, as well as the photographs of the violation produced by the Municipality (attached to note dated XX), do not show any signs positioned in the vicinity of the photo/video system used to detect the violation of the Highway Code against the complainant. " In this regard, it is recalled that the notice must specifically indicate the specific purposes of the processing actually pursued, in order to adequately inform data subjects of the processing performed. In this case, however, the Municipality indicated multiple processing purposes in a single notice, even though they are pursued through different video devices. " This same generic period is also mentioned in the second-level notice; - it does not fully address the rights of data subjects and the methods for exercising them, with reference being made only to Articles 11–15 of the Regulation, rather than Articles 15 et seq.
of the Regulation. ] in the second-level information notice," cannot be accepted. This is because such information, particularly the methods for exercising data subjects' rights, is among the most important elements that must be immediately communicated to data subjects from the first level of information. it/it/privacy) was found, first and foremost. com/drive/folders/1QSyeS187E69ZLkpzpGpeP0tnAY5rmGZW), but there was no information regarding data processing through video surveillance systems. pdf). " Furthermore, the document did not specify the retention period for images collected for administrative purposes, stating only that "Images for urban security purposes are retained for a period not exceeding 7 days, subject to further retention requirements in the event of specific requests from law enforcement or judicial authorities. " Considering this, it is noted that the Municipality, during the investigation, failed to make the appropriate adjustments.
As subsequently confirmed by the Authority on 2019, the same information—unsuitable—is still present on the institutional website and can be found using the same paths described above. it/it/documenti_pubblici/trattamento-dati-relativo-al-servizio-di-videosorveglianza, this search method is not intuitive for interested parties as a first-line search, especially given the generic name that refers to all video surveillance processing and not just the system for detecting violations of the Highway Code. " This section, in addition to outdated references to personal data protection legislation (see "Article 13, Legislative Decree No. 196 of June 30, 2003"), does not indicate how to exercise the rights granted to data subjects pursuant to Articles 15 to 22 of the Regulation, nor does it specify where the extended information containing the additional and complete elements required by Articles 13 and 14 of the Regulation can be found.
complainant], without, however, providing the Authority with documentary evidence relating to the updated information during the investigation. On this point, it is recalled that, more generally, with regard to the information provided to data subjects regarding the processing of personal data related to the activities under their jurisdiction—in this case, the local police service—in light of the aforementioned principle of transparency pursuant to Article 5, paragraph 1, letter a) of the Regulation, the data controller must take appropriate measures to provide the data subject with all the information referred to in Articles 13 (where personal data are collected from the data subject) and 14 (where the personal data have not been obtained from the data subject) of the Regulation in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (Article 12, paragraph 1, of the Regulation).
" […]” (see “Guidelines on transparency under Regulation 2016/679” of the Article 29 Data Protection Working Party of 29 November 2017, as amended and last adopted on 11 April 2018 and endorsed by the European Data Protection Board on 25 May 2018, point 38). In addition, in the case of data controllers with a digital/online presence, “an appropriate measure” to provide information for the purposes of transparency is to provide it through an electronic privacy statement/notice. Depending on the circumstances of data collection and processing, the data controller may, however, need to use other methods and forms in addition to this method […],” thus combining, in this layered approach, distinct methods and ensuring, in any case, “that the most important information […] is always transmitted in the first method used to communicate with the data subject […]” (see Guidelines, cited above, point 40, and, most recently, Order No.
165 of March 27, 2025, web doc. No. 10201385). For the reasons set out above, it is established that the Municipality failed to provide the complainant, at the time of ascertaining the violation of the Highway Code, with first-level information regarding the processing of personal data carried out through the photo/video system in question, as well as with adequate information regarding the processing carried out by the Municipality's local police force, and subsequently failed to provide the data subjects with adequate first- and second-level information. In relation to the photo/video devices in question, in violation of Articles 5, paragraph 1, letter a), 12, paragraph 1, and 13 of the Regulation. 2. " On this point, the "Provision on Video Surveillance" issued by the Italian Data Protection Authority on April 8, 2010 (web doc. no. 1). In this regard, it should be noted that the Ministerial Decree of April 11, 2024, concerning the "Methods for the placement and use of technical control devices or means for the remote detection of violations of the rules of conduct referred to in Article 142 of Legislative Decree 285 of 1992," also provides that "in order to allow the vehicle owner who, pursuant to Article 25 of Law No.
