[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNMnORzyI6gs-uODq3jiyzMncLQI06wg88_28biz7EZQ":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"a006ca1f-7edc-4c4e-a8ee-503fc90fb22e","Garante per la protezione dei dati personali (Italy) - 585\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-585-2026-9ca496","Created page with \"{{DPAdecisionBOX |Jurisdiction=Italy |DPA-BG-Color= |DPAlogo=LogoIT.png |DPA_Abbrevation=Garante per la protezione dei dati personali |DPA_With_Country=Garante per la protezione dei dati personali (Italy) |Case_Number_Name=585\u002F2026 |ECLI= |Original_Source_Name_1=Garante per la protezione dei dati personali |Original_Source_Link_1=https:\u002F\u002Fwww.garanteprivacy.it\u002Fweb\u002Fguest\u002Fhome\u002Fdocweb\u002F-\u002Fdocweb-display\u002Fdocweb\u002F10297306 |Original_Source_Language_1=Italian |Original_Source_L...\" Show changes","Italy's Garante per la protezione dei dati personali has fined La Patria S.p.A. €20,000 for failing to adequately respond to two data subject access requests. The company did not provide suitable or correct information, interpreting the requests under national labor law rather than GDPR. The Garante found violations of Articles 12, 13, and 15 GDPR, emphasizing that controllers must inform data subjects of refusal reasons and their right to judicial remedy, even if the request doesn't explicitly cite GDPR.","Italy's Garante fines La Patria S.p.A. €20,000 for inadequate response to data access requests.","Help Garante per la protezione dei dati personali (Italy) - 585\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 12:35, 21 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators80 edits Tag: Decisions [1.0] (No difference) Latest revision as of 12:35, 21 September 2026 Garante per la protezione dei dati personali - 585\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 12 GDPR Article 13 GDPR Article 15 GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 39000.0 EUR Parties: La Patria S.p.A. National Case Number\u002FName: 585\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a controller €20,000 for insufficiently responding to two access requests, by not providing suitable nor correct information. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response, to two access requests, by the controller regarding the disciplinary proceedings which led to his dismissal. Particularly, the data subject requested to review and obtain a copy of all documentation, including GPS data, license plate number, and case file. In its defence, the controller submitted that the data subject requested access to the documentation pertaining to the disciplinary proceedings, referencing national labour law, and made no reference to the GDPR. Therefore, the requests were interpreted as part of the data subject’s right to a defence under national labour law, and the controller found it sufficient to deal with it as such. The controller explained that had the data subject made evident that the request was an exercise of their data subject rights, namely the right to access under Article 15 GDPR, they would have allowed for a response compliant with the GDPR. As regards the GPS data, the controller explained that the GPS devices were intended for fleet management, and active and passive safety of the drivers, and that no data directly related to the drivers was processed. Thus, in order for the controller to have complied with this request they would have had to access the system and undertake processing which they had not done before. As a result of the use of the GPS for the above-mentioned purposes, in good faith the controller did not have a privacy notice concerning the processing of data via the GPS. Finally, the controller claimed that the data subject did not suffer any harm. Holding The DPA found that the inadequate response provided by the controller to the data subjects access requests violated Article 12 and Article 15 GDPR. The DPA held that the fact that the data subject did not refer to GDPR provisions in their request, despite having made the subject matter clear, and lacked reference to harm suffered, was not sufficient to alleviate the controller of their obligations to respond. The DPA clarified that where a controller is unable to comply with an access request, they must still inform the data subject of the reasons for refusal and their right to a judicial remedy against the DPA. The DPA further found a violation of Article 13 GDPR, for not providing a privacy notice regarding the geolocation data to its employees. This resulted in inadequate information about the processing operations. The DPA clarified that geolocation data can be indirectly linked to the individual using the car, and thus constitutes personal data processing. In that regard, the controller should have gone beyond offering a mere description, and disclosed the processing operations being carried out and their corresponding compliance with the GDPR. As a result of the foregoing violations, the DPA fined the controller €39,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10297306] Decision of August 6, 2026 Register of Decisions No. 585 of August 6, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Claudio Filippi, Deputy Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016\u002F679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed by Mr. XX against La Patria S.p.A.; HAVING EXAMINED the documentation in the case file; HAVING REGARD TO the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1\u002F2000; RAPPORTEUR: Dr. Agostino Ghiglia; 1. FACTS AND COURSE OF THE PRELIMINARY INVESTIGATION 1.1. Origin of the preliminary investigation and activities carried out. On July 26, 2023, Mr. XX filed a complaint pursuant to Article 77 of the Regulation and Articles 142 et seq. of the Code against La Patria S.p.A. (hereinafter, the Company). In response to this complaint, corrective measures were submitted on November 26, 2023, and April 18, 2024, following specific requests from the Office dated November 16, 2023, and April 3, 2024, respectively. The complaint alleged violations of the Regulations, specifically: the failure to respond to two requests for access to data in which the complainant asked to “review and obtain a copy of all documentation pertaining to the […] [disciplinary] charge, including the recording of the GPS device installed on the company vehicle with license plate number […]” (June 14, 2022) and to have “access to the case files in order to review and obtain copies of all documentation pertaining to the aforementioned disciplinary charge” (June 25, 2022); the Company’s submission, in the proceedings before the judicial authority, of an “alleged list of GPS records—a satellite system with which company vehicles are equipped—which, according to the Company’s assertions, [Company], dates from the period between April 2, 2022, and May 25, 2022,” as well as having commissioned a private investigation firm to conduct surveillance of the complainant. On May 2, 2024, the Office sent a request for information pursuant to Article 157 of the Code to the Company, which responded on June 10, 2024. On that occasion, the Company stated that: “[the complainant] was employed by La Patria Spa […] as a security guard until July 4, 2022, the date on which the employee was terminated for just cause following disciplinary proceedings initiated with a disciplinary charge dated June 7, 2022, which was subsequently rescinded and replaced by a disciplinary charge dated June 21, 2022” (see note dated June 10, 2024, p. 1); “By order of January 30, 2024, the Court […] ruled that the termination was unlawful” (see cited note, p. 1); “In that ruling, the Court also ruled on the legality of the investigative inquiry commissioned by La Patria from [the investigative agency]” (see cited note, p. 2); “As of the date of this brief, an appeal is pending […] pursuant to Art. 1, paragraph 5, of Law No. 92\u002F2012, filed by La Patria Spa” (see cited note, p. 2); “With regard to the employment relationship established with the [complainant], attached are the privacy notices in effect at the time during the period covered by the circums","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_585\u002F2026&diff=53118&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-21T12:35:22+00:00","2026-09-21T14:00:18.544802+00:00",7,[18],{"name":19,"type":20},"La Patria S.p.A.","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]