Skip to content
Content type · 699 documents in this view · 3,831 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Italy (49) Clear filter
651–699 of 699 sort newestlargest fineoldest
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Personal Data Jan 14, 2021
€2,000 Poliambulatorio Talenti S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) fined Poliambulatorio Talenti S.r.l. EUR 2,000 for failing to respond to the data subject's request for access to his and his daughters' data in a timely… ITALY ·Art. 12, 15 Personal Data Supervisory Authorities Healthcare Jan 14, 2021
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Art. 5, 6, 9 +1 Storage Limitation Retention Period Controllers Dec 17, 2020
€2,000 Ordine degli Assistenti Sociali della Regione Lazio: Insufficient fulfilment of data subjects rights The Italian DPA (Garante) has imposed a fine of EUR 2,000 on Ordine degli Assistenti Sociali della Regione Lazio. On November 27, 2019, a data subject had sent an email to the… ITALY ·Art. 12 Personal Data Controllers Supervisory Authorities Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle Personal Data Controllers Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Art. 5, 13, 14 +4 DPIA Controllers Processing Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Art. 5, 6 Personal Data Controllers Processing Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Art. 5, 6, 37 Public Authority Personal Data Controllers Dec 17, 2020
€3,000 Charly Mike s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 3,000 on Charly Mike s.r.l.. The controller is the hotel operator of the Hotel Olimpo in Alberobello. Garante received a complaint… ITALY ·Art. 5, 13 Controllers Supervisory Authorities Processing Nov 26, 2020
€10,000 Reti Televisive Italiane S.p.a.: Non-compliance with general data processing principles The television station broadcasted a documentary about the link between emissions from a local ceramics plant and health problems in the population, in which the person… ITALY ·Art. 5 Processing Telecommunications Healthcare Nov 26, 2020
€20,000 Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing The union UILCOM Sardegna filed a complaint with the Italian DPA (garante) against the call center operator Concentrix Cvg Italy s.r.l. regarding an internal regulation of the… Art. 5, 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Healthcare Nov 26, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Art. 5, 13 Personal Data Supervisory Authorities Processing Nov 23, 2020
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Art. 9 Personal Data Healthcare Processing Nov 17, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Art. 12, 13, 14 Personal Data Supervisory Authorities Public Authority Nov 17, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Art. 5, 6, 7 +7 Direct Marketing Accountability Personal Data Nov 12, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY ·Art. 5, 12, 13 Personal Data Controllers Processing Oct 29, 2020
€4,000 Borgo Fonte Scura s.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 4,000 on Borgo Fonte Scura s.r.l.. The controller had installed a video surveillance system which also recorded the three data… ITALY ·Art. 5, 13 Controllers Personal Data Processing Oct 29, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY ·Art. 5, 9 Notification Obligation Data Breaches Healthcare Oct 26, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Art. 5, 6, 13 +2 Processors Controllers Personal Data Sep 30, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Art. 5, 6, 9 +1 Controllers Processors Personal Data Sep 30, 2020
€2,000 Istituto Comprensivo Statale Crucoli Torretta: Insufficient technical and organisational measures to ensure information security Publication of personal data of students on the website of the Institute with, inter alia, notes about health and progress in school due to technical failure. ITALY ·Art. 5, 32 Personal Data Security Education Sep 7, 2020
€2,000 Comune di Casaloldo: Insufficient legal basis for data processing Publication of personal data on the website of the community. ITALY ·Art. 5, 6 Personal Data Processing Public Authority Sep 3, 2020
€10,000 Cavauto S.R.L.: Insufficient legal basis for data processing Access to personal data of a former employee (containing his browser history) on his work computer. ITALY ·Art. 5, 6, 7 Personal Data Processing Right of Access Aug 10, 2020
€10,000 Community of Baronissi: Insufficient legal basis for data processing The community published on its website personal data of data subjects including names, birth dates, place of birth, place of residence, etc. ITALY ·Art. 5, 6 Personal Data Processing Public Authority Aug 10, 2020
€3,000 GTL S.R.L.: Insufficient fulfilment of data subjects rights Failure to graint access to personal data of a data subject according to Art. 15 GDPR. ITALY ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Aug 6, 2020
€2,000 School: Insufficient legal basis for data processing Placing personal data of pupils on a public notice board. ITALY ·Art. 5, 6 Personal Data Processing Education Aug 5, 2020
€15,000 Mapei S.p.A.: Insufficient legal basis for data processing The company had left the e-mail account of the data subject active even after the termination of his employment and had automatically forwarded incoming e-mails. The company did… ITALY ·Art. 5, 6, 12 +3 Personal Data Processing Supervisory Authorities Aug 4, 2020
€5,000 National Institute for Social Security - Department of the Province of Brescia: Insufficient fulfilment of data subjects rights Failure to graint access to personal health data of a data subject according to Art. 15 GDPR. ITALY ·Art. 15 Healthcare Personal Data Health Data Aug 4, 2020
