# Italian DPA: Meteorological Institute violated transparency duties during video

- Type: Enforcement
- Source: Garante per la protezione dei dati personali (Italy)
- Date: 2026-10-01
- Original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10297167
- Canonical: https://overview.legal/posts/449709
- Topics: Personal Data, Processing, DPIA, Transparency, Video Surveillance, Monitoring, Controllers, Supervisory Authorities

## Summary

Facts — The DPA received two distinct but related complaints from employees (the data subjects) of the National Institute of Meteorological Research (the controller) concerning the transparency of the use of video surveillance. The controller clarified that the surveillance was subject to a trade agreement within which they were testing the use and coverage of 10 cameras. The cameras would only record when the alarm was activated, and excluded the possibility of recording areas which were subject to public access. Storage of the recordings was limited to 72 hours from the trigger of an alarm. The controller further explained that at the time the surveillance system was being tested without actually recording any images. Particularly, the controller sought to verify the technical and adequate functioning of the cameras and monitors as well as effective coverage of the security parameter. Due to insufficient and inadequate coverage of certain areas, which was deemed contrary to the purpose of the surveillance, the controller subsequently installed 8 additional cameras. The controller clarified that this was in line with the agreement which allowed for extraordinary maintenance. As a result of the surveillance being at the testing phase, the controller did not provide the data subjects and staff of the information regarding data processing. The controller emphasised that before its official operation this information would be provided. Holding — The DPA held that the installed cameras were incompatible with the agreement as a result of increasing the number of cameras as well as the modification of their location and subsequent area being converted. Nonetheless, the DPA found that the extraordinary maintenance did not allow for the defined area being covered by the cameras to be altered. Therefore, although the purpose of surveillance activation was to test the system, personal data processing was still being undertaken. The DPA further emphasised that the controller failed to inform its staff and interested parties sufficiently of the surveillance practices, neither of the associated personal data processing happening, prior to its implementation. The DPA held that the lack of information and the fact that the signage was affixed after the processing had already taken place was insufficient. Finally, the DPA found that the controller implemented the video surveillance in its workplace, which considered of the processing of personal data of its employees, in absence of the necessary data protection impact assessment, contrary to Article 35 GDPR. In light of the foregoing the DPA fined the controller €10,000 for violations of Articles 5(1)(a), 12, 13, 35 and 88 GDPR.

## Full text

[Web Doc. No. 10297167] Decision of September 3, 2026 Register of Decisions No. 620 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection,” which sets forth provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC” (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and functioning of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Dr. Agostino Ghiglia; PREAMBLE 1. Introduction. In separate but related complaints filed pursuant to Article 77 of the Regulation against the National Institute of Metrological Research—INRIM (hereinafter, the “Institute”), two employees of the Institute alleged a violation of the regulations governing data protection. Specifically, it was alleged that, after entering into an agreement with union representatives pursuant to Article 4 of Law No. 300 of May 20, 1970, regarding the use of a video surveillance system at the Institute’s Turin headquarters, said system was activated during a test phase without, however, ensuring the necessary transparency of the processing with respect to the data subjects (employees and individuals who visit the premises for various reasons), by subjecting areas not covered by the agreement to video surveillance, as well as by using monitoring screens located in areas potentially accessible even to unauthorized individuals. 2. The Preliminary Investigation. In response to a request for information (see XX), made pursuant to Article 157 of the Code, the Institute, in a letter dated XX (Ref. No. XX), as supplemented by a subsequent letter dated XX (Ref. No. XX), stated, in particular, that: - “the video surveillance system covered by the union agreement entered into on May 16, 2025, pursuant to Art. 4 of Law No. 300/1970 […] was installed at the INRiM headquarters in Turin”; - “The physical installation of the cameras, which began on May 19, 2025, was completed on October 30, 2025. A total of 18 cameras have been installed”; - “On October 31, 2025, the system was activated in test mode, a status that was maintained even during the subsequent holidays and days when the Institute was closed on November 1 and 2 […;] during the testing phase, only the viewing function was activated, with no recording of images”; - “On the following workdays, from November 3 to 5, the contracted enterprise—in order to calibrate and adjust the cameras and monitors—activated the system for a few hours, again without any image recording”; - “Starting November 6, 2025, in order to test the system, it was activated exclusively during the institution’s nighttime hours of closure, from 8:30 p.m. to 7:30 a.m., and on days when the institution is closed: Saturdays, Sundays, and holidays. During these operating hours, image recording occurs only when the alarm is triggered—that is, when an object crosses the optical barrier […;] the areas subject to surveillance are all located within the Institute’s premises, excluding the possibility of filming areas open to the public”; - “[…] the system therefore never entered into operation for the prescribed surveillance purposes, as established by the […] Agreement, but only to verify its technical functionality and adequacy, with specific regard to the effective and efficient coverage of the security perimeter and the proper functioning of the cameras and monitors”; - “The Agreement is based on […] purposes […of] protecting company assets […, allowing for…] filming exclusively of the perimeter walls and fences”; - the union agreement permitted “[…] adjustments due to the presence of visual obstructions (e.g., vegetation and existing structures) […]”; - “the site plan attached to the agreement provided for the installation of 10 cameras. However, during the final design and technical installation phases, it became apparent that the number of devices was insufficient to ensure adequate coverage of the areas to be monitored and, consequently, to effectively pursue the intended purposes of the video surveillance system […] it therefore became necessary to supplement the originally planned number with an additional 8 cameras”; - “this modification, however, should not in itself be considered a breach of the agreement. In fact, the agreement itself provides for mechanisms to verify the consistency of the actual installation with what was agreed upon. Art 7 provides that: “The consistency of the system, in its final installation, with what is set forth in this agreement may be subject to verification by the RSU and/or the labor unions, upon submission of a request to the General Management”; - “The email communication from the Director General dated November 14, 2025 […] must be interpreted in this light, in which the Institute informed the RSU of the need to convene a meeting to explain the modifications made, in order to assess the system’s compliance with the agreed-upon purposes”; - “The storage periods for video recordings, in the event the system is activated, are those specified in Art. 2.4 [of the union agreement,] pursuant to which: “The maximum period for video recording storage is 72 hours from the time the recordings are captured […]”; - “the testing and verification phase, involving the RSU, has not yet been completed and, therefore, the system has not yet become operational”; - “Consequently, the privacy notice