Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) ·515/2026 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l

(the controller), which was sent without his consent to third parties, amongst which one of the third parties already had a consulting contract with the data subject.

Summary

The data subject exercised his rights pursuant to Articles 15- 22 GDPR however received no response from the controller. The DPA asked the controller to respond within which it found out that the controller had sent a delayed response due to a series of reorganisations. The controller also clarified that they do not process personal data and the only information relating to the data subject was that present in the emails. The controller explained that the forwarding of the email was exclusively for commercial purposes. Holding — The DPA held that the controller failed to respond to the access request in violation of Article 12(3) GDPR, by not informing the data subject within one month of receiving the request the reasons for the controller’s delay, and his possibility to lodge a complaint with a supervisory authority and seeking judicial remedy in violation of Article 12(4) GDPR. Given the minor nature of the controller’s violations, the DPA issued a warning to the controller.

How it connects

Full text

[Web Doc. No. 10289286] Decision of July 3, 2026 Register of Decisions No. 515 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, members; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. XX on March 27, 2023, pursuant to Art. 77 of the Regulation, alleging a data breach in terms of personal data protection by ReLife Recycling s.r.l.; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. The complaint against the Company and the preliminary investigation. Reference is made to the complaint dated December 5, 2023, in which Mr. XX represented that he had had contact (exchanges of emails) with the company Benfante s.r.l. (now ReLife Recycling s.r.l.) “to request a quote from a company”; specifically, the complainant stated that on July 1, 2021, he sent a message from his account to the account XX and copied XX, “which was followed by an exchange of correspondence between the complainant and Mr. XX of Benfante s.r.l.” The complainant also stated that he had learned that subsequently, on July 2, 2021, the aforementioned email exchange had been forwarded, without his consent, from the address XX to third parties—specifically, to the email address XX of the administrator of XX (a company for which the complainant currently held a consulting contract). Finally, the representative of the complainant stated that he had exercised, with respect to the aforementioned company, the rights set forth in Articles 15 through 22 of the Regulation, via a certified letter sent on June 14, 2023 (duly delivered), without receiving any response. By letter dated July 3, 2024 (Ref. No. 81947), the Office sent ReLife Recycling s.r.l. (hereinafter the “Company”) a request to comply with the requests made by the data subject, to provide a response to him, and to send a copy of the response to this Authority. In a subsequent communication dated July 29, 2024, ReLife Recycling s.r.l. forwarded to the Data Protection Authority the response provided to Mr. XX, in which the Company stated: that it had provided a “delayed response” to the data subject due to “a series of reorganizations of our management systems that unfortunately led to an oversight regarding his communication”; that it does not process “any (…) personal data” of the data subject and that the only information “available” to the Company “is that relating to the email exchange mentioned in your letter”; that it had forwarded the aforementioned email exchange to XX “solely and exclusively for commercial purposes”; in particular, “in light of the (…) improper conduct on the part of the same individual,” who “proposed a product not from the company where he worked (i.e., XX), which was already our long-standing supplier, but from a third party.” Invited to submit a rebuttal in a letter dated December 30, 2024, the complainant, through attorney XX, reiterated the complaints already expressed and stated that the controller had provided a “delayed” and “incomplete” response, as it was “deficient with regard to the following aspects”: specification of the categories of data processed; disclosure of the recipients or categories of recipients to whom his personal data had been disclosed (…); specification of the storage period for his personal data (…); disclosure of the origin of the data (…); confirmation that the restriction of processing had been implemented; confirmation that the objection to processing had been acknowledged.” 2. Initiation of the proceedings. Based on the findings of the preliminary investigation, and taking into account the statements made by the parties, it was determined that the Company failed to respond to Mr. XX’s access request for his personal data, submitted by the complainant pursuant to Articles 15 through 22 of the Regulation, in violation of Article 12, para 3, of the Regulation itself, and failed to inform him, within one month of receiving the request, of the reasons for the non-compliance and of the possibility of lodging a complaint with a supervisory authority and seeking judicial remedy, in violation of Article 12, para 4, of the Regulation. In light of the foregoing, the Office notified the Company, by letter dated March 25, 2025, the notice of initiation of proceedings, pursuant to Article 166, paragraph 5, of the Code, in relation to the violation of Articles 12, para 3, and 12, para 4, of the Regulation. On April 19, 2025, the Company submitted its defense brief, pursuant to Article 18 of Law No. 689/1981, in which it argued that the delay in responding to the access request for personal data submitted by XX was caused by a complex corporate reorganization resulting from extraordinary transactions and not by intentional negligence. It is also noted that the request arose in a specific commercial context related to the relationship between the company and XX, and that XX would have used the right of access primarily in the context of a dispute with that company, rather than to review its own personal data. Although it responded late, the Company asserts that it provided all relevant information, cooperated with the Data Protection Authority, and subsequently strengthened its procedures for responding to requests by data subjects to exercise their data subject rights regarding the processing of personal data, as well as appointed a Data Protection Officer (DPO). For these reasons, it considers a monetary penalty to be disproportionate and requests, at most, the issuance of a warning. 