€1,000 Supermarket: Insufficient legal basis for data processing The operator of a supermarket displayed the letter of dismissal to the personnel manager on the publicly visible notice board of the supermarket. ITALY ·Art. 5, 6 Processing Human Resources Supervisory Authorities Aug 4, 2020
€2,000 Community of Manduria: Insufficient legal basis for data processing The community transmitted personal data of a community employee to the press without sufficient legal basis. ITALY ·Art. 5, 6 Personal Data Processing Employees Jul 30, 2020
€4,000 Region of Campania: Insufficient legal basis for data processing Publication of an enforcement order in civil proceedings on the Region's website. The document listed the names and place of residence and the amount of the claim. ITALY ·Art. 5, 6 Processing Public Authority Supervision Jul 29, 2020
€3,000 Community of San Giorgio Jonico: Insufficient legal basis for data processing Publication of personal data on the municipal website with regard to legal proceedings. ITALY ·Art. 5, 6 Personal Data Processing Public Authority Jul 29, 2020
€200,000 Merlini s.r.l.: Insufficient legal basis for data processing The company had carried out telemarketing activities on behalf of Wind Tre S.p.A. through a third party provider as data processor without sufficient legal basis fpr data… ITALY ·Art. 5, 6, 7 +2 Processors Controllers Processing Jul 13, 2020
€800,000 Iliad Italia S.p.A.: Non-compliance with general data processing principles The fine relates to data protection infringements concerning the processing of customer data for the activation of SIM cards and the manner in which payment data was recorded. In… ITALY ·Art. 5, 25 Integrity and Confidentiality Principle Personal Data Transparency Jul 13, 2020
€17M Wind Tre S.p.A.: Insufficient legal basis for data processing Fines for several unlawful data processing activities relating to direct marketing. Hundreds of data subjects claimed to have received unsolicited communications sent without… ITALY ·Art. 5, 6, 12 +2 Consent Personal Data Processing Jul 13, 2020
€15,000 Mapei S.p.A.: Insufficient fulfilment of data subjects rights Mapei failed to respond to the request for access to personal data of the data subject. In addition, Mapei had left the e-mail account of the person concerned active even after… ITALY ·Art. 5, 12, 13 +1 Right of Access Personal Data Supervisory Authorities Jul 2, 2020
€4,000 Liceo Artistico Statale di Napoli: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information in the teacher rankings published on the Institute's website. This… ITALY ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
€4,000 Liceo Scientifico Nobel di Torre del Greco: Insufficient legal basis for data processing The AEPD's decision reveals that the high school unlawfully published health data and other information of more than 2000 teachers in the teacher rankings published on the… ITALY ·Art. 5, 6, 9 Retention Period Fairness & Transparency Healthcare Mar 6, 2020
€3,000 San Giorgio Jonico: Insufficient legal basis for data processing Publication of a citizen's personal data on a website and failure to comply with requests for deletion. ITALY ·Art. 5, 6, 17 Personal Data Processing Public Authority Mar 5, 2020
€4,000 Comune di Urago: Insufficient legal basis for data processing The local council has published on its website information containing a person's personal data, including health information. ITALY ·Art. 5, 6 Personal Data Processing Public Authority Feb 13, 2020
€20,000 RTI - Reti Televisive Italiane s.p.a.: Insufficient legal basis for data processing The television station broadcasted a documentary about prostitution in Switzerland, in which the persons interviewed were not made sufficiently anonymous. ITALY ·Art. 5, 6 Processing Telecommunications Supervisory Authorities Feb 6, 2020
€4,000 Comune di Colledara: Insufficient legal basis for data processing Publication of documents relating to a public tender with personal data on a website ITALY ·Art. 5, 6 Personal Data Processing Public Authority Jan 30, 2020
€30,000 Azienda Ospedaliero Universitaria Integrata di Verona (Hospital): Insufficient technical and organisational measures to ensure information security The fine was preceded by access to health data by unauthorised persons, allowing a trainee and a radiologist to gain access to the health data of their colleagues. The… ITALY ·Art. 5, 32 Security Personal Data Processing Jan 23, 2020
€30,000 Sapienza Università di Roma: Insufficient technical and organisational measures to ensure information security The fine is based on the fact that, according to the data protection authority, the Sapienza Università made available online identification data of two people who had reported… ITALY ·Art. 5, 32 Security Identification Education Jan 23, 2020
€10,000 Community of Francavilla Fontana: Insufficient legal basis for data processing The community published on its website information about a court trial, including personal data such as health data about a data subject. ITALY ·Art. 5, 6 Personal Data Types of Special Categories of Personal Data Processing Jan 15, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Direct Marketing Storage Limitation Jan 15, 2020
€8.5M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Art. 5, 6, 17 +1 Integrity and Confidentiality Principle Storage Limitation Direct Marketing Dec 11, 2019
€3M Eni Gas e Luce: Insufficient legal basis for data processing The Italian supervisory authority imposed two fines totalling EUR 11,5 million on Eni Gas and Luce (Egl) for unlawful processing of personal data in the context of advertising… ITALY ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Processing Dec 11, 2019
€50,000 Italian political party Movimento 5 Stelle: Insufficient technical and organisational measures to ensure information security A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had… ITALY ·Art. 32 Controllers Processors Security Apr 17, 2019