regarding the processing of personal data has not yet been provided to the Institute’s staff [; …] the notice will in any case be provided to employees before the system becomes operational through publication on the institutional intranet, following a specific internal communication”; - “the signage [containing the first-level privacy notice] was posted on November 17, 2025”; - “the second-level privacy notice will be made available to data subjects through publication on the Institute’s institutional website”; - “INRiM has decided to postpone [the] data protection impact assessment until the technical and organizational structure of the facility has been finalized, in any case prior to its entry into operation”; - “The surveillance monitors are located in the guardhouse, a room where—during daytime hours—staff from the company contracted to provide the relevant service are on duty, and—during nighttime hours—staff from the company contracted to provide armed security are on duty”; - “Following testing, it was determined that certain windows of the guardhouse need to be blacked out, a measure to be implemented before the system becomes operational”; - “[…] access to the video footage will be limited to Institute personnel authorized for that purpose.” By letter dated XX (Ref. No. XX), the Office, based on the information gathered, the inspections conducted, and the facts that emerged following the preliminary investigation, notified the Institute, pursuant to Article 166, paragraph 5, of the Code, the initiation of proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation, on the grounds that the Institute had carried out, through video surveillance cameras, the processing of personal data of employees on duty and other individuals present in various capacities at the Turin office, in a manner inconsistent with the principle of “lawfulness, fairness, and transparency” and in the absence of a legal basis, in violation of Articles 5, para 1, subparagraph (a), Article 6, para 1, subparagraph c), and para 2 and para 3, and Article 88, para 1, of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970); for failing to ensure the necessary transparency of the processing with respect to data subjects, in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation; for failing to conduct a data protection impact assessment prior to commencing processing, in violation of Article 35 of the Regulation. In the same notice, the aforementioned data controller was invited to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Art. 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). In a letter dated XX (Ref. No. XX), the Institute submitted a defense brief, stating, in particular, that: - “the system was activated for testing […] under significantly limited conditions, both operationally and in terms of duration”; - “the system operated exclusively in view-only mode, without any recording of images, and the system’s activation in the presence of staff was limited to an extremely limited number of workdays (a total of four workdays), specifically: Friday, October 31, 2025, and, subsequently, the period between November 3 and 5, 2025, for the time strictly necessary (amounting to a few hours per day) to carry out the verification, calibration, and adjustment of the equipment by the contracted enterprise […]”; - “[…] the system has never been used to monitor employees’ work activities or for disciplinary purposes […]”; - “the activities […] were carried out during a phase of installation, technical verification, and testing of the system, which the Institute considered not yet to correspond to its actual entry into service for the video surveillance purpose provided for in the union agreement”; - there was, therefore, “an erroneous interpretation of the regulatory framework applicable to the system’s testing and commissioning phase”; - there were “technical circumstances that made it necessary, during the installation phase, to increase the number of camera modules (from 10 to 18) [… in order] to ensure continuous perimeter coverage of the Institute […]”; - “the Institute has […] begun preparing the privacy documentation related to the system”;on June 12, 2026, a meeting convened by the General Management with union representatives was held […and] the parties agreed on the need to obtain additional technical information from the installation company and to proceed, following the necessary further analysis, to a further joint review”. 3. Outcome of the Preliminary Investigation. 3.1 Lawfulness of the Processing. The processing of personal data relating to employees, carried out through video surveillance cameras capable of recording staff passing through or staying in the workplace, may be performed by the employer if it is necessary for the management of the employment relationship, in compliance with the applicable legal framework, as defined by national and EU legislation, regulations, or collective bargaining agreements (Articles 6(1)(c) and 88 of the Regulation). Within this framework, the employer must comply with national rules that “include appropriate and specific measures to safeguard the human dignity […] of the data subjects, in particular with regard to the transparency of the processing […] and workplace monitoring systems” (Article 88(2) of the Regulation, to which Article 6(2) of the Regulation refers). As consistently reiterated in the Data Protection Authority’s rulings, processing resulting from the use of technological tools in places where work is also carried out finds its legal basis in the sector-specific regulations set forth in Art. 4 of Law No. 300 of May 20, 1970 (Workers’ Statute), paragraph 1 of which provides that “audiovisual systems and other devices that also enable remote monitoring of workers’ activities may be used exclusively for organizational and production needs, for workplace safety, and for the protection of company assets, and may be installed subject to a collective agreement entered into by the unified union representation or by the company-level union representatives […]. In the absence of such an agreement, the systems and devices referred to in the first sentence may be installed subject to authorization from the regional office of the National Labor Inspectorate or, alternatively, […] from the central office of the National Labor Inspectorate.” This provision uniformly defines, at the national level, the scope of permitted processing in every workplace (public and private) and constitutes, within the domestic legal system, a more specific provision offering greater safeguards than that set forth in Art. 88 of the Regulation, compliance with which - by virtue of the reference in the Code to pre-existing national sector-specific provisions that protect the dignity of individuals in the workplace, with particular reference to possible monitoring by the employer (Art 114 “Guarantees Regarding Remote Monitoring”) - is a condition for the lawfulness of the processing (see Art. 5, para. 1, subpara. a) and 6, para. 1, subpara. c) of the Regulation); see, at the European level, the guidance contained in “Guidelines 3/2019 on the processing of personal data through video devices,” adopted by the European Data Protection Board on January 29, 2020, para. 11, as well as the previous guidance from the Art 29 Working Party in “Opinion 2/2017 on the processing of data in the workplace,” WP 249; see para. 4.1 of the “Provision on Video Surveillance” of April 8, 2010, web doc. no. 1712680, and, most recently, the Data Protection Authority’s FAQ No. 9 on video surveillance, dated December 2020, web doc. 9496574, and the Data Protection Authority’s numerous decisions regarding specific cases, including, with specific regard to the use of video surveillance in the workplace, the provisionNo. 