Back to Feed
PolicySep 9, 2026

Garante per la protezione dei dati personali (Italy) - 553/2026

Italian DPA fines school €10,000 for unlawful processing of dismissed employee data.

Summary

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has fined a school €10,000 for violating GDPR. The school unlawfully processed data of dismissed employees by sharing details of disciplinary proceedings with other branches, exceeding the necessity and data minimization principles. The DPA found no sufficient legal obligation for such broad notification and noted that individuals are obligated to declare prior dismissal, a claim verifiable by employers.

Full text

Help Garante per la protezione dei dati personali (Italy) - 553/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 10:15, 9 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators59 edits Tag: Decisions [1.0] Latest revision as of 10:16, 9 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators59 editsmTag: Visual edit Line 108: Line 108: The controller deemed the notice of termination as necessary, and the only way to ensure that dismissed employees are prevented from entering into employment contracts within the school administration. Particularly, the controller emphasised that pursuant to national law, giving notice of termination without reference to the disciplinary dismissal does not suffice to preclude the data subject from being rehired. Especially as a prevention mechanism against fraudulent inclusion of dismissed personnel where individuals who have been dismissed fail to disclose the reasons for termination.The controller deemed the notice of termination as necessary, and the only way to ensure that dismissed employees are prevented from entering into employment contracts within the school administration. Particularly, the controller emphasised that pursuant to national law, giving notice of termination without reference to the disciplinary dismissal does not suffice to preclude the data subject from being rehired. Especially as a prevention mechanism against fraudulent inclusion of dismissed personnel where individuals who have been dismissed fail to disclose the reasons for termination. === Holding ====== Holding === The DPA held that the controller did not sufficiently identify a legal obligation within national regulations which provides the notification to other branches of the school administration, of the imposition of disciplinary measures. Especially because national law imposes the obligation on individuals participating in a selection procedure to declare that they have not been dismissed before, and this declaration is verifiable.The DPA held that the controller did not sufficiently identify a legal obligation within national regulations which provides the notification to other branches of the school administration, of the imposition of disciplinary measures. Especially because national law imposes the obligation on individuals participating in a selection procedure to declare that they have not been dismissed before, and this declaration is verifiable. Line 119: Line 117: Furthermore, the DPA found that in light of the principles of necessity and data minimisation it would have been sufficient if the controller provided only notice of the termination without details on the proceedings which led to the data subject’s dismissal. This was considered in light of the fact that the information made available to various recipients could have had significant adverse effects on the data subject.Furthermore, the DPA found that in light of the principles of necessity and data minimisation it would have been sufficient if the controller provided only notice of the termination without details on the proceedings which led to the data subject’s dismissal. This was considered in light of the fact that the information made available to various recipients could have had significant adverse effects on the data subject. Thus, the DPA found the controller in violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]] and Article 6(1)(c), (e), 6(2) and 6(3) GDPR and correspondingly imposed a €10.000 fine on the controller.Thus, the DPA found the controller in violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]] and [[Article 6 GDPR|Article 6(1)(c), (e), 6(2) and 6(3) GDPR]] and correspondingly imposed a €10.000 fine on the controller. == Comment ==== Comment == Latest revision as of 10:16, 9 September 2026 Garante per la protezione dei dati personali - 553/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Article 6(2) GDPR Article 6(3) GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 10000.0 EUR Parties: n/a National Case Number/Name: 553/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the Ministry of Education and Merit €10.000 for unlawfully processing the data subject’s personal data concerning her dismissal by notifying various administrative branches. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches of her dismissal. The DPA started an investigation and found that the controller had notified all public schools within the Monza and Brianza Territorial Area, the Teacher and ATA Ranking Offices and the Pensions Office of the data subject’s name, place and date of birth, job title, and disciplinary sanction imposed following disciplinary proceedings. The controller underscored that the Regional School Offices and Territorial Offices which lack legal autonomy and the Educational Institutions which has autonomy, are branches and subordinate of the same singular school administration of the controller. The controller deemed the notice of termination as necessary, and the only way to ensure that dismissed employees are prevented from entering into employment contracts within the school administration. Particularly, the controller emphasised that pursuant to national law, giving notice of termination without reference to the disciplinary dismissal does not suffice to preclude the data subject from being rehired. Especially as a prevention mechanism against fraudulent inclusion of dismissed personnel where individuals who have been dismissed fail to disclose the reasons for termination. Holding The DPA held that the controller did not sufficiently identify a legal obligation within national regulations which provides the notification to other branches of the school administration, of the imposition of disciplinary measures. Especially because national law imposes the obligation on individuals participating in a selection procedure to declare that they have not been dismissed before, and this declaration is verifiable. Additionally, the DPA found the mere possibility that a dismissed employee may apply for another selection procedure is hypothetical, and thus the processing as in the case of the data subject was undertaken by the controller in absence of a legal basis. In reference to the declaration by the controller that the Regional School Offices, Territorial Offices and the Educational Institutions are branches and subordinates and thus notification of the data subject’s dismissal was permitted, was not accepted by the DPA. Namely, as the DPA maintained that as a general rule the personal data of employees pertaining to their employment relationship may not be disclosed to parties other than those involved in the employment relationship. Moreover, as independent controllers they were not authorised to process such data and thus are third parties for the purposes of personal data protection. Furthermore, the DPA found that in light of the principles of necessity and data minimisation it would have been sufficient if the controller provided only notice of the termination without details on the proceedings which led to the data subject’s dismissal. This was considered in light of the fact that the information made available to various recipients could have had significant adverse effects on the data subject. Thus, the DPA found

Entities

Garante per la protezione dei dati personali (vendor)