[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYX7UjPi4m67n7SUhgYq-hnlEckrMTLZi7u0SOzv7rYU":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"2c6fb930-16b1-418a-9f38-a93a3b364d94","Garante per la protezione dei dati personali (Italy) - 10286417","garante-per-la-protezione-dei-dati-personali-italy-10286417-021d9b","Facts ← Older revision Revision as of 17:22, 14 September 2026 Line 121: Line 121: === Facts === === Facts === The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the \"Transparent Administration\" section of its website. A document was published by an employee, but other act was published at the same time, and it contained the names of 50 employees of that company and the waste tax roll (TARI) of around 31,000 taxpayers, both natural and legal persons. The roll listed names, tax codes, addresses of residence, cadastral data, the address and surface area of the taxed properties, and the tax category assigned to each taxpayer. The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the \"Transparent Administration\" section of its website. A document was published by an employee, but other act was published at the same time, and it contained the names of 50 employees of that company and the waste tax roll of around 31,000 taxpayers, both natural and legal persons. The roll listed names, tax codes, addresses of residence, cadastral data, the address and surface area of the taxed properties, and the tax category assigned to each taxpayer. The documents remained online for eleven days. They were viewed 57 times, 44 times by external users, and downloaded 31 times, always by external users. The documents remained online for eleven days. They were viewed 57 times, 44 times by external users, and downloaded 31 times, always by external users. The controller notified the breach to the DPA under [[Article 33 GDPR|Article 33 GDPR]]. It did not inform the data subjects, arguing that the breach was unlikely to result in a high risk because the published data did not fall under Articles 9 or 10 GDPR, and it left that decision to the DPA. A local newspaper then reported the publication. The controller replied with a press release on its website, it stated that the controller had acted promptly and followed its protocols, and that the published document contained personal data which was neither sensitive nor judicial, as well as data of legal persons which, in the controller's view, fell outside data protection law. The controller notified the breach to the DPA under [[Article 33 GDPR]]. It did not inform the data subjects, arguing that the breach was unlikely to result in a high risk because the published data did not fall under Articles 9 or 10 GDPR, and it left that decision to the DPA. A local newspaper reported the publication, and the controller replied with a press release on its website, stating that had acted promptly and followed its protocols, and that the published document contained personal data which was neither sensitive nor judicial, as well as data of legal persons which, in the controller's view, fell outside data protection law. A third party reported the publication to the DPA under Article 144 of the Italian Data Protection Code. During the investigation, the controller asked its supplier to change the default setting, disabled the automatic publication of attachments and carried out a DPIA on the publication software, which the DPO approved. The DPIA concluded that human error was unlikely because staff had been made aware of data protection issues. A third party reported the publication to the DPA under Article 144 of the Italian Data Protection Code. During the investigation, the controller asked its supplier to change the default setting, disabled the automatic publication of attachments and carried out a DPIA on the publication software, which the DPO approved. The DPIA concluded that human error was unlikely because staff had been made aware of data protection issues. Line 138: Line 139: Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time. Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time. Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf. Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf. Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the TARI category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination. Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the waste tax category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination. Sixth, the DPA held that the press release did not amount to a communication under [[Article 34 GDPR|Article 34 GDPR]]. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own. Finally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of Articles 5(1)(a), 5(2), 12(1), 24 and 34 GDPR. Sixth, the DPA held that the press release did not amount to a communication under [[Article 34 GDPR]]. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own. Finally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of Articles 5(1)(a), 5(2), 12(1), 24 and 34 GDPR. The DPA classified the gravity of the violation as medium and the conduct as negligent. It took into account as mitigating factors the small size of the municipality, the absence of previous relevant violations and the controller's cooperation, in particular the new procedure requiring an active step from the operator to upload attachments. On these grounds, the DPA fined the controller €6,000. The DPA classified the gravity of the violation as medium and the conduct as negligent. It took into account as mitigating factors the small size of the municipality, the absence of previous relevant violations and the controller's cooperation, in particular the new procedure requiring an active step from the operator to upload attachments. On these grounds, the DPA fined the controller €6,000.","The Italian Data Protection Authority (Garante) has fined the Municipality of Rieti €6,000 for a data breach where sensitive taxpayer information, including names and property details, was inadvertently published online for eleven days. The municipality failed to adequately assess the risk and notify data subjects, arguing the data was not sensitive under GDPR. The Garante found multiple violations, including a lack of detection measures and inadequate communication of the breach.","Italian DPA fines Municipality of Rieti €6,000 for publishing sensitive taxpayer data online.","Help Garante per la protezione dei dati personali (Italy) - 10286417: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 17:16, 14 September 2026 view sourceLigialagev (talk | contribs)42 edits Tag: Decisions [1.0] Latest revision as of 17:22, 14 September 2026 view source Ligialagev (talk | contribs)42 editsm Tag: Visual edit Line 121: Line 121: === Facts ====== Facts === The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the \"Transparent Administration\" section of its website. A document was published by an employee, but other act was published at the same time, and it contained the names of 50 employees of that company and the waste tax roll (TARI) of around 31,000 taxpayers, both natural and legal persons. The roll listed names, tax codes, addresses of residence, cadastral data, the address and surface area of the taxed properties, and the tax category assigned to each taxpayer.The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the \"Transparent Administration\" section of its website. A document was published by an employee, but other act was published at the same time, and it contained the names of 50 employees of that company and the waste tax roll of around 31,000 taxpayers, both natural and legal persons. The roll listed names, tax codes, addresses of residence, cadastral data, the address and surface area of the taxed properties, and the tax category assigned to each taxpayer. The documents remained online for eleven days. They were viewed 57 times, 44 times by external users, and downloaded 31 times, always by external users. The documents remained online for eleven days. They were viewed 57 times, 44 times by external users, and downloaded 31 times, always by external users. The controller notified the breach to the DPA under [[Article 33 GDPR|Article 33 GDPR]]. It did not inform the data subjects, arguing that the breach was unlikely to result in a high risk because the published data did not fall under Articles 9 or 10 GDPR, and it left that decision to the DPA. A local newspaper then reported the publication. The controller replied with a press release on its website, it stated that the controller had acted promptly and followed its protocols, and that the published document contained personal data which was neither sensitive nor judicial, as well as data of legal persons which, in the controller's view, fell outside data protection law.The controller notified the breach to the DPA under [[Article 33 GDPR]]. It did not inform the data subjects, arguing that the breach was unlikely to result in a high risk because the published data did not fall under Articles 9 or 10 GDPR, and it left that decision to the DPA. A local newspaper reported the publication, and the controller replied with a press release on its website, stating that had acted promptly and followed its protocols, and that the published document contained personal data which was neither sensitive nor judicial, as well as data of legal persons which, in the controller's view, fell outside data protection law. A third party reported the publication to the DPA under Article 144 of the Italian Data Protection Code. During the investigation, the controller asked its supplier to change the default setting, disabled the automatic publication of attachments and carried out a DPIA on the publication software, which the DPO approved. The DPIA concluded that human error was unlikely because staff had been made aware of data protection issues.A third party reported the publication to the DPA under Article 144 of the Italian Data Protection Code. During the investigation, the controller asked its supplier to change the default setting, disabled the automatic publication of attachments and carried out a DPIA on the publication software, which the DPO approved. The DPIA concluded that human error was unlikely because staff had been made aware of data protection issues. Line 138: Line 139: Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time.Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time. Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf.Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf. Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the TARI category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination.Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the waste tax category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination. Sixth, the DPA held that the press release did not amount to a communication under [[Article 34 GDPR|Article 34 GDPR]]. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own. Finally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of Articles 5(1)(a), 5(2), 12(1), 24 and 34 GDPR.Sixth, the DPA held that the press release did not amount to a communication under [[Article 34 GDPR]]. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the d","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10286417&diff=53013&oldid=53012","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-14T17:22:01+00:00","2026-09-14T18:00:10.449778+00:00",7,[18,21],{"name":19,"type":20},"TARI","product",{"name":22,"type":23},"Garante per la protezione dei dati personali","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]