70 of February 12, 2026, web doc. No. 10226611; No. 43 of January 29, 2026, web doc. No. 10226639; October 23, 2025, No. 628, web doc. No. 10196164; July 10, 2025, No. 410, web doc. No. 10162731; April 10, 2025, No. 201, web doc. No. 10139433; April 11, 2024, No. 234, web doc. No. 10013356; November 16, 2023, No. 578, web doc. No. 9963486; March 11, 2021, No. 90, web doc. No. 9582791; March 5, 2020, No. 53, web doc. No. 9433080; see Order No. 167 of September 19, 2019, web doc. No. 9147290). This is in accordance with the case law of the European Court of Human Rights in the case of Antovic and Mirković v. Montenegro (Application No. 70838/13 of November 28, 2017), which held that respect for private life must also extend to public workplaces, emphasizing that the use of video surveillance devices in the workplace can be justified only in compliance with the safeguards provided for by applicable national law; in the absence of such safeguards, it constitutes an unlawful interference with the employee’s private life, pursuant to Art. 8, para. 2, of the ECHR. In the case under investigation, on May 16, 2025, the Institute entered into an agreement with the labor unions, pursuant to Art. 4 of Law No. 300/1970, an agreement regarding the use of a “perimeter video surveillance system” (preamble) at its Turin headquarters to “ensure the protection of company assets” (Art. 1.1). This agreement specifies that “the CCTV cameras will be installed so as to film exclusively the perimeter walls and fences, subject to the necessary adjustments due to the presence of visual obstructions (e.g., vegetation and existing structures) […] in accordance with the detailed site plan provided to the union representatives for review” (Art. 2.1); “the system records the images captured by the CCTV system 24 hours a day, including Saturdays, Sundays, holidays, and days when the Institute is closed” (Art. 2.3). After entering into this agreement with the labor unions, however, the Institute installed the system in a manner that did not comply with the layout plan agreed upon with the labor unions, increasing the number of cameras by eight and modifying their placement and respective coverage areas. Nevertheless, the same union agreement stipulated that “the perimeter video surveillance system may be subject to extraordinary maintenance, including non-substantial technological improvements or upgrades, without the need to amend this agreement, provided that […] the defined coverage areas are not altered” (Art. 2.5). The Institute put this system into operation in a manner inconsistent with the layout plan agreed upon with the labor unions, even on workdays (on October 31, 2025, and then from November 3 to 5, albeit for a few hours each day). Although the system was activated for testing purposes and without recording images—merely displaying them in real time—it nonetheless involved the processing of personal data of employees on duty and other individuals present at the Turin office for various reasons, in a manner inconsistent with the procedures agreed upon with the labor unions and, therefore, in a manner that did not comply with the principle of “lawfulness, fairness, and transparency” and in the absence of a legal basis, in violation of Articles 5(1)(a), para 1, Article 6(1)(c) and para 2, and para 3, and Article 88(1) of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970). However, the grounds for the complaint regarding the placement of surveillance monitors in areas potentially accessible even to unauthorized persons cannot be upheld, given that, as stated by the Institute during the preliminary investigation—and assuming accountability also pursuant to Article 168 of the Code— these monitors are located in the reception area, a room where only personnel assigned to the reception or security service work; and that, once the testing phase is complete and the system is operating under normal conditions, certain windows of the reception area will in any case be covered to prevent the monitors from being viewed by unauthorized persons. 3.2. Transparency of Processing. 3.2.1. With Respect to Employees. In accordance with the principle of “lawfulness, fairness, and transparency” (Article 5, para 1, subparagraph a) of the Regulation), the controller must take appropriate measures to provide the data subject with all the information referred to in Articles 13 and 14 of the Regulation in a concise, transparent, intelligible, and easily accessible form, using plain and clear language (see Article 12, para 1, of the Regulation). In this regard, the Institute has stated that it did not provide its employees with a specific privacy notice regarding the video surveillance system in question pending “the definition, to be verified with the RSU, of the technical and functional aspects.” As explained above, the Institute nevertheless put the video surveillance system into operation on certain days when the offices were open—albeit in a manner different from that agreed upon with the labor unions—without the employees being aware of this circumstance or of the essential characteristics of the resulting processing of their personal data. Instead, the Institute should have provided its employees with a specific privacy notice regarding the processing of personal data before putting the system into operation and, therefore, before initiating any data processing through said system, as it is irrelevant that the system was activated solely for testing and technical verification purposes. It must therefore be concluded that the Institute acted in a manner inconsistent with the principle of “lawfulness, fairness, and transparency,” in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation. 3.2.2. With regard to other categories of data subjects. When video surveillance devices are used, the controller, in addition to providing first-level information by posting warning signs near the area under video surveillance, must also provide data subjects with “second-level information,” which must “contain all the mandatory elements required under Article 13 of the [Regulation]” and “be easily accessible to the data subject, for example through a comprehensive information page made available at a central hub […] or posted in an easily accessible location” (“Guidelines 3/2019 on the Processing of Personal Data through Video Devices,” op. cit., specifically para. 7; but see also the Data Protection Authority’s “Provision on Video Surveillance” of April 8, 2010, cited above, in particular para. 3.1; most recently, see the Data Protection Authority’s FAQ No. 4 on video surveillance, cited above). Top-level information (warning notice) “should convey the most important details, such as the processing purpose, the identity of the controller, and the existence of the data subject rights, along with information on the most significant impacts of the processing” (“Guidelines 3/2019 on the Processing of Personal Data through Video Devices,” op. cit., para. 114). Furthermore, the signage must also include information that might come as a surprise to the data subject. This could include, for example, the transfer of data to third parties—particularly if they are located outside the EU—and the data storage period. If such information is not provided, the data subject should be able to rely on the assumption that only real-time Surveillance is taking place, without any data recording or transmission to third parties (ibid., cited above, para. 115). The first-level warning signage must contain a clear reference to the second level of information, for example by indicating a website where the text of the extended privacy notice can be consulted. In the case at hand, although the Institute activated the video surveillance system on October 31, 2025, and then from November 3 to 5 (for a few hours each day), it stated that it had posted “the signage [containing the first-level data processing notice] [only] on November 17, 2025,” while no second-level notice was made available to the data subjects. It should also be noted, however, that this sign—posted after the dates on which the video surveillance system was activated for testing purposes—does not comply with data protection regulations, since it does not clearly indicate the details of the controller of the processing (it only reads the acronym “INRIM,” without any contact information); it refers to a generic and potentially misleading processing purpose (“security”) rather than the one actually pursued (protection of company assets); it does not mention the rights of data subjects, does not specify the data storage periods, and does not clarify that the so-called “QR Code” allows users to access a complete second-level privacy notice (see the sample information sign in para 115 of the “Guidelines 3/2019 on the Processing of Personal Data via Video Devices,” cited above). The Institute has, therefore, acted in a manner inconsistent with the principle of “lawfulness, fairness, and transparency” and in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation. 