[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP7utgN7BbtwwTbDmetPJaB5XsUhfOFrXJ75OaXhwPZg":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"36d8158a-1747-4ed8-aeaf-0f6aa98a5dd8","Garante per la protezione dei dati personali (Italy) - 585\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-585-2026-627ab4","Facts ← Older revision Revision as of 07:41, 23 September 2026 Line 97: Line 97: === Facts === === Facts === The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response, to two access requests, by the controller regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR|Article 15 GDPR]], they would have allowed for a response compliant with the GDPR. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR]], they would have allowed for a response compliant with the GDPR. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS. Finally, the controller claimed that the data subject did not suffer any harm. Finally, the controller claimed that the data subject did not suffer any harm. === Holding === === Holding === The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and [[Article 15 GDPR|Article 15 GDPR]]. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA. The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and [[Article 15 GDPR]]. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA. The DPA further found a violation of [[Article 13 GDPR|Article 13 GDPR]], for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR. The DPA further found a violation of [[Article 13 GDPR]], for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR. As a result of the foregoing violations, the DPA fined the controller €39,000. As a result of the foregoing violations, the DPA fined the controller €39,000.","The Italian DPA has fined La Patria S.p.A. €39,000 for violating GDPR articles 12, 13, and 15. The company failed to adequately respond to an employee's data access requests regarding disciplinary proceedings and did not provide a privacy notice for GPS data used in fleet management. The DPA emphasized that even if a request isn't explicitly GDPR-referenced, controllers must still comply with data subject rights and inform individuals of refusal reasons.","Italian DPA fines La Patria S.p.A. €39,000 for GDPR violations.","Help Garante per la protezione dei dati personali (Italy) - 585\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:35, 21 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators86 edits Tag: Decisions [1.0] Latest revision as of 07:41, 23 September 2026 view source Mba (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators984 editsm Tag: Visual edit Line 97: Line 97: === Facts ====== Facts === The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response, to two access requests, by the controller regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file.The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR|Article 15 GDPR]], they would have allowed for a response compliant with the GDPR.In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under [[Article 15 GDPR]], they would have allowed for a response compliant with the GDPR. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS.As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS. Finally, the controller claimed that the data subject did not suffer any harm.Finally, the controller claimed that the data subject did not suffer any harm. === Holding ====== Holding === The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and [[Article 15 GDPR|Article 15 GDPR]]. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA.The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and [[Article 15 GDPR]]. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA. The DPA further found a violation of [[Article 13 GDPR|Article 13 GDPR]], for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR.The DPA further found a violation of [[Article 13 GDPR]], for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR. As a result of the foregoing violations, the DPA fined the controller €39,000.As a result of the foregoing violations, the DPA fined the controller €39,000. Latest revision as of 07:41, 23 September 2026 Garante per la protezione dei dati personali - 585\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 12 GDPR Article 13 GDPR Article 15 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 39000.0 EUR Parties: La Patria S.p.A. National Case Number\u002FName: 585\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €20,000 for insufficiently responding to two access requests, by not providing suitable nor correct information. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_585\u002F2026&diff=53170&oldid=53118","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-23T07:41:59+00:00","2026-09-23T08:00:09.411889+00:00",7,[18],{"name":19,"type":20},"La Patria S.p.A.","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",[]]