241 of August 7, 1990, has a legitimate interest in identifying the actual perpetrator of the violation and in obtaining any relevant information from the competent authority, viewing of the photographic or video documentation must be made available upon request by the recipient of the report, in compliance with the rules on access to processed personal data. 4). This measure is also recommended for video devices used to detect other traffic violations. " Indeed, the documentation submitted by the data subject along with the complaint shows that license plates other than the complainant's were not obscured. In light of the foregoing considerations, it is therefore established that the Municipality, by failing to obscure the images during the investigation carried out against the complainant, acted in violation of the data minimization principle pursuant to Article 5, paragraph 1, letter c) of the Regulation.
3. Impact Assessment In the event of high risks to data subjects—for example, resulting from the use of new technologies—the data controller must conduct a data protection impact assessment, in order to adopt, in particular, appropriate measures to address such risks, consulting the Garante in advance, where the conditions are met (see Articles 35 and 36, paragraph 1, of the Regulation). A data protection impact assessment is always required when the processing involves "systematic monitoring on a large scale of a publicly accessible area" (see Article 35, paragraph 3, letter c), of the Regulation) and must be conducted by the controller before proceeding with the processing (Article 35, paragraph 1, of the Regulation). From the documents submitted during the investigation, it appears that the Municipality prepared the data protection impact assessment only after the processing of personal data had begun, in violation of Article 35 of the Regulation.
With reference to the case at hand, the Municipality submitted a data protection impact assessment approved by the City Council only on XX (see "MINUTES OF RESOLUTION OF THE CITY COUNCIL NO. 250 OF XX", attached to the note of XX). The aforementioned assessment has no specific date, as it was not signed, and, furthermore, it lacks the opinion of the Data Protection Officer (Articles 37 and 39, paragraph 1, letters a) and c), and paragraph 2 of the Regulation). In any case, it is noted that, since the complainant's violation of the Highway Code was detected in the month of XX using the photo/video system already in operation, the impact assessment appears to have been conducted after the start of the processing. Finally, it is noted that, while acknowledging the Municipality's statement regarding the fact that "a single document was prepared, referring to the devices included in the city's video surveillance system […examining] a set of similar processing operations that present similar high risks, also pursuant to Article 35, paragraph 1 of the GDPR," this does not imply a generic assessment of the individual processing operations performed; specific information must instead be provided for an effective analysis of the relevant risks.
" In light of the foregoing considerations, the Municipality has therefore been found to have violated Article 35 of the Regulation, which requires data controllers to conduct a comprehensive impact assessment of all relevant elements before initiating processing, also considering that this tool is suitable for demonstrating the data controller's accountability for the processing performed. 4. Conclusions In light of the above assessments, it is noted that the statements made by the Municipality during the investigation – the veracity of which may be held accountable pursuant to Article 168 of the Code – while worthy of consideration, do not address the concerns notified by the Office in the initiation of the proceedings and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Guarantor Regulation No. 1/2019, as none of the cases envisaged in Article 11 therein apply.
The Office's preliminary assessments are therefore confirmed, and the processing of personal data by the Municipality is found to be unlawful, having violated Articles 5, paragraph 1, letters a) and c), 12, paragraph 1, 13, and 35 of the Regulation. Violation of the aforementioned provisions gives rise to the administrative sanctions provided for in Article 83, paragraphs 4 and 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code. 5. Corrective measures (Article 58, paragraph 2, letter d), of the Regulation) Article 58, paragraph 2, of the Regulation grants the Garante the power to "order the controller or processor to bring processing operations into conformity with the provisions of this Regulation, where appropriate, in a specific manner and within a specific period" (letter d).
2 above, the first- and second-level information notices for the processing in question are still inadequate; furthermore, the second-level information notices are not easily accessible to data subjects. ). Pursuant to Articles 58, paragraph 1, letter d), a) of the Regulation and Article 157 of the Code, the Municipality shall also communicate to this Authority, providing adequately documented feedback, within thirty days of notification of this provision, the initiatives undertaken to implement the above-mentioned order pursuant to Article 58, paragraph 2, letter d), as well as any measures implemented to ensure compliance with personal data protection legislation. 6. Adoption of the injunction order for the application of the administrative fine and additional penalties (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code) The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation and Article 166, paragraph 7, of the Code, hereby issues a request for the enforcement of the administrative fine and additional penalties.
