# Comune di Ustica: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Italian Data Protection Authority (Garante)
- Date: 2024-06-06
- Original: https://www.enforcementtracker.com/ETid-2394
- Canonical: https://overview.legal/posts/48509
- Topics: Health Data, Healthcare, IP Address, Personal Data, Public Authority, Education, Processing Agreement, Public Sector, Processing, Special Categories of Data

## Summary

The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private individuals. In the course of its investigation, the DPA found that the municipality had published the data without a valid legal basis and therefore had acted unlawfully.

## Full text

The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private individuals. In the course of its investigation, the DPA found that the municipality had published the data without a valid legal basis and therefore had acted unlawfully.

GDPR Articles: Art. 5 (1) a), c) GDPR, Art. 6 (1) c), e) GDPR, Art. 6 (2) GDPR, Art. 6 (3) b) GDPR, Art. 9 (1), (2), (4) GDPR, Art. 37 (7) GDPR, Art. 2-ter (1), (3) Codice della privacy, Art. 2-septies (8) Codice della privacy
Industry: Public Sector and Education

---
Generated by overview.legal · https://overview.legal/posts/48509 · 2026-08-22
