Back to Feed
PolicyAug 3, 2026

Garante per la protezione dei dati personali (Italy) - 542/2026

Italian DPA fines company €2M for GDPR violations related to data processing.

Summary

Italy's Garante per la protezione dei dati personali has fined a controller €2,000,000 for multiple GDPR violations. The violations included improper processing of contact data, lack of transparency, insufficient legal basis for processing, and failure to implement adequate data protection by design. The controller collected extensive personal information, including data from private communications and browsing activity, without a clear legitimate interest or necessity, and failed to adequately protect public officials' data.

Full text

Help Garante per la protezione dei dati personali (Italy) - 542/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 14:53, 30 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators252 edits Tag: Decisions [1.0] Latest revision as of 10:51, 3 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators252 editsmTag: Visual edit (One intermediate revision by the same user not shown)Line 129: Line 129: The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy.The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, restricted the Community Program in Italy and extended the opt-out period to fourteen days.After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Line 135: Line 136: Regarding the territorial scope of the GDPR, the DPA acknowledged that [[Article 3 GDPR|Article 3(2)(a) GDPR]] could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that [[Article 3 GDPR|Article 3(2)(b) GDPR]] applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring.Regarding the territorial scope of the GDPR, the DPA acknowledged that [[Article 3 GDPR|Article 3(2)(a) GDPR]] could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that [[Article 3 GDPR|Article 3(2)(b) GDPR]] applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 12 GDPR|Article 12 GDPR]]. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 12 GDPR]]. Moreover, the DPA assessed whether [[Article 6 GDPR|Article 6(1)(f) GDPR]] provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under [[Article 6 GDPR|Article 6(1)(f) GDPR]].Moreover, the DPA assessed whether [[Article 6 GDPR|Article 6(1)(f) GDPR]] provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under [[Article 6 GDPR|Article 6(1)(f) GDPR]]. Line 141: Line 142: It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework. However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate.It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework. However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected data extending beyond ordinary professional contact information, including information derived from emails, calendars, meetings, CRM systems, browser extensions and browsing activity. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necess

Entities

Garante per la protezione dei dati personali (vendor)