166 of the Code, has the power to “impose an administrative pecuniary sanction pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case” and, in this context, “the [Garante] Board adopts the injunction order, with which it also orders, with regard to the application of the accessory administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code” (Article 16, paragraph 1, of the Guarantor Regulation no. 1/2019). Considering that the Municipality's violation of the above provisions occurred as a result of conduct that can be considered consistent (same processing or related processing, as they relate to the same photo/video system), Article 83, paragraph 3, of the Regulations applies, pursuant to which the total amount of the administrative fine does not exceed the amount specified for the most serious violation.
Given that, in this case, the most serious violations, relating to Articles 5, 12, and 13 of the Regulations, are subject to the penalty provided for by Article 83, paragraph 5, of the Regulations, as also referenced in Article 166, paragraph 2, of the Code, the total amount of the fine is to be quantified up to €20,000,000 (twenty million). The aforementioned administrative fine imposed, based on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation. With specific regard to the nature and severity of the violation (Article 83, paragraph 2, letter a), of the Regulation), it must be considered that the Municipality, in particular, failed to provide adequate information to data subjects regarding the processing of personal data carried out through the implemented data collection system, failed to conduct a timely impact assessment of the aforementioned system, and used, with regard to the investigation of the complainant, the photo/video system in question without adopting adequate data minimization measures.
Furthermore, the following must be considered: - the negligent nature of the violation (Article 83, paragraph 2, letter b) of the Regulation); - that the processing in question does not concern special categories of data (Article 83, paragraph 2, letter g). In light of these circumstances, it is believed that, in this case, the level of severity of the breach committed by the data controller can be considered medium (see European Data Protection Board, "Guidelines 04/2022 on the calculation of administrative fines under the GDPR" of 23 May 2023, point 60). That said, it is believed that, for the purposes of quantifying the fine, the fact that the data controller is a municipality of modest size and that there are no previous relevant breaches committed by the data controller should be taken into consideration, in a favorable manner (Article 83, paragraph 2, letter e), of the Regulation).
However, the limited level of cooperation demonstrated by the data controller with the supervisory authority in remedying the violation and mitigating its possible negative effects must be considered unfavorable to the Municipality (Article 83, paragraph 2, letter f) of the Regulation). 00 (five thousand/00) for the violation of Articles 5, paragraph 1, letters a) and c), 12, paragraph 1, 13, and 35 of the Regulation, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order must be published on the Garante's website. This is in consideration of the specific circumstances of the specific case, in particular, the Municipality's failure to comply with the principle of transparency, pursuant to Article 5, paragraph 1, letter a) of the Regulation, by failing to provide adequate information to data subjects, and the principle of data minimization, pursuant to Article 5, paragraph 1, letter c), of the Regulation, by failing, with reference to the investigation carried out against the complainant, to adopt measures aimed at ensuring the adequate obscuring of individuals and/or information not involved in the detected infringement.
Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met. 00 (five thousand/00) as an administrative fine for the violations indicated in the grounds. 00 (five thousand/00) in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this provision, under penalty of the adoption of the resulting enforcement proceedings pursuant to Article 27 of Law No. ); - pursuant to Articles 58, paragraph 1, letter b) of the GDPR, a) of the Regulation and Article 157 of the Code, to communicate to this Authority, providing adequately documented feedback, within thirty days of notification of this order, the initiatives undertaken to implement the above order pursuant to the aforementioned Article 58, paragraph 2, letter d), as well as any measures implemented to ensure compliance with the legislation on the protection of personal data.
ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Data Protection Authority no. 1/2019, the publication of the injunction order on the website of the Data Protection Authority; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Regulation of the Data Protection Authority no. 1/2019, the publication of this order on the website of the Data Protection Authority; - pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Regulation of the Data Protection Authority no. 17 of the Guarantor Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, as provided for by Art. 57, paragraph 1, letter u), of the Regulation. Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE PRESIDENT Stanzione THE REPORTER Stanzione THE SECRETARY GENERAL Montuori