Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Ica s.r.l.: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement News De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Case Law GC and Others v CNIL Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin News What Happened to the Risk-Based Approach to Data Transfers? News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures
Full text
The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for traffic violations. However, due to a lack of security precautions, it was theoretically possible for unauthorized persons to access personal data stored via the program. For this reason, the DPA found that ICA had failed to implement appropriate technical and organizational measures providing a level of security commensurate with the risk posed to the data subject.
Industry: Industry and Commerce
Original document at the source www.garanteprivacy.it