Back to Feed
PolicyOct 7, 2026

Garante per la protezione dei dati personali (Italy) - 10297167

Italian DPA fines employer €10,000 for unlawful workplace surveillance.

Summary

Italy's Garante per la protezione dei dati personali has fined the National Institute of Meteorological Research €10,000 for implementing CCTV surveillance in the workplace without adequately informing employees and interested third parties. The authority also found that the controller failed to conduct a Data Protection Impact Assessment (DPIA) before initiating the processing, violating GDPR articles related to transparency, data processing impact assessments, and employee data.

Full text

Help Garante per la protezione dei dati personali (Italy) - 10297167: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:13, 1 October 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators111 edits Tag: Decisions [1.0] Latest revision as of 06:18, 7 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators111 editsmTag: Visual edit Line 100: Line 100: }}}} The DPA fined a controller €10,000 for implementing surveillance in the workplace without the necessary information being provided to its employees and interested third parties, and in absence of a DPIA.The DPA fined an employer €10,000 for implementing CCTV workplace surveillance without informing its employees. Further, the DPA held that the controller failed to perform a DPIA prior to the processing. == English Summary ==== English Summary == Line 121: Line 121: The DPA further emphasised that the controller failed to inform its staff and interested parties sufficiently of the surveillance practices, neither of the associated personal data processing happening, prior to its implementation. The DPA held that the lack of information and the fact that the signage was affixed after the processing had already taken place was insufficient.The DPA further emphasised that the controller failed to inform its staff and interested parties sufficiently of the surveillance practices, neither of the associated personal data processing happening, prior to its implementation. The DPA held that the lack of information and the fact that the signage was affixed after the processing had already taken place was insufficient. Finally, the DPA found that the controller implemented the video surveillance in its workplace, which considered of the processing of personal data of its employees, in absence of the necessary data protection impact assessment, contrary to [[Article 35 GDPR|Article 35 GDPR]].Finally, the DPA found that the controller implemented the video surveillance in its workplace, which considered of the processing of personal data of its employees, in absence of the necessary data protection impact assessment, contrary to [[Article 35 GDPR]]. In light of the foregoing the DPA fined the controller €10,000 for violations of Articles 5(1)(a), 12, 13, 35 and 88 GDPR. In light of the foregoing the DPA fined the controller €10,000 for violations of Articles 5(1)(a), 12, 13, 35 and 88 GDPR. Latest revision as of 06:18, 7 October 2026 Garante per la protezione dei dati personali - 10297167 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 12(1) GDPR Article 13 GDPR Article 32 GDPR Article 88 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: 01.10.2026 Fine: 10000.0 EUR Parties: Nazionale di Ricerca Metrologica National Case Number/Name: 10297167 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined an employer €10,000 for implementing CCTV workplace surveillance without informing its employees. Further, the DPA held that the controller failed to perform a DPIA prior to the processing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received two distinct but related complaints from employees (the data subjects) of the National Institute of Meteorological Research (the controller) concerning the transparency of the use of video surveillance. The controller clarified that the surveillance was subject to a trade agreement within which they were testing the use and coverage of 10 cameras. The cameras would only record when the alarm was activated, and excluded the possibility of recording areas which were subject to public access. Storage of the recordings was limited to 72 hours from the trigger of an alarm. The controller further explained that at the time the surveillance system was being tested without actually recording any images. Particularly, the controller sought to verify the technical and adequate functioning of the cameras and monitors as well as effective coverage of the security parameter. Due to insufficient and inadequate coverage of certain areas, which was deemed contrary to the purpose of the surveillance, the controller subsequently installed 8 additional cameras. The controller clarified that this was in line with the agreement which allowed for extraordinary maintenance. As a result of the surveillance being at the testing phase, the controller did not provide the data subjects and staff of the information regarding data processing. The controller emphasised that before its official operation this information would be provided. Holding The DPA held that the installed cameras were incompatible with the agreement as a result of increasing the number of cameras as well as the modification of their location and subsequent area being converted. Nonetheless, the DPA found that the extraordinary maintenance did not allow for the defined area being covered by the cameras to be altered. Therefore, although the purpose of surveillance activation was to test the system, personal data processing was still being undertaken. The DPA further emphasised that the controller failed to inform its staff and interested parties sufficiently of the surveillance practices, neither of the associated personal data processing happening, prior to its implementation. The DPA held that the lack of information and the fact that the signage was affixed after the processing had already taken place was insufficient. Finally, the DPA found that the controller implemented the video surveillance in its workplace, which considered of the processing of personal data of its employees, in absence of the necessary data protection impact assessment, contrary to Article 35 GDPR. In light of the foregoing the DPA fined the controller €10,000 for violations of Articles 5(1)(a), 12, 13, 35 and 88 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10297167] Decision of September 3, 2026 Register of Decisions No. 620 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection,” which sets forth provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC” (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the

Entities

Garante per la protezione dei dati personali (vendor)CCTV (product)National Institute of Meteorological Research (vendor)