Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Municipality of Bologna: Insufficient technical and organisational measures to ensure information security
The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna.
Full text
The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process data, including health data, of childreen with disabilities and special needs. The controller failed to ensure, that the processor had sufficient technical and organisational measures to ensure data security, resulting in a data leak.
Industry: Public Sector and Education
How it connects
Related across sources
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin C-807/21 (Deutsche Wohnen) Dec 5, 2023 Fines Public Authority Processors
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
C-623/17 Privacy International v Secretary of State C-623/17 (Privacy International) Oct 6, 2020 IP Address Material scope (GDPR) Legitimate Interest
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) Oct 6, 2015 Privacy Shield Supervision IP Address
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data