Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Vimar S.p.A.: Insufficient legal basis for data processing
How it connects
Related across sources
Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin Guidance Guidelines 07/2022 on certification as a tool for transfers News De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). News What Happened to the Risk-Based Approach to Data Transfers? News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
Full text
The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without their knowledge. Multiple people within the controller's company used this account for three years.
Industry: Industry and Commerce
Original document at the source www.garanteprivacy.it