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and punitive measures. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the preliminary investigation do not address the findings notified by the Office in the notice initiating the proceedings and are therefore insufficient to warrant thedismissal of this proceeding, as none of the cases provided for in Article 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. In this regard, it should be noted that, unless the act constitutes a more serious offense, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, shall be held liable pursuant to Art. 168 of the Code, “False Statements to the Data Protection Authority and Interruption of the Performance of the Data Protection Authority’s Duties or Exercise of Its Powers.” It is therefore established that the Company’s conduct, with regard to its failure to respond to the access request submitted by the complainant, is unlawful, as set forth above, in relation to Articles 12(3) and (4) of the Regulation, since the Company did not, within one month of receiving the data subject’s request, neither responded to the request nor informed the data subject of the reasons for the failure to comply and of the possibility of lodging a complaint with a supervisory authority and seeking judicial remedy. Having assessed all the evidence gathered during the investigation and the specific circumstances of the case, it is nevertheless considered that the violation, as established above, may be deemed “minor” (see Art. 83, para. 2, and Recital 148 of the Regulation), taking into account, in particular: the negligent nature of the Company’s conduct; the number of data subjects involved (one); the absence of prior violations by the Company; the procedures implemented by the Company to prevent similar occurrences in the future. Given that, pursuant to Recital 148 of the Regulation, “in the case of a minor infringement or where the financial penalty that would otherwise be imposed would constitute a disproportionate burden on a natural person, a warning may be issued instead of a financial penalty,” it is deemed sufficient to issue a warning to the controller pursuant to Article 143 of the Code and Article 58(2)(b) of the Regulation. It is further noted that the conditions are met for the violation to be recorded in the Authority’s internal register pursuant to Article 57(1)(u) of the Regulation (Article 17 of the Data Protection Authority’s Regulation No. 1/2019). Finally, please be advised that, in accordance with the Authority’s statutory and regulatory provisions (Article 154-bis, paragraph 3, of the Code; Article 37 of the Authority’s Regulation No. 1/2019), a copy of this decision will be published on the Authority’s website. THEREFOREWHILE, THE DATA PROTECTION AUTHORITY finds that the processing carried out by ReLife Recycling s.r.l., with registered office in Sant’Olcese (GE), Via Gramsci 2, ZIP Code 16010, VAT No. 03083200109, pursuant to Articles 12, para 3 and 4, and 15 of the Regulation and Article 157 of the Code; pursuant to Article 58, para 2, subparagraph b), of the Regulation, issues a warning to ReLife Recycling s.r.l., as the controller in question, for having conducted personal data processing in violation of the data protection regulations; ORDERS pursuant to Article 154-bis, paragraph 3, of the Code, the publication of this decision on the Data Protection Authority’s website. in accordance with Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the violation shall be recorded in the Authority’s internal register referred to in Article 57, para 1, subparagraph u), of the Regulation. Pursuant to Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree of September 1, 2011, No. 150, an appeal against this decision may be filed with the ordinary courts—under penalty of inadmissibility—within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 3, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori [Web Doc. No. 10289286] Decision of July 3, 2026 Register of Decisions No. 515 of July 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. XX on March 27, 2023, pursuant to Art. 77 of the Regulation, alleging a violation of personal data protection regulations by ReLife Recycling s.r.l.; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. The complaint against the Company and the preliminary investigation. Reference is made to the complaint dated December 5, 2023, in which Mr. XX represented that he had had contact (exchanges of emails) with the company Benfante s.r.l. (now ReLife Recycling s.r.l.) “to request a quote from a company”; specifically, the complainant stated that on July 1, 2021, he sent a message from his account to the account XX and copied XX, “which was followed by an exchange of correspondence between the complainant and Mr. XX of Benfante s.r.l.” The complainant also stated that he had learned that subsequently, on July 2, 2021, the aforementioned email exchange had been forwarded, without his consent, from the address XX to third parties—specifically, to the email address XX of the administrator of XX (a company for which the complainant currently held a consulting contract). Finally, the complainant stated that he had exercised, against the aforementioned company, the rights set forth in Articles 15 through 22 of the Regulation, via a certified letter sent on June 14, 2023 (duly delivered), without receiving any response. By letter dated July 3, 2024 (Ref. No. 81947), the Office sent ReLife Recycling s.r.l. (hereinafter the “Company”) a request to comply with the requests made by the data subject, by providing a response to the data subject and sending a copy of the response to this Authority. In a subsequent communication dated July 29, 2024, ReLife Recycling s.r.l. forwarded to the Data Protection Authority the response provided to Mr. XX, in which the Company stated: that it had provided a “delayed response” to the data subject due to “a series of reorganizations of our management systems that unfortunately led to an oversight regarding his communication”; that it does not process “any (…) personal data” of the data subject and that the only information “available” to the company “is that relating to the email exchange mentioned in your letter”; that it had forwarded the aforementioned email exchange to XX “solely and exclusively for commercial purposes”; in particular, “in light of the (…) improper conduct on the part of the same individual,” who “proposed a product not from the company where he worked (i.e., XX), which was already our long-standing supplier, but from a third party.” Invited to submit a rebuttal in a letter dated December 30, 2024, the complainant, through attorney XX, reiterated the complaints already expressed and stated that the controller had provided a “delayed” and “incomplete” response, as it was “deficient with regard to the following aspects”: indication of the categories of data processed; disclosure of the recipients or categories of recipients to whom his personal data had been disclosed (…); specification of the storage period for his personal data (…); disclosure of the origin of the data (…); confirmation that the restriction of processing had been implemented; confirmation that the objection to processing had been acknowledged.” 