Skip to content
Content type · 699 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Italy (50) Clear filter
551–600 of 699 sort newestlargest fineoldest
€10,000 Findomestic Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on Findomestic Banca spa. A customer had filed a complaint with the DPA regarding a breach of confidentiality related to the… ITALY ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Apr 7, 2022
€50,000 Palumbo Superyacht Ancona s.r.l.: Insufficient legal basis for data processing The Italian DPA has fined Palumbo Superyacht Ancona s.r.l. EUR 50,000. The company had blocked an employee's company email account without permission. The employee had reported… ITALY ·Art. 5, 12, 13 +3 Storage Limitation Supervisory Authorities Processing Apr 7, 2022
€10,000 E-Mac Professional s.r.l.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Art. 12, 15 Personal Data Supervisory Authorities Apr 7, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Art. 5, 13, 29 +2 Integrity and Confidentiality Principle Personal Data Controllers Apr 7, 2022
€20,000 Made in Italy s.r.l.s.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 20,000 on Made in Italy s.r.l.s.. A data subject had filed a complaint with the DPA after receiving promotional calls from the… Art. 6, 7, 15 +5 ·Insufficient legal basis for data processing Direct Marketing Controllers Personal Data Apr 7, 2022
€40,000 Azienda ospedaliera di Perugia: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Azienda ospedaliera di Perugia EUR 40,000. During an investigation at the healthcare facility, the DPA found multiple GDPR violations. The… ITALY ·Art. 5, 13, 14 +4 DPIA Personal Data Processing Apr 7, 2022
€15,000 Rebirth s.r.l.: Insufficient fulfilment of information obligations The Italian DPA has fined Rebirth s.r.l. EUR 15,000. The controller had installed 14 surveillance cameras in a café it operated without, however, informing about the video… ITALY ·Art. 5, 13, 114 +1 Controllers Supervisory Authorities Video Surveillance Apr 7, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Security Mar 24, 2022
€10,000 Azienda USL Toscana Centro: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has imposed a fine of EUR 10,000 on Azienda USL Toscana Centro. The DPA initiated an investigation against the controller after it reported a data breach… ITALY ·Art. 5, 9, 32 Data Breaches Security Healthcare Mar 10, 2022
€8,000 Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo: Insufficient legal basis for data processing The Italian DPA (Garante) has fined the Agenzia Regionale per la Tutela dell'Ambiente dell'Abruzzo EUR 8,000. A former employee of the environmental agency had filed a complaint… ITALY ·Art. 2, 5, 6 +1 Personal Data Processing Employees Mar 10, 2022
€10,000 Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 10,000 on Alfa Shipyard s.r.l.. The controller had failed to implement measures ordered by the DPA in due time. ITALY ·Art. 58 Supervision Supervisory Authorities Controllers Mar 10, 2022
€6,000 Azienda sanitaria provinciale di Caltanissetta: Insufficient legal basis for data processing The Italian DPA has fined Azienda sanitaria provinciale di Caltanissetta EUR 6,000. The data subject had asked the controller, in the context of legal proceedings, to send any… ITALY ·Art. 2, 5, 6 +3 Personal Data Controllers Supervisory Authorities Mar 10, 2022
€10,000 Costampress S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and did not provide sufficient information about this. ITALY ·Art. 5, 12, 13 Personal Data Processing Supervisory Authorities Feb 10, 2022
€1,500 Studio Colli Aniene Verderocca S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,500 on Studio Colli Aniene Verderocca S.r.l.. A data subject had filed a complaint with the DPA for unsolicited telephone advertising.… ITALY ·Art. 12, 14, 15 +2 Personal Data Direct Marketing Supervisory Authorities Feb 10, 2022
€5,000 Arte del vivere S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 5,000 on Arte del vivere S.r.l.. A data subject filed a complaint with the DPA as his personal data had been published on the website… ITALY ·Art. 12, 17, 157 Personal Data Controllers Supervisory Authorities Feb 10, 2022
€10,000 Region of Tuscany: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had… ITALY ·Art. 2, 5, 6 Data Breaches Personal Data Supervisory Authorities Feb 10, 2022
€10,000 Scanshare S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Scanshare S.r.l.. That fine is related to a fine imposed on the Region of Tuscany. The region stated that it had inadvertently… ITALY ·Art. 28, 32 Personal Data Security Supervisory Authorities Feb 10, 2022