3.3 The data protection impact assessment. When a type of processing may pose a high risk to the rights and freedoms of natural persons and, in any case, when the strictly defined conditions apply, the controller must, prior to carrying out the processing, conduct a data protection impact assessment in order to adopt, in particular, appropriate measures to address such risks, after consulting the Data Protection Authority in advance, where the conditions are met (see Articles 35 and 36(1) of the Regulation). Taking into account the guidance provided on this matter at the European level as well, it is considered that, in the present case, the Institute should have conducted a data protection impact assessment before commencing the processing, given that it entailed specific risks to the rights and freedoms of employees. This is due both to the particular “vulnerability” of the data subjects in the workplace (see Recitals 75 and Art. 88 of the Regulation and the “Guidelines on data protection impact assessments and the criteria for determining whether processing ‘is likely to result in a high risk’ under Regulation 2016/679,” WP 248 of April 4, 2017, which expressly mentions “employees” among the categories of vulnerable data subjects), as well as the fact that systems are used that involve “systematic monitoring” in the workplace, defined as “processing used to observe, monitor, or control data subjects, including data collected via networks” (see criterion No. 3 set forth in the Guidelines, cited above, but see also criteria 4 and 7; see Articles 35 and 88(2) of the Regulation; see also Decision No. 467 of October 11, 2018, web doc. No. 9058979, Annex No. 1, which expressly mentions “processing carried out in the context of the employment relationship using technological systems […] that enable remote monitoring of employees’ activities”). The failure to conduct a data protection impact assessment regarding video surveillance systems used in the workplace has, for these reasons, been the subject of recent corrective and punitive decisions by the Data Protection Authority (see, in particular, decisionsNo. 70 of February 12, 2026, web doc. No. 10226611; No. 43 of January 29, 2026, web doc. No. 10226639; October 23, 2025, No. 628, cited above; July 10, 2025, No. 410, web doc. No. 10162731; April 10, 2025, Web Doc. No. 10139433; March 13, 2025, No. 135, web doc. No. 10128005; November 16, 2023, No. 578, web doc. No. 9963486). In light of all the foregoing considerations, it must be concluded that the Institute processed employees’ personal data through the video surveillance system in question without conducting a prior data protection impact assessment and, therefore, in violation of Article 35 of the Regulation. 4. Conclusions. In light of the assessments referred to above, it is noted that the statements made by the controller during the preliminary investigation—for the veracity of which the controller may be held accountable pursuant to Art. 168 of the Code—while worthy of consideration, do not suffice to rebut the findings notified by the Office in the notice initiating the proceedings and are insufficient to warrant the dismissal of these proceedings, especially since none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The Office’s preliminary assessments are therefore confirmed, and the processing of personal data by the Institute is found to be unlawful, as it carried out the processing of personal data using video surveillance cameras in violation of Articles 5(1)(a), para. 1, 6(1)(c) and (2) and (3), 12(1), 13, 35, and 88(para 1) of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970). Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing operation or related processing operations), Art 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Recital 1: Given that, in the present case, the most serious violations—relating to Articles 5, para 1, subparagraph (a); 6, para 1, subparagraph (c), and paragraphs 2 and 3; 12, para 1, 13, and 88, para 1, of the Regulation, as well as Article 2-ter of the Code, are subject to the penalty provided for in Article 83, para 5, of the Regulation, as also referred to in Article 166, para 2, of the Code, The total amount of the penalty is to be set at up to 20,000,000 euros. In this context, considering, in any case, that the conduct has ceased to have any effect—given that, as stated by the Institute, the video surveillance cameras in question were activated during office hours for only four business days, the conditions for adopting further corrective measures under Article 58(2) of the Regulation do not apply. 5. Adoption of the injunction order for the imposition of the administrative fine and ancillary sanctions (Articles 58(2)(i) and 83 of the Regulation; Article 166, paragraph 7, of the Code). The Data Protection Authority, pursuant to Articles 58(2)(i) and 83 of the Regulation, as well as Article 166 of the Code, has the power to “impose an administrative fine pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in lieu of such measures, depending on the circumstances of each individual case” and, in this context, “the Board [of the Data Protection Authority] issues an injunction, by which it also orders the application of the ancillary administrative sanction of publication, in full or in part, on the Data Protection Authority’s website pursuant to Article 166, paragraph 7, of the Code” (Art. 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019). In this regard, taking into account Article 83(3) of the Regulation, in the present case, the violation of the aforementioned provisions is subject to the imposition of the administrative fine provided for in Article 83(5) of the Regulation. The amount of the aforementioned administrative fine, depending on the circumstances of each individual case, must be determined by taking due account of the factors set forth in Article 83(2) of the Regulation. Considering that: - although the processing was not fully in compliance with the provisions of the union agreement, it was carried out for testing purposes and lasted only a few hours over the course of just four workdays (see Art. 83(2)(a) of the Regulation); - the violation was committed through negligence (see Art. 83(2)(b) of the Regulation); - the processing did not involve special categories of data as defined in Article 9 of the Regulation (see Article 83(2)(g) of the Regulation), it is considered that, in the present case, the severity of the violation committed by the controller is low (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60). That said, given that the controller is a public research institution of national importance but operating on a local basis and without providing services directly to users, it is considered that, for the purposes of determining the amount of the fine, the following circumstances should be taken into account: - The Institute cooperated fully with the Authority during the investigation (see Art. 83, para. 2, subpar. f) of the Regulation); - there are no relevant prior violations committed by the Institute (see Article 83(2)(e) of the Regulation). In light of the above factors, assessed as a whole, the Authority has determined that the amount of the fine shall be 10,000 (ten thousand) euros for the violation of Articles 5(1)(a), para 1, 6, para 1, subparagraph c), and para 2 and 3, 12, para 1, 13, 35, and 88, para 1, of the Regulation, as well as Articles 2-ter and 114 of the Code, as an administrative fine deemed, pursuant to Article 83, para 1, of the Regulation, to be effective, proportionate, and dissuasive. It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the fact that the processing concerns the personal data of employees, who are vulnerable individuals in the workplace and, moreover, were not informed about the nature of the processing. Finally, it is noted that the conditions set forth in Article 17 of Regulation No. 1/2019 are met. GIVEN THE FOREGOING, THE DATA PROTECTION AUTHORITY declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by the Institute is unlawful due to a violation of Articles 5(1)(a), Article 6(1)(c) and (2) and (3), Article 12(1), Article 13, Article 35, and Article 88(1) of the Regulation, as well as Articles 2-ter and 114 of the Code, as set forth in the reasoning; ORDERS the National Institute of Metrological Research (INRIM), in the person of its pro tempore legal representative, with registered office at Strada Delle Cacce, 91 - 10135 Turin (TO), Tax ID No. 09261710017, to pay the sum of 10,000 (ten thousand) euros as an administrative fine for the violations indicated in the grounds of this decision. It is noted that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half of the imposed penalty; ORDERS the aforementioned institution, in the event that the dispute is not settled pursuant to Article 166, paragraph 8, of the Code, to pay the sum of 10,000 (ten thousand) in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of this injunction on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violations and the measures taken in accordance with Article 58, para 2 of the Regulation, in the Authority’s internal register provided for by Article 57, para 1, letter u) of the Regulation. Pursuant to Article 78 of the Regulation, Article 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts, under penalty of inadmissibility, within thirty days from the date of notification of the decision or within sixty days if the appellant resides abroad. Rome, September 3, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori [Web Doc. No. 10297167] Decision of September 3, 2026 Register of Decisions No. 620 of September 3, 2026 THE DATA PROTECTION COMMISSIONER AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair, Prof. Ginevra Cerrina Feroni, Vice Chair, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection,” which sets forth provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC” (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at the performance of the duties and the exercise of the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and functioning of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Dr. Agostino Ghiglia; PREAMBLE 1. Introduction. In separate but related complaints filed pursuant to Article 77 of the Regulation against the National Institute of Metrological Research—INRIM (hereinafter, the “Institute”), two employees of the Institute alleged a data breach. Specifically, it was alleged that, after entering into an agreement with union representatives pursuant to Article 4 of Law No. 300 of May 20, 1970, regarding the use of a video surveillance system at the Institute’s Turin headquarters, said system was activated during a testing phase without, however, ensuring the necessary transparency of the processing with respect to the data subjects (employees and individuals who visit the premises for various reasons), subjecting areas not covered by the agreement to video surveillance, as well as using monitoring screens located in areas potentially accessible even to unauthorized individuals. 2. The Preliminary Investigation. In response to a request for information (see XX), submitted pursuant to Article 157 of the Code, the Institute, in a letter dated XX (Ref. No. XX), as supplemented by a subsequent letter dated XX (Ref. No. XX), stated, in particular, that: - “the video surveillance system covered by the union agreement entered into on May 16, 2025, pursuant to Art. 4 of Law No. 300/1970 […] was installed at the INRiM headquarters in Turin”; - “The physical installation of the cameras, which began on May 19, 2025, was completed on October 30, 2025. A total of 18 cameras have been installed”; - “On October 31, 2025, the system was activated in test mode, a state that was maintained even during the subsequent holidays and days when the Institute was closed on November 1 and 2 […;] during the testing phase, only the display function was activated, with no recording of images”; - “On the following business days, from November 3 to 5, the contracted enterprise—in order to calibrate and adjust the cameras and monitors—activated the system for a few hours, again without any image recording”; - “Starting November 6, 2025, in order to test the system, it was activated exclusively during the institution’s nighttime hours of closure, from 8:30 p.m. to 7:30 a.m., and on days the institution is closed: Saturdays, Sundays, and holidays. During these operating hours, image recording occurs only when the alarm is triggered—that is, when an object crosses the optical barrier […;] the areas subject to video surveillance are all located within the Institute’s perimeter, excluding the possibility of filming areas open to the public”; - “[…] the system therefore never entered into operation for the prescribed surveillance purposes, as established by the […] Agreement, but only to verify its technical functionality and adequacy, with specific regard to the effective and efficient coverage of the security perimeter and the proper functioning of the cameras and monitors”; - “The Agreement is based on […] purposes […of] protecting company assets […, allowing for…] filming exclusively of the perimeter walls and fences”; - the union agreement allowed for “[…] adjustments due to the presence of visual obstructions (e.g., vegetation and existing structures) […]”; - “the site plan attached to the agreement provided for the installation of 10 cameras. However, during the final design and technical installation phases, it became apparent that the number of devices was insufficient to ensure adequate coverage of the areas to be monitored and, consequently, to effectively achieve the purpose of the video surveillance system […] it therefore became necessary to supplement the originally planned number with an additional 8 cameras”; - “this modification, however, should not in itself be considered a breach of the agreement. In fact, the agreement itself provides for mechanisms to verify that the actual installation is consistent with what was agreed upon. Art 7 provides that: “The consistency of the system, in its final installation, with what is set forth in this agreement may be subject to verification by the RSU and/or the labor unions, upon submission of a request to the General Management”; - “The email communication from the Director General dated November 14, 2025 […] should be interpreted in this light; in it, the Institute informed the RSU of the need to convene a meeting to explain the modifications made, in order to assess the system’s compliance with the agreed-upon purposes”; - “The storage periods for video recordings, in the event the system is activated, are those specified in Art. 2.4 [of the union agreement], pursuant to which: “The maximum period for video recording storage is 72 hours from the time the recordings are captured […]”; - “the testing and verification phase, involving the RSU, has not yet been completed and, therefore, the system has not yet become operational”; - “Consequently, the privacy notice regarding the processing of personal data has not yet been provided to the Institute’s staff [; …] the notice will in any case be provided to employees before the system becomes operational through publication on the institutional intranet, following a specific internal communication”; - “The signage [containing the first-level privacy notice] was posted on November 17, 2025”; - “The second-level privacy notice will be made available to data subjects through publication on the Institute’s institutional website”; - “INRiM has decided to postpone [the] data protection impact assessment until the technical and organizational structure of the facility has been finalized, in any case prior to its entry into operation”; - “The surveillance monitors are located in the guardhouse, a room where—during daytime hours—staff from the company contracted to provide the relevant service are on duty, and—during nighttime hours—staff from the company contracted to provide armed security are on duty”; - “Following testing, it was determined that certain windows of the guardhouse need to be blacked out, to be completed before the facility begins operations”; - “[…] access to the video footage will be limited to Institute personnel authorized for that purpose.” By letter dated XX (Ref. No. XX), the Office, based on the information gathered, the inspections conducted, and the facts that emerged following the preliminary investigation, notified the Institute, pursuant to Article 166, paragraph 5, of the Code, the initiation of proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation, on the grounds that the Institute had carried out, through the use of video surveillance cameras, the processing of personal data of employees on duty and other individuals present at the Turin office in various capacities, in a manner inconsistent with the principle of “lawfulness, fairness, and transparency” and without a legal basis, in violation of Articles 5, para 1, subparagraph a), Article 6(1)(c) and (2) and (3), and Article 88(1) of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970); for failing to ensure the necessary transparency of the processing with respect to data subjects, in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation; for failing to conduct a data protection impact assessment prior to commencing processing, in violation of Article 35 of the Regulation. In the same notice, the aforementioned data controller was invited to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Art. 