Skip to content
Content type · 699 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Italy (50) Clear filter
501–550 of 699 sort newestlargest fineoldest
€1,000 Colosseo S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Colosseo S.r.l.. An individual had filed a complaint with the DPA because the controller had sent him an unsolicited commercial… ITALY ·Garante ·Art. 5, 6, 12 +4 Right to Object Personal Data Direct Marketing Aug 5, 2022
€1,000 Mister Brick S.a.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on Mister Brick S.a.s.. An individual had filed a complaint with the DPA against the controller for having received unsolicited… ITALY ·Garante ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Aug 5, 2022
€20,000 Cosmopol Security S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Cosmopol Security S.p.A. EUR 20,000. An individual had filed a complaint with the DPA against the controller. The individual had received invoices… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 5, 2022
€26,000 Policoro municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 26,000 on Policoro municipality. The municipality had installed a video surveillance system without, however, providing sufficient… ITALY ·Garante ·Art. 5, 12, 13 +2 Storage Limitation Retention Period Supervisory Authorities Aug 1, 2022
€2,000 Auto Hi-Fi System S.n.c: Non-compliance with general data processing principles The Italian DPA has fined Auto Hi-Fi System S.n.c in the amount of EUR 2,000. The controller had installed a video surveillance system that covered not only the public road but… ITALY ·Garante ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jul 28, 2022
€3,000 Azienda Socio Sanitaria Territoriale Rhodense: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Azienda Socio Sanitaria Territoriale Rhodense EUR 3,000. The healthcare facility had reported the loss of a patient's medical record. The file contained… ITALY ·Garante ·Art. 5, 32 Security Personal Data Privacy by Design & Default Jul 21, 2022
€2,000 Global Service s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Global Service s.r.l. EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the data subjects… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Jul 21, 2022
€10,000 Stay over s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Stay Over s.r.l. EUR 10,000. A former employee had filed a complaint with the DPA. The company had failed to respond to a request for access to personal… ITALY ·Garante ·Art. 5, 12, 13 +2 Right of Access Personal Data Supervisory Authorities Jul 21, 2022
€10,000 Clio S.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on Clio S.r.l.. Clio provides and manages a whistleblowing reporting application for various private and public entities. As part… ITALY ·Garante ·Art. 2, 5, 6 +1 Processors Controllers Supervisory Authorities Jul 21, 2022
€5,000 Ginosa municipality: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Ginosa municipality. The fine is related to the fine against Clio S.r.l.. Clio provides and manages a whistleblowing reporting… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Supervisory Authorities Public Authority Jul 21, 2022
€20,000 Acqua Novara.VCO S.p.a.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 20,000 on Acqua Novara.VCO S.p.a.. The fine is related to the fine against Clio S.r.l.. Clio provides and manages a whistleblowing… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Supervisory Authorities Processing Jul 21, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY ·Garante ·Art. 5, 6, 7 +4 Data Breaches Personal Data Fairness & Transparency Jul 7, 2022
€20,000 Intesa Sanpaolo Vita S.p.a.: Non-compliance with general data processing principles The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the… ITALY ·Garante ·Art. 5 Personal Data Controllers Processing Jul 7, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Legitimate Interest Direct Marketing Marketing Jul 7, 2022
€5,000 Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Federazione Italiana Sommelier, Albergatori e Ristoratori. The federation had sent a protocol containing personal data of a… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Cloud Computing Jun 30, 2022
€20,000 Deutsche Bank S.p.A.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jun 16, 2022
€70,000 Unicredit S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Unicredit S.p.A. EUR 70,000. An employee had filed a complaint with the DPA claiming that their right to access their personal data had not been… ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Jun 16, 2022
€2,000 Federazione Italiana Nuoto: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Federazione Italiana Nuoto EUR 2,000 for failing to respond to the data subject's request for access to their data in a timely manner. ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Jun 16, 2022
€26,000 Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Italy ·Garante ·Art. 5, 12, 13 +3 Public Authority Supervisory Authorities Storage Limitation Jun 9, 2022
€10,000 Cribis Credit Management s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Cribis Credit Management s.r.l. EUR 10,000. The company had inadvertently sent an e-mail about late payments on a subscription to the head of the data… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Insurance Jun 9, 2022
€16,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Region of Tuscany. The region had published documents on its website containing information on professionals from the… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education May 26, 2022
€50,000 Azienda sanitaria universitaria Friuli Occidentale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 50,000 on the healthcare facility Azienda sanitaria universitaria Friuli Occidentale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Personal Data Types of Special Categories of Personal Data May 26, 2022
€70,000 Azienda sanitaria universitaria Friuli Centrale: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 70,000 on the healthcare facility Azienda sanitaria universitaria Friuli Centrale. Employees of the healthcare facility had accessed… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Personal Data Types of Special Categories of Personal Data May 26, 2022
€46,000 Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing The Italian DPA has fined Azienda Sanitaria Locale Roma EUR 46,000. The healthcare facility had published the names and health information of 1337 patients on its website. In most… ITALY ·Garante ·Art. 2, 5, 6 +1 Retention Period Healthcare Personal Data May 26, 2022
€100,000 Intesa Sanpaolo S.p.A: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on Intesa Sanpaolo S.p.A.. The bank had unlawfully disclosed data of the data subject to unauthorized third parties (the father… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Insurance May 26, 2022
