Garante per la protezione dei dati personali (Italy) - 10286417
Italian DPA fines municipality €6,000 for GDPR violations related to public data disclosure.
Summary
The Italian Data Protection Authority (Garante) has fined a municipality €6,000 for multiple GDPR violations. The violations stemmed from an inadequate opt-in/opt-out mechanism for publishing personal data online, a failure to verify publication requirements, late discovery of a data publication breach, and an insufficient risk assessment. The DPA also found the municipality's press release regarding the incident to be inadequate.
Full text
Help Garante per la protezione dei dati personali (Italy) - 10286417: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 17:22, 14 September 2026 view sourceLigialagev (talk | contribs)42 editsm Tag: Visual edit← Older edit Latest revision as of 09:08, 16 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators74 editsmTag: Visual edit Line 134: Line 134: === Holding ====== Holding === First, the DPA held that the software allowed the operator only to exclude a document from publication (opt-out) instead of selecting the documents to be published (opt-in). This default setting made the disclosure of personal data dependent on a single manual step and therefore increased the risk of loss of confidentiality through human error or system faults. The controller could not show that it had followed up on its request to the supplier, since the ticket it produced was merely a suggestion to change the default. The DPA therefore found a violation of Articles 5(1)(a), 5(1)(c), 5(1)(f), 25 and 32 GDPR.First, the DPA held that the software allowed the operator only to exclude a document from publication (opt-out) instead of selecting the documents to be published (opt-in). <u>This default setting made the disclosure of personal data dependent on a single manual step and therefore</u> increased the risk of loss of confidentiality through human error or system faults. The controller could not show that it had followed up on its request to the supplier<u>, since the ticket it produced was merely a suggestion to change the default. T</u>he DPA therefore found a violation of [[Article 5 GDPR|Articles 5(1)(a), 5(1)(c), 5(1)(f)]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]]. Second, the DPA held that a legal publication duty does not create an automatism. Before disclosing personal data online, the controller had to verify which data and documents the applicable rules actually required it to publish. Second, the DPA held that a legal publication duty does not create an automatism. Before disclosing personal data online, the controller had to verify which data and documents the applicable rules actually required it to publish. Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time.Third, the DPA rejected the argument that the cadastral data was <u>in any event</u> available <u>through the tax administration's</u> online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone<u>, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time</u>. Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf.Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of [[Article 5 GDPR|Articles 5(1)(f), 5(2)]], [[Article 24 GDPR|Article 24]], [[Article 25 GDPR|Article 25]] and [[Article 32 GDPR]]. <u>The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf.</u> Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the waste tax category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination.Fifth, the DPA held that the controller should also have considered the number of data subjects, the type and nature of data <u>(identification data and home addresses involved), and the fact that the waste tax category revealed highly personal information,</u> which may allow for the standard of living to be inferred <u>from the type of dwelling.</u> On such a basis the breach was likely to result in a high risk, for instance of theft or discrimination. Therefore, the DPA found that the controller could not limit its risk assessment to whether the breach involved data under [[Article 9 GDPR|Article 9]] and [[Article 10 GDPR]]. Sixth, the DPA held that the press release did not amount to a communication under [[Article 34 GDPR]]. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own. Finally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of Articles 5(1)(a), 5(2), 12(1), 24 and 34 GDPR.Sixth, the DPA held that the press release <u>did not amount</u> was inadequate to be considered a communication under [[Article 34 GDPR]]. It did not state the categories of personal data affected or <u>identify the categories</u> of data subjects, and made incorrect statements <u>it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person.</u> <u>The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own.</u> Additionally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of [[Article 5 GDPR|Articles 5(1)(a), 5(2)]], [[Article 12 GDPR|Article 12(1)]], [[Article 24 GDPR|Article 24]] and [[Article 34 GDPR|Article 34 GDPR.]] The DPA classified the gravity of the violation as medium and the conduct as negligent. It took into account as mitigating factors the small size of the municipality, the absence of previous relevant violations and the controller's cooperation, in particular the new procedure requiring an active step from the operator to upload attachments. On these grounds, the DPA fined the controller €6,000.The DPA classified the gravity of the violation as medium and the conduct as negligent. It took into account as mitigating factors the small size of the municipality, the absence of previous relevant violations and the controller's cooperation, in particular the new procedure requiring an active step from the operator to upload attachments. On these grounds, the DPA fined the controller €6,000. Latest revision as of 09:08, 16 September 2026 Garante per la protezione dei dati personali - 10286417 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 5(2) GDPR Article 12(1) GDPR Article 24 G