2. Initiation of the proceedings. Based on the findings of the preliminary investigation, and taking into account the statements made by the parties, it was determined that the Company failed to respond to Mr. XX’s access request for his personal data, submitted by the complainant pursuant to Articles 15 through 22 of the Regulation, in violation of Article 12, para 3, of the Regulation itself, and did not inform him, within one month of receiving the request, of the reasons for the failure to comply and of the possibility of lodging a complaint with a supervisory authority and seeking judicial redress, in violation of Article 12, para 4, of the Regulation. In light of the foregoing, the Office notified the Company, by letter dated March 25, 2025, the notice of initiation of proceedings, pursuant to Article 166, paragraph 5, of the Code, in connection with the violation of Articles 12, para 3, and 12, para 4, of the Regulation. On April 19, 2025, the Company submitted its defense brief, pursuant to Article 18 of Law No. 689/1981, in which it argued that the delay in responding to the access request for personal data submitted by XX was caused by a complex corporate reorganization resulting from extraordinary transactions and not by intentional negligence. It is also noted that the request arose within a specific commercial context related to the relationship between the company and XX, and that XX would have used the right of access primarily in the context of a dispute with that company, rather than to verify its own personal data. Although it responded late, the Company asserts that it provided all relevant information, cooperated with the Data Protection Authority, and subsequently strengthened its procedures for responding to requests to exercise data subject rights regarding the processing of personal data, as well as appointed a Data Protection Officer (DPO). For these reasons, it considers a monetary penalty to be disproportionate and requests, at most, the issuance of a warning. 3. The outcome of the preliminary investigation and the proceedings for the adoption of corrective and punitive measures. In light of the overall findings, the Authority considers that the statements, documentation, and explanations provided by the controller during the preliminary investigation do not sufficiently address the findings notified by the Office in the notice initiating the proceedings and are therefore insufficient to justifydismissal of this proceeding, since none of the cases provided for in Article 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. In this regard, it should be noted that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Data Protection Authority, falsely declares or attests to facts or circumstances, or produces false documents or records, is liable under Art. 168 of the Code, “False statements to the Data Protection Authority and obstruction of the Authority’s duties or powers.” It is therefore established that the Company’s conduct—specifically, its failure to respond to the access request submitted by the complainant—is unlawful, as set forth above, in relation to Articles 12(3) and (4) of the Regulation, since the Company did not, within one month of receiving the data subject’s request, either responded to the request or informed the data subject of the reasons for the failure to comply and of the possibility of lodging a complaint with a supervisory authority and seeking judicial remedy. Having assessed all the evidence gathered during the investigation and the specific circumstances of the case, it is nevertheless considered that the violation, as established above, may be deemed “minor” (see Art. 83, para. 2, and Recital 148 of the Regulation), taking into account, in particular: the negligent nature of the Company’s conduct; the number of data subjects involved (one); the absence of prior violations by the Company; the procedures implemented by the Company to prevent similar occurrences in the future. Given that, pursuant to Recital 148 of the Regulation, “in the case of a minor infringement or if the financial penalty that would otherwise be imposed would constitute a disproportionate burden on a natural person, a warning may be issued instead of a financial penalty,” it is deemed sufficient to issue a warning to the controller pursuant to Article 143 of the Code and Article 58(2)(b) of the Regulation. It is further noted that the conditions are met for the violation to be recorded in the Authority’s internal register pursuant to Article 57(1)(u) of the Regulation (Article 17 of the Data Protection Authority’s Regulation No. 1/2019). Finally, please be advised that, in accordance with the Authority’s statutory and regulatory provisions (Article 154-bis, paragraph 3, of the Code; Article 37 of the Data Protection Authority Regulation No. 1/2019), a copy of this decision will be published on the Data Protection Authority’s website. THEREFOREWHILE, THE DATA PROTECTION AUTHORITY finds that the processing carried out by ReLife Recycling s.r.l., with registered office in Sant’Olcese (GE), Via Gramsci 2, ZIP Code 16010, VAT No. 03083200109, pursuant to Articles 12, para 3 and 4, and 15 of the Regulation and Article 157 of the Code; pursuant to Article 58, para 2, letter b), of the Regulation, issues a warning to ReLife Recycling s.r.l., as the controller in question, for having conducted personal data processing in violation of the regulations governing data protection; ORDERS pursuant to Article 154-bis, paragraph 3, of the Code, the publication of this decision on the Data Protection Authority’s website. in accordance with Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the violation shall be recorded in the Authority’s internal register referred to in Article 57(1)(u) of the Regulation. Pursuant to Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree No. 150 of September 1, 2011, No. 150, an appeal against this decision may be filed with the ordinary courts—under penalty of inadmissibility—within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 3, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori