Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Autostrade per l'Italia spa: Non-compliance with general data processing principles

The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx.

€1,000,000 Fine
Autostrade per l'Italia spa
ITALY
Art. 5 GDPR Art. 13 GDPR Art. 28 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx. 100,000 registered users of the toll reimbursement app 'Free to X.' A consumer organization reported problems with the service, which provides toll refunds for delays caused by roadworks, to the DPA. The DPA found that Autostrade held the position of the data controller, instead of a processor, as stated in the documents governing the relationship between 'ASPI' and 'Free to X', the company that develops and operates the app, as well as in the information notice given to users. In fact, 'ASPI', as the operator of the highway network, was responsible for determining the reimbursement mechanism, the type of compensation measures, the processing and the causes of delays due to road works. 'Free to X' was only tasked with implementing the service. This incorrect assignment of privacy roles resulted in the notice to users being incorrect.

§

The notice should have included the actual identity of the controller, namely ASPI, as well as all the necessary information for proper and transparent processing in accordance with data protection laws. The DPA finally found that ASPI also violated the GDPR by not designating Free to X as a processor. GDPR Articles: Art. 5 (1) a) GDPR, Art. 13 GDPR, Art. 28 GDPR Industry: Transportation and Energy

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
C-757/22 Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the… CJEU ·Fourth Chamber Jul 11, 2024 Personal Data Transparency Fairness & Transparency
C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… CJEU ·First Chamber Jun 22, 2023 Right of Access Personal Data Right to Restriction