€2,000 Comune di Guidizzolo: Insufficient legal basis for data processing The community published information about a court case on its website, including personal data such as the name and professional information of a data subject. ITALY ·Art. 2, 5, 6 Personal Data Processing Education Feb 10, 2022
€3,500 Azienda socio sanitaria territoriale Melegnano e della Martesana: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 3,500 on Azienda socio sanitaria territoriale Melegnano e della Martesana. The DPA initiated an investigation against the… ITALY ·Art. 5, 9 Healthcare Controllers Processing Feb 10, 2022
€2,000 Private club 'Ruian': Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 2,000 on the private club 'Ruian'. The controller had installed video surveillance cameras which, among other things, also… ITALY ·Art. 5, 13 Retention Period Controllers Supervisory Authorities Jan 27, 2022
€40,000 T.S.M. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on T.S.M. s.r.l.. A data subject had filed a complaint with the DPA against the company for failing to comply with their requests… ITALY ·Art. 13, 15, 21 +2 Personal Data Supervisory Authorities Processing Jan 27, 2022
€14,000 Azienda sanitaria unica regionale Marche: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 14,000 on Azienda sanitaria unica regionale Marche. The DPA launched an investigation against the health department following media… ITALY ·Art. 5, 32, 35 Security Personal Data Supervisory Authorities Jan 13, 2022
€1,000 A.S.L. Napoli 1 Centro: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 1,000 on A.S.L. Napoli 1 Centro. An employee at the health authority had filed a complaint with the DPA against the… ITALY ·Art. 2, 5, 6 Personal Data Processing IP Address Jan 13, 2022
€1,000 Villa Masi Residenza per anziani: Insufficient fulfilment of information obligations Inexistence of signalization regarding the use of CCTV systems in a nursing care facility. ITALY ·Art. 13 Supervisory Authorities Healthcare Video Surveillance Jan 13, 2022
€4,000 Medicina & Lavoro s.r.l.: Insufficient fulfilment of data subjects rights Failure to respond to the data subject's request for access to their data in a timely manner. ITALY ·Art. 12, 15 Personal Data Supervisory Authorities Healthcare Jan 13, 2022
€7,500 Azienda Sanitaria Locale Frosinone: Insufficient fulfilment of information obligations The Italian DPA has fined Azienda Sanitaria Locale Frosinone EUR 7,500. In the course of its investigation against the medical facility, the Garante found that their privacy… ITALY ·Art. 5, 12, 13 Supervisory Authorities Processing Processing Agreement Jan 13, 2022
€10,000 ASL Latina: Insufficient legal basis for data processing The Italian DPA (Garante) fined ASL Latina EUR 10,000. The controller had mistakenly sent documents containing health data of the data subject to an uninvolved third party. ITALY ·Art. 5, 6, 9 Healthcare Personal Data Controllers Dec 17, 2021
€10,000 Centro di Medicina preventiva s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Centro di Medicina preventiva s.r.l. EUR 10,000. The controller reported a database under Art. 33 GDPR in connection with a cyberattack by a… ITALY ·Art. 5, 25, 32 +1 Privacy by Design & Default Security Controllers Dec 16, 2021
€20,000 Corradi s.r.l.: Non-compliance with general data processing principles The company had left the e-mail account of the data subject active even after the termination of his employment and had automatically forwarded incoming e-mails. The company did… ITALY ·Art. 5, 13, 157 Personal Data Processing Supervisory Authorities Dec 16, 2021
Enel Energia S.p.A: Insufficient legal basis for data processing Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched… ITALY ·Art. 5, 6, 12 +7 Direct Marketing Personal Data Controllers Dec 16, 2021
€20,000 FCA Italy s.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined FCA Italy s.p.a. EUR 20,000. A former customer of the controller had asked the controller to provide him with the transcripts of telephone conversations… Art. 12 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Dec 16, 2021
€1,000 Università Telematica Internazionale Uninettuno: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Università Telematica Internazionale Uninettuno. A professor had filed a complaint with the DPA against the educational… ITALY ·Art. 5 Retention Period Personal Data Processing Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2021