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). In a letter dated XX (Ref. No. XX), the Institute submitted a defense brief, stating, in particular, that: - “the system was activated in [a] test phase […] under significantly limited conditions, both operationally and in terms of duration”; - “the system operated exclusively in view-only mode, without any recording of images, and the system’s activation in the presence of staff was limited to an extremely limited number of workdays (a total of four workdays), specifically: Friday, October 31, 2025, and, subsequently, the period between November 3 and 5, 2025, for the time strictly necessary (amounting to a few hours per day) to carry out the verification, calibration, and adjustment of the equipment by the contracted enterprise […]”; - “[…] the system has never been used to monitor employees’ work activities or for disciplinary purposes […]”; - “the activities […] were carried out during a phase of installation, technical verification, and testing of the system, which the Institute considered not yet to have entered into actual operation for the video surveillance purpose provided for in the union agreement”; - there was, therefore, “an erroneous interpretation of the regulatory framework applicable to the system’s testing and commissioning phase”; - there were “technical circumstances that made it necessary, during the installation phase, to increase the number of camera modules (from 10 to 18) [… in order] to ensure continuous perimeter coverage of the Institute […]”; - “the Institute has […] begun preparing the privacy documentation related to the system”;on June 12, 2026, a meeting convened by the General Management with union representatives was held […and] the parties agreed on the advisability of obtaining additional technical information from the installation company and, following the necessary further investigation, proceeding with a further joint verification”. 3. Outcome of the Preliminary Investigation. 3.1 The Lawfulness of the Processing. The processing of personal data relating to employees, carried out using video surveillance cameras capable of recording personnel passing through or staying in the workplace, may be performed by the employer if it is necessary for the management of the employment relationship, in compliance with the applicable legal framework, as defined by national and EU legislation, regulations, or collective bargaining agreements (Articles 6(1)(c) and 88 of the Regulation). Within this framework, the employer must comply with national rules that “include appropriate and specific measures to safeguard the human dignity […] of the data subjects, in particular with regard to the transparency of the processing […] and workplace monitoring systems” (Article 88(2) of the Regulation, to which Article 6(2) of the Regulation refers). As consistently reiterated in the Data Protection Authority’s rulings, processing resulting from the use of technological tools in locations where work is also carried out finds its legal basis in the sector-specific regulations set forth in Art. 4 of Law No. 300 of May 20, 1970 (Workers’ Statute), paragraph 1 of which provides that “audiovisual equipment and other devices that also enable remote monitoring of workers’ activities may be used exclusively for organizational and production needs, for workplace safety, and for the protection of company assets, and may be installed subject to a collective agreement entered into by the unified union representative body or by the company-level union representatives […]. In the absence of such an agreement, the systems and devices referred to in the first sentence may be installed only with the authorization of the regional office of the National Labor Inspectorate or, alternatively, […] the central office of the National Labor Inspectorate.” This provision uniformly defines, at the national level, the scope of permitted processing in every workplace (public and private) and constitutes, within the domestic legal system, a more specific provision offering greater safeguards than that set forth in Art. 88 of the Regulation, compliance with which - by virtue of the Code’s reference to pre-existing national sector-specific provisions protecting the dignity of individuals in the workplace, with particular reference to possible monitoring by the employer (Art 114 “Guarantees Regarding Remote Monitoring”) - is a condition for the lawfulness of the processing (see Art. 5, para. 1, subpar. a) and Art. 6, para. 1, subpar. c) of the Regulation); see, at the European level, the guidance contained in “Guidelines 3/2019 on the processing of personal data through video devices,” adopted by the European Data Protection Board on January 29, 2020, para. 11, as well as the previous guidance from the Art 29 Working Party in “Opinion 2/2017 on the processing of data in the workplace,” WP 249; see para. 4.1 of the “Provision on Video Surveillance” of April 8, 2010, web doc. no. 1712680, and, most recently, the Data Protection Authority’s FAQ No. 9 on video surveillance, dated December 2020, web doc. 9496574, and the numerous decisions of the Data Protection Authority regarding specific cases, including, with specific regard to the use of video surveillance in the workplace, theNo. 70 of February 12, 2026, web doc. No. 10226611; No. 43 of January 29, 2026, web doc. No. 10226639; October 23, 2025, No. 628, Web Doc. No. 10196164; July 10, 2025, No. 410, Web Doc. No. 10162731; April 10, 2025, No. 201, web doc. No. 10139433; April 11, 2024, No. 234, web doc. No. 10013356; November 16, 2023, No. 578, web doc. No. 9963486; March 11, 2021, No. 90, web doc. No. 9582791; March 5, 2020, No. 53, Web Doc. No. 9433080; see Order No. 167 of September 19, 2019, Web Doc. No. 9147290). This is in accordance with the case law of the European Court of Human Rights in the case of Antovic and Mirković v. Montenegro (Application No. 70838/13 of November 28, 2017), which held that the right to privacy must also extend to public workplaces, emphasizing that the use of video surveillance devices in the workplace can be justified only in accordance with the safeguards provided for by applicable national law; in the absence of such safeguards, it constitutes an unlawful interference with the employee’s private life, pursuant to Art. 8, para. 2, of the ECHR. In the case under investigation, on May 16, 2025, the Institute entered into an agreement with the labor unions, pursuant to Art. 4 of Law No. 300/1970, an agreement regarding the use of a “perimeter video surveillance system” (preamble) at its Turin headquarters to “ensure the protection of company assets” (Art. 1.1). This agreement specifies that “the CCTV cameras will be installed so as to film exclusively the perimeter walls and fences, subject to the necessary adjustments due to the presence of visual obstacles (e.g., vegetation and existing structures) […] in accordance with the detailed site plan provided to the union representatives for review” (Art. 2.1); “the system records the images captured by the CCTV system 24 hours a day, including Saturdays, Sundays, holidays, and days when the Institute is closed” (Art. 2.3). After entering into this agreement with the labor unions, however, the Institute installed the system in a manner that did not comply with the site plan agreed upon with the labor unions, increasing the number of cameras by eight and modifying their placement and respective coverage areas. Nevertheless, the same union agreement stipulated that “the perimeter video surveillance system may be subject to extraordinary maintenance, including non-substantial