Back to Feed
PolicyJul 21, 2026

Garante per la protezione dei dati personali (Italy) - 457/2026

Italy's DPA fines Municipality of Vasto €5,000 for GDPR violations related to traffic cameras.

Summary

Italy's Garante per la protezione dei dati personali has fined the Municipality of Vasto €5,000 for violating GDPR. The municipality failed to provide adequate information to data subjects about traffic cameras used for violations and processed excessive data by not limiting image capture to license plates. The DPA also found issues with the privacy policy and the timing and scope of the Data Protection Impact Assessment.

Full text

Help Garante per la protezione dei dati personali (Italy) - 457/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:32, 21 July 2026 view source Ap (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators746 edits Tag: submission [1.0]Newer edit → (No difference) Revision as of 14:32, 21 July 2026 Garante per la protezione dei dati personali - 457/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(c) GDPR Article 5(1)(a) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Article 12(1) GDPR Article 12(5) GDPR Article 13 GDPR Article 35 GDPR Type: Complaint Outcome: Upheld Started: Decided: 18.06.2026 Published: Fine: 5,000 EUR Parties: Municipality of Vasto National Case Number/Name: 457/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ap The DPA fined a municipality €5,000 for not providing data subjects with sufficient information relating to the cameras used to record driving violations. The municipality also processed an excessive amount of data by not limiting the image to the data subject’s license plate. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. Holding The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35, as the controller had prepared a data protection impact assessment (DPIA) after the processing activities began. The DPA noted that the DPIA was also not specific enough. The DPA fined the controller €5,000. In addition, the DPA ordered the controller to adopt appropriate measures to provide data subjects with adequate information and update its DPIA. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [web doc. no. 10267254] Measure of June 18, 2026 Register of Measures no. 457 of June 18, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation"); SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code"); CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019"); Having seen the documents in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801; Rapporteur: Professor Pasquale Stanzione; WHEREAS 1. Introduction By complaint filed on XX pursuant to Article 77 of the Regulation and Article 141 of the Code, Mr. XX complained of a violation of the regulations on the protection of personal data by the Municipality of Vasto (hereinafter, the "Municipality"), regarding the receipt of a report alleging infringement of Article 146 of Legislative Decree No. 285 of 30 April 1992 ("New Highway Code", or "C.d.S."), verified by video surveillance. In In particular, it was stated that "With report no. […] the Vasto Local Police Headquarters charged […] with a violation of Article 146/3 of the Highway Code for a break-in committed on XX […] a violation confirmed using XX equipment […highlighting] the absence of any form of information near the location where cameras were installed to detect the violation of "running a red light" and that "the front windshield and rear window of the vehicle […] were not automatically darkened to make the driver and any passengers unrecognizable." 2. The Investigative Activity In response to two requests for information from the Authority (respectively, protocol no. XX of XX and no. XX of XX), formulated pursuant to Article 157 of the Code, the Municipality declared, in notes dated XX and XX (respectively, Authority protocol nos. XX and XX), to which full reference is made, in particular, that: - the first-level information notice "is placed near the violation detection device. […and] it is noted that the signage is being updated throughout the municipal area, which contains information that is more consistent with European Regulation 679/2016 and up-to-date. This signage, in addition to the essential information on processing, also contains a link, via QR code, to the second-level information notice, complete with the information required pursuant to Articles 13 and 14 of the GDPR. This information notice is available on the Municipality's website" (see note dated XX); - "In the vicinity of the traffic light violation detection device, warning signs are present, and signs have also been placed regarding the municipal video surveillance system, which also includes devices for detecting traffic code violations. […]" (see note of XX); - "There is also another camera, used for urban security purposes, near

Entities

Garante per la protezione dei dati personali (vendor)traffic cameras (product)