€2,000 Turkish City: Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Turkish City' EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 13 Controllers Personal Data Supervisory Authorities May 26, 2022
€10,000 Afragola municipality: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Afragola municipality. A former employee of the municipality had filed a complaint with the DPA because the municipality had… ITALY ·Garante ·Art. 2, 5, 12 Personal Data Supervisory Authorities Processing May 26, 2022
€4,000 Università Agraria di Nettuno: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the Università Agraria di Nettuno. A former employee of the university had filed a complaint with the DPA due to the fact that… ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Education May 26, 2022
€2,000 Store owner: Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Turkish City' EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities May 26, 2022
€12,000 Comune di Napoli Corpo di Polizia Municipale: Insufficient legal basis for data processing The Italian DPA has fined the police authority 'Comune di Napoli Corpo di Polizia Municipale' EUR 12,000. The police authority had sent a list of names, addresses, tax numbers,… ITALY ·Garante ·Art. 5, 6, 88 +1 Consent Processing Education May 22, 2022
€3,000 Zito Auto di Gianfranco Zito: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 3,000 on the company Zito Auto di Gianfranco Zito. The company had installed video surveillance cameras which monitored, among other… ITALY ·Garante ·Art. 5, 114 Retention Period Processing Video Surveillance May 22, 2022
€7,000 Azienda Socio Sanitaria Territoriale Dei Sette Laghi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 7,000 on the healthcare facility Azienda Socio Sanitaria Territoriale Dei Sette Laghi. A patient had mistakenly received… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Security Health Data May 22, 2022
€2,000 Singh Market: Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Singh Market' EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities May 12, 2022
€20,000 Bazar di Hu Xiaoyan: Insufficient fulfilment of information obligations The Italian DPA has imposed a fine of EUR 20,000 on the company 'Bazar di Hu Xiaoyan'. The controller had operated video surveillance cameras in its premises without a required… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Supervisory Authorities May 12, 2022
€6,000 Villabate municipality: Non-compliance with general data processing principles The Italian DPA has fined Villabate municipality EUR 6,000. The municipality had disclosed personal data of a former employee to unauthorized third parties without a valid legal… ITALY ·Garante ·Art. 5, 6, 37 +1 Public Authority Personal Data Supervisory Authorities May 12, 2022
€200,000 Amiu S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Amiu S.p.A.. The company operates the waste collection service for the city of Taranto and acted as a processor for this… ITALY ·Garante ·Art. 5, 6, 28 +1 Processors Monitoring Controllers Apr 28, 2022
€2,000 Ekss s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined the restaurant operator Ekss s.r.l. EUR 2,000. The controller had installed video surveillance cameras in its premises without properly informing the… ITALY ·Garante ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Apr 28, 2022
€1,500 Direzione Didattica Statale 1° Circolo-Eboli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,500 on the school 'Direzione Didattica Statale 1° Circolo-Eboli'. The educational institution had sent a document containing the names… ITALY ·Garante ·Art. 2, 5, 6 +1 Types of Special Categories of Personal Data Healthcare Processing Apr 28, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data Healthcare Processing Apr 28, 2022
€50,000 Istituto Nazionale Assicurazione Infortuni sul Lavoro: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Istituto Nazionale Assicurazione Infortuni sul Lavoro (Public Accident Insurance for workers) EUR 50,000. As part of its investigation, the DPA found… ITALY ·Garante ·Art. 2, 5, 6 +2 Security Personal Data Data Breaches Apr 28, 2022
€2,500 'Isabella Gonzaga' high school: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the 'Isabella Gonzaga' high school. The school had published a document, which also contained personal health data of some… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Processing Apr 28, 2022
€2,000 Comune di Partanna: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Garante ·Art. 2, 5, 6 Personal Data Processing Public Authority Apr 28, 2022
€1,000 Educationest s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Educationest s.r.l. EUR 1,000. The daycare center had sent an email to the families of the children in its care, informing them of the pregnancy and the… ITALY ·Garante ·Art. 5, 6 Consent Processing Education Apr 28, 2022
€3,000 Comune di Monte Sant'Angelo: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Monte Sant'Angelo. A person who had participated in a selection procedure had filed a complaint with the DPA due to… ITALY ·Garante ·Art. 2, 5, 6 +1 Personal Data Controllers Processing Apr 28, 2022
€40,000 Il Sole 24 Ore S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined the newspaper Il Sole 24 Ore S.p.a. EUR 40,000. The newspaper had published an article on the recognition by the Italian authorities of a U.S. judge's… ITALY ·Garante ·Art. 5, 9, 12 Personal Data Supervisory Authorities Processing Apr 28, 2022
€20,000 Nos s.r.l.s.: Insufficient legal basis for data processing The Italian DPA fined Nos s.r.l.s. in the amount EUR 20,000. Nos acted as a processor for Vodafone and did advertising for the telecommunications company. For this purpose, Nos… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Controllers Consent Apr 28, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Data Breaches Security Apr 28, 2022
€150,000 Tarento municipality: Insufficient fulfilment of information obligations The Italian DPA has imposed a fine of EUR 150,000 on Tarento municipality. The company Amiu S.p.A had operated the local waste collection service on behalf of the municipality.… ITALY ·Garante ·Art. 5, 12, 13 +3 Monitoring DPIA Supervisory Authorities Apr 28, 2022
€1,000 ASST di Lodi: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 1,000 on ASST di Lodi. The healthcare facility had reported a data breach to the DPA pursuant to Art. 33 GDPR. A patient had… ITALY ·Garante ·Art. 5, 9, 32 Data Breaches Personal Data Security Apr 26, 2022
€40,000 ISWEB S.p.A.: Insufficient data processing agreement The Italian DPA imposed a fine of EUR 40,000 on ISWEB S.p.A.. The fine is related to a fine against the healthcare facility Azienda ospedaliera di Perugia. ISWEB had provided the… ITALY ·Garante ·Art. 28 Processors Supervisory Authorities Processing Apr 7, 2022