technological improvements or upgrades, without the need to amend this agreement, provided that […] the defined coverage areas are not altered” (Art. 2.5). The Institute put this system into operation in a manner inconsistent with the floor plan agreed upon with the labor unions, even on workdays (on October 31, 2025, and then from November 3 to 5, albeit for a few hours each day). Although the system was activated for testing purposes and without recording the images—merely displaying them in real time—it nonetheless involved the processing of personal data of employees on duty and other individuals present at the Turin office for various reasons, in a manner inconsistent with the procedures agreed upon with the labor unions and, therefore, in a manner that did not comply with the principle of “lawfulness, fairness, and transparency” and in the absence of a legal basis, in violation of Articles 5(1)(a), para. 1, Article 6, para 1, subparagraph c), and para 2 and 3, and Article 88, para 1, of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970). However, the grounds for the complaint regarding the placement of surveillance monitors in areas potentially accessible even to unauthorized persons cannot be upheld, given that, as stated by the Institute during the preliminary investigation—and with the Institute assuming accountability also pursuant to Article 168 of the Code— these monitors are located in the gatehouse, a room where only personnel assigned to the reception or security service work; and that, once the testing phase is complete and the system has begun regular operation, certain windows of the reception area will in any case be covered to prevent the monitors from being viewed by unauthorized persons. 3.2. Transparency of Processing. 3.2.1. With Respect to Employees. In accordance with the principle of “lawfulness, fairness, and transparency” (Article 5, para 1, subparagraph a) of the Regulation), the controller must take appropriate measures to provide the data subject with all the information referred to in Articles 13 and 14 of the Regulation in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (see Article 12, para 1, of the Regulation). In this regard, the Institute has stated that it did not provide its employees with a specific privacy notice regarding the video surveillance system in question pending “the definition, to be verified with the RSU, of the technical and operational aspects.” As explained above, the Institute nevertheless put the video surveillance system into operation on certain days when the offices were open—albeit in a manner differing from that agreed upon with the labor unions—without the employees being aware of this circumstance or of the essential characteristics of the resulting processing of their personal data. Instead, the Institute should have provided its employees with a specific privacy notice regarding the processing of personal data before putting the system into operation and, therefore, before carrying out any data processing through said system, as it is irrelevant that the system was activated solely for testing and technical verification purposes. It must therefore be concluded that the Institute acted in a manner inconsistent with the principle of “lawfulness, fairness, and transparency,” in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation. 3.2.2. With regard to other categories of data subjects. When video surveillance devices are used, the controller, in addition to providing “first-level information” by posting warning signs near the area under video surveillance, must also provide data subjects with “second-level information,” which must “contain all the mandatory elements required under Article 13 of the [Regulation]” and “be easily accessible to the data subject, for example through a comprehensive information page made available at a central hub […] or posted in an easily accessible location” (“Guidelines 3/2019 on the Processing of Personal Data through Video Devices,” op. cit., specifically para. 7; but see also the Data Protection Authority’s “Provision on Video Surveillance” of April 8, 2010, cited above, in particular para. 3.1; most recently, see the Data Protection Authority’s FAQ No. 4 on video surveillance, cited above). The first-level information (warning sign) “should convey the most important details, such as the processing purpose, the identity of the controller, and the existence of the data subject rights, along with information on the most significant impacts of the processing” (“Guidelines 3/2019 on the Processing of Personal Data via Video Devices,” op. cit., para. 114). Furthermore, the signage must also include information that might come as a surprise to the data subject. This could include, for example, the transfer of data to third parties—particularly those located outside the EU—and the data storage period. If such information is not provided, the data subject should be able to rely on the fact that only real-time Surveillance is taking place, without any data recording or transmission to third parties (ibid., op. cit., para. 115). The first-level warning signage must contain a clear reference to the second level of information, for example, by indicating a website where the text of the extended privacy notice can be consulted. In the case at hand, although the Institute activated the video surveillance system on October 31, 2025, and again from November 3 to 5 (for a few hours each day), it stated that it had posted “the signage [containing the first-level notice on data processing] [only] on November 17, 2025,” while no second-level notice was made available to the data subjects. It should also be noted that this sign, posted after the dates on which the video surveillance system was activated for testing purposes, does not comply with data protection regulations, given that it does not clearly indicate the details of the controller (it only reads the acronym “INRIM,” without any contact information); it refers to a generic and potentially misleading processing purpose (“security”) rather than the one actually pursued (protection of company assets); it does not mention the rights of data subjects, does not specify the data storage periods, and does not clarify that the so-called “QR Code” allows users to access a complete second-level privacy notice (see the sample information sign in para 115 of the “Guidelines 3/2019 on the Processing of Personal Data through Video Devices,” cited above). The Institute has, therefore, acted in a manner inconsistent with the principle of “lawfulness, fairness, and transparency” and in violation of Articles 5(1)(a), 12(1), and 13 of the Regulation. 3.3 The data protection impact assessment. When a type of processing may pose a high risk to the rights and freedoms of natural persons and, in any case, when the strictly defined circumstances apply, the controller must, before carrying out the processing, conduct a data protection impact assessment in order to adopt, in particular, appropriate measures to address such risks, after consulting the Data Protection Authority in advance, where the conditions for such consultation are met (see Articles 35 and 36(1) of the Regulation). Taking into account the guidance provided on this point at the European level as well, it is considered that, in the present case, the Institute should have conducted a data protection impact assessment before commencing the processing, given that such processing entailed specific risks to the rights and freedoms of employees. This is due both to the particular “vulnerability” of the data subjects in the workplace (see Recitals 75 and Art. 88 of the Regulation and the “Guidelines on the data protection impact assessment and the criteria for determining whether processing ‘may result in a high risk’ within the meaning of Regulation 2016/679,” WP 248 of April 4, 2017, which expressly mentions “employees” among the categories of vulnerable data subjects), as well as the fact that systems are used that involve “systematic monitoring” in the workplace, defined as “processing used to observe, monitor, or control data subjects, including data collected via networks” (see criterion No. 3 set forth in the Guidelines, cited above, but see also criteria 4 and 7; see Articles 35 and 88(2) of the Regulation; see also Provision No. 467 of October 11, 2018, web doc. No. 9058979, Annex No. 1, which expressly mentions “processing carried out in the context of the employment relationship using technological systems […] that enable remote monitoring of employees’ activities”). The failure to conduct a data protection impact assessment regarding video surveillance systems used in the workplace has, for these reasons, been the subject of recent corrective and sanctioning measures by the Data Protection Authority (see, in particular, decisionsNo. 