Back to Feed
PolicySep 8, 2026

Garante per la protezione dei dati personali (Italy) - 551/2026

Italy's DPA fines public sector entity €10,000 for unlawful data publication.

Summary

Italy's Garante per la protezione dei dati personali (DPA) has fined a public sector entity €10,000 for violating GDPR. The DPA found that the publication of a ranking list containing personal data of 90 individuals, including details that could infer disability and financial situations, was unlawful. The entity's defense that the publication was required by national law was rejected, as the law did not apply to ineligible candidates or the specific context of the publication.

Full text

Help Garante per la protezione dei dati personali (Italy) - 551/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:04, 8 September 2026 view sourceLs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsTag: Visual edit← Older edit Latest revision as of 13:55, 8 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators396 editsmTag: Visual edit Line 101: Line 101: A data subject who was deemed ineligible lodged a complaint with the DPA.A data subject who was deemed ineligible lodged a complaint with the DPA. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The selection procedure included questions regarding the disability status and financial situations of the applicants. Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data.The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure.The controller further clarified that the data processed did not fall within the special category nature of [[Article 9 GDPR]], claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that it had taken measures to prevent such unlawful processing from happening again. The controller further clarified that the data processed did not fall within the special category nature of [[Article 9 GDPR]], claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that they have taken measures to prevent such unlawful processing from happening again. === Holding ====== Holding === The DPA held that the controller’s reference to national law was irrelevant given the fact that the requirement does not apply to the publishing of ineligible candidates carried out through the placement of individuals registered on employment lists. The DPA clarified that this law applies to the final rankings of the eligible candidates who were not selected as part of a competitive selection procedure, which was not the case. Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years.The DPA held that the national law did not apply to the publishing of ineligible candidates but only of selected candidates.Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA also found that the data, together with the selection criteria which included a "degree of invalidity" and questions on financial situations, could infer a general condition of disability, potentially revealing sensitive personal data and information on the financial situation of the applicants. The mere participation to the selection procedure could therefore already reveal certain data, in violation of [[Article 9 GDPR]]. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA found that the mere fact that participating in such a procedure could lead to inference of special category data which may have adverse effects on the data subject, makes the publication of such unlawful in light of [[Article 9 GDPR]].The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of [[Article 5 GDPR]], [[Article 6 GDPR]] and [[Article 9 GDPR]].The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of [[Article 5 GDPR|Articles 5]], [[Article 6 GDPR|6]] and [[Article 9 GDPR|9 GDPR]]. == Comment ==== Comment == Latest revision as of 13:55, 8 September 2026 Garante per la protezione dei dati personali - 551/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 10000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number/Name: 551/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based selection process. The data was also indexed on Google. A data subject who was deemed ineligible lodged a complaint with the DPA. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which staff is hired from employment centers into civil service. The procedure was organised according to national provisions which included a provision relating to the publication of the selected candidates. The selection procedure included questions regarding the disability status and financial situations of the applicants. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller further clarified that the data processed did not fall within the special category nature of Article 9 GDPR, claiming that it did n

Entities

Garante per la protezione dei dati personali (vendor)