€7,000 Società Med Store Saronno s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Società Med Store Saronno s.r.l. EUR 7,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR. The facility had… ITALY ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Art. 5, 32 Security Personal Data Privacy by Design & Default Dec 2, 2021
€30,000 Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. EUR 30,000. The nursing home notified the DPA of a data breach pursuant to Art. 33 GDPR.… ITALY ·Art. 5, 32 Data Breaches Security Right of Access Dec 2, 2021
€5,000 Azienda USL di Parma: Non-compliance with general data processing principles The Italian DPA (Garante) fined Azienda USL di Parma EUR 5,000. A patient filed a complaint with the DPA because she had mistakenly received two reports of diagnostic tests on two… ITALY ·Art. 5, 9 Healthcare Processing Supervisory Authorities Dec 2, 2021
€200,000 Aimon Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Aimon Srl. Two data subjects had complained about unsolicited SMS advertising from B&T S.p.A. to the DPA. In the course of the… ITALY ·Art. 5, 6, 12 +1 Direct Marketing Personal Data Supervisory Authorities Nov 25, 2021
€400,000 B&T S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 400,000 on B&T S.p.A. Two data subjects had complained to the DPA about unsolicited SMS advertising. In addition, they stated that it was… ITALY ·Art. 5, 6, 12 +3 Right to Object Direct Marketing Personal Data Nov 25, 2021
€6,000 Società H San Raffaele Resnati s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. The DPA initiated an investigation against the health care provider after it… ITALY ·Art. 5, 9 Healthcare Processing Data Breaches Nov 25, 2021
€150,000 TIM S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has fined mobile operator TIM S.p.A. EUR 150,000 for denying a data subject access to his phone data needed to defend himself in a criminal case. Since… ITALY ·Art. 15 Right of Access Personal Data Supervisory Authorities Nov 11, 2021
€2,000 OTTO s.r.l.: Insufficient fulfilment of information obligations The Italian DPA (Garante) has imposed a fine of EUR 2,000 on OTTO s.r.l.. During an administrative inspection of a store managed by OTTO, the police found that a video… ITALY ·Art. 13 Controllers Supervisory Authorities Video Surveillance Oct 28, 2021
€2,000 Anfiteatro Flavio s.r.l.: Insufficient fulfilment of information obligations The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Anfiteatro Flavio s.r.l.. During an administrative inspection of a hotel managed by Anfiteatro Flavio, the police… ITALY ·Art. 13 Controllers Supervisory Authorities Video Surveillance Oct 28, 2021
€8,000 Health Protection Agency of Sardinia (ATS): Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 8,000 on the Health Protection Agency of Sardinia (ATS). A patient had mistakenly received medical records and clinical… ITALY ·Art. 5, 9 Healthcare Processing Health Data Oct 14, 2021
€11,000 Territorial Administration of the Government of Genoa: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 11,000 on the Territorial Administration of the Government of Genoa. The department had published a file on its website that contained a… ITALY ·Art. 2, 5, 6 Processing Public Authority Supervisory Authorities Sep 29, 2021
€2,000 Physician: Insufficient legal basis for data processing The Italian DPA (Garante) has fined a physician EUR 2,000. A patient had complained to the DPA that the doctor had disclosed his personal data to third parties without… ITALY ·Art. 5, 9 Personal Data Consent Healthcare Sep 29, 2021
€2,000 Istituto Comprensivo - IC Cosenza III “V. Negroni”: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo - IC Cosenza III “V. Negroni”. The educational institution had published a document, which also contained… ITALY ·Art. 2, 5, 6 +1 Healthcare Types of Special Categories of Personal Data Processing Sep 21, 2021
€5,000 Ciechi Ardizzone Gioeni di Catania: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the Ciechi Ardizzone Gioeni di Catania residential home for blind people. A visitor to the residence filed a complaint… ITALY ·Art. 5, 12, 13 +1 Integrity and Confidentiality Principle Retention Period Fairness & Transparency Sep 16, 2021
€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Art. 2, 5, 6 +6 Storage Limitation Retention Period Privacy Shield Sep 16, 2021
€5,000 La Prima S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) has imposed a fine of EUR 5,000 on the real estate portal La Prima S.r.l.. A data subject had filed a complaint against the controller with the DPA. She… ITALY ·Art. 5, 6, 24 +1 Personal Data Controllers Consent Sep 16, 2021