Garante per la protezione dei dati personali (Italy) - 457/2026
Italian DPA fines Municipality of Vasto €5,000 for GDPR violations related to traffic cameras.
Summary
The Italian Data Protection Authority (Garante per la protezione dei dati personali) fined the Municipality of Vasto €5,000 for violating GDPR. The violations included processing more data than necessary by capturing more than just license plates with traffic cameras and failing to conduct a proper Data Protection Impact Assessment (DPIA) before processing began. The DPA also ordered the municipality to improve data subject information and update its DPIA.
Full text
Help Garante per la protezione dei dati personali (Italy) - 457/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:52, 21 July 2026 view sourceAp (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators746 editsmTag: Visual edit← Older edit Latest revision as of 19:45, 21 July 2026 view source Mba (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators964 editsm Tag: Visual edit Line 89: Line 89: The DPA also found a violation of [[Article 5 GDPR#1c|Article 5(1)(c) GDPR]], as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary.The DPA also found a violation of [[Article 5 GDPR#1c|Article 5(1)(c) GDPR]], as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35, as the controller had prepared a data protection impact assessment (DPIA) after the processing activities began. The DPA noted that the DPIA was also not specific enough. Finally, the DPA found a violation of [[Article 35 GDPR]], as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA.The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA. Latest revision as of 19:45, 21 July 2026 Garante per la protezione dei dati personali - 457/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(c) GDPR Article 5(1)(a) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Article 12(1) GDPR Article 12(5) GDPR Article 13 GDPR Article 35 GDPR Type: Complaint Outcome: Upheld Started: Decided: 18.06.2026 Published: Fine: 5,000 EUR Parties: Municipality of Vasto National Case Number/Name: 457/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ap The DPA fined a municipality €5,000 for not providing data subjects with sufficient information relating to the cameras used to record driving violations. The municipality also processed an excessive amount of data by not limiting the image to the data subject’s license plate. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [web doc. no. 10267254] Measure of June 18, 2026 Register of Measures no. 457 of June 18, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction By complaint filed on XX pursuant to Article 77 of the Regulation and Article 141 of the Code, Mr. XX complained of a violation of the regulations on the protection of personal data by the Municipality of Vasto (hereinafter, the "Municipality"), regarding the receipt of a report alleging infringement of Article 146 of Legislative Decree No. 285 of 30 April 1992 ("New Highway Code", or "C.d.S."), verified by video surveillance. In In particular, it was stated that "With report no. […] the Vasto Local Police Headquarters charged […] with a violation of Article 146/3 of the Highway Code