70 of February 12, 2026, web doc. No. 10226611; No. 43 of January 29, 2026, web doc. No. 10226639; October 23, 2025, No. 628, cit.; July 10, 2025, No. 410, web doc. No. 10162731; April 10, 2025, web doc. no. 10139433; March 13, 2025, No. 135, web doc. No. 10128005; November 16, 2023, No. 578, web doc. No. 9963486). In light of all the foregoing considerations, it must be concluded that the Institute processed employees’ personal data through the video surveillance system in question without conducting a prior data protection impact assessment and, therefore, in violation of Article 35 of the Regulation. 4. Conclusions. In light of the assessments referred to above, it is noted that the statements made by the controller during the preliminary investigation—for the veracity of which the controller may be held accountable pursuant to Art. 168 of the Code—while worthy of consideration, do not suffice to rebut the findings notified by the Office in the notice initiating the proceedings and are insufficient to warrant the dismissal of this proceeding, as none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. The Office’s preliminary assessments are therefore upheld, and the processing of personal data by the Institute is found to be unlawful, as it carried out the processing of personal data via video surveillance cameras in violation of Articles 5(1)(a), 6(1)(c) and (2) and (3), 12(1), 13, 35, and 88(para 1) of the Regulation, as well as Articles 2-ter and 114 of the Code (with reference to Article 4 of Law No. 300/1970). Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing operation or related processing operations), Art 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Recital 1: Given that, in the present case, the most serious violations—relating to Articles 5, para 1, subparagraph (a); 6, para 1, subparagraph (c) and paragraphs 2 and 3; 12, para 1, 13, and 88(1) of the Regulation, as well as Article 2-ter of the Code, are subject to the penalty provided for in Article 83(5) of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, The total amount of the penalty is to be set at up to 20,000,000 euros. In this context, considering, in any case, that the conduct has ceased to have any effect—given that, as stated by the Institute, the video surveillance cameras in question were activated during office hours for only four business days, the conditions for adopting further corrective measures under Article 58(2) of the Regulation do not apply. 5. Adoption of the injunction ordering the imposition of the administrative fine and ancillary penalties (Articles 58(2)(i) and 83 of the Regulation; Article 166(7) of the Code). The Data Protection Authority, pursuant to Articles 58(2)(i) and 83 of the Regulation, as well as Article 166 of the Code, has the power to “impose an administrative fine pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in lieu of such measures, depending on the circumstances of each individual case” and, in this context, “the Board [of the Data Protection Authority] issues an injunction, by which it also orders the application of the ancillary administrative sanction of its publication, in full or in part, on the Data Protection Authority’s website pursuant to Article 166, paragraph 7, of the Code” (Art. 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019). In this regard, taking into account Article 83(3) of the Regulation, in the present case, the violation of the aforementioned provisions is subject to the imposition of the administrative fine provided for in Article 83(5) of the Regulation. The amount of the aforementioned administrative fine, depending on the circumstances of each individual case, must be determined by taking due account of the factors set forth in Article 83(2) of the Regulation. Taking into account that: - although the processing was not fully in compliance with the provisions of the union agreement, it was carried out for testing purposes and lasted only a few hours over the course of just four workdays (see Art. 83(2)(a) of the Regulation); - the violation was committed through negligence (see Article 83(2)(b) of the Regulation); - the processing did not involve special categories of personal data referred to in Article 9 of the Regulation (see Article 83(2)(g) of the Regulation), it is considered that, in the present case, the severity of the violation committed by the controller is low (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60). That said, considering that the controller is a public research institution of national significance but operating on a local basis and without providing services directly to the public, it is considered that, for the purposes of determining the amount of the fine, the following circumstances should be taken into account: - the Institute cooperated fully with the Authority during the investigation (see Art. 83, para. 2, subpar. f) of the Regulation); - there are no relevant prior violations committed by the Institute (see Art. 83(2)(e) of the Regulation). In light of the above factors, assessed as a whole, the Authority has determined that the monetary penalty shall amount to 10,000 (ten thousand) euros for the violation of Articles 5(1)(a), para 1, 6, para 1, subparagraph c), and para 2 and 3, 12, para 1, 13, 35, and 88(1) of the Regulation, as well as Articles 2-ter and 114 of the Code, as an administrative fine deemed, pursuant to Article 83(1) of the Regulation, to be effective, proportionate, and dissuasive. It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, this section containing the injunction order must be published on the Data Protection Authority’s website. This is in light of the fact that the processing concerns the personal data of employees, who are vulnerable individuals in the workplace and, moreover, were not informed about the nature of the processing. Finally, it is noted that the conditions set forth in Art. 17 of Regulation No. 1/2019 are met. GIVEN THE FOREGOING, THE DATA PROTECTION AUTHORITY declares, pursuant to Article 57(1)(f) of the Regulation, that the processing carried out by the Institute is unlawful due to a violation of Articles 5(1)(a), Article 6(1)(c) and (2) and (3), Article 12(1), Article 13, Article 35, and Article 88(1) of the Regulation, as well as Articles 2-ter and 114 of the Code, as set forth in the reasoning; ORDERS the National Institute of Metrological Research (INRIM), in the person of its pro tempore legal representative, with registered office at Strada Delle Cacce, 91 - 10135 Turin (TO), Tax ID No. 09261710017, to pay the sum of 10,000 (ten thousand) euros as an administrative fine for the violations indicated in the reasoning. It is noted that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half of the imposed penalty; ORDERS the aforementioned Institution, in the event that the dispute is not settled pursuant to Article 166, paragraph 8, of the Code, to pay the sum of 10,000 (ten thousand) in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the relevant enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981; ORDERS - pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of this injunction order on the Data Protection Authority’s website; - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, the publication of this order on the Authority’s website; - Pursuant to Article 17 of the Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58, para 2 of the Regulation, in the Authority’s internal register provided for by Article 57, para 1, letter u) of the Regulation. Pursuant to Articles 78 of the General Data Protection Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary courts, on pain of inadmissibility, within thirty days from the date of notification of the decision or within sixty days if the appellant resides abroad. Rome, September 3, 2026 THE CHAIRMAN Stanzione THE RAPPORTEUR Ghiglia THE SECRETARY GENERAL Montuori

---
Generated by overview.legal · https://overview.legal/posts/449709 · 2026-10-02
