Back to Feed
PolicySep 28, 2026

Garante per la protezione dei dati personali (Italy) - 615/2026

Italian DPA fines municipality €5,000 for unlawful disclosure of employee complaint.

Summary

The Italian DPA fined the Municipality of Aprilia €5,000 for unlawfully disclosing an employee's complaint to his employer. The municipality forwarded the employee's certified email, which detailed allegations of mismanagement and bullying, to his employer without a legal basis. This disclosure led to disciplinary proceedings and the employee's dismissal, violating GDPR principles of lawfulness, purpose limitation, and data minimisation.

Full text

Help Garante per la protezione dei dati personali (Italy) - 615/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:24, 28 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators95 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 14:24, 28 September 2026 Garante per la protezione dei dati personali - 615/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Type: Complaint Outcome: n/a Started: Decided: Published: 03.09.2026 Fine: 5000.0 EUR Parties: Comune di Aprilia National Case Number/Name: 615/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a municipality €5,000 for unlawfully disclosing an employee’s complaint to his employer without a legal basis, violating the principles of lawfulness, purpose limitation and data minimisation. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission to report alleged mismanagement and workplace bullying. Instead of arranging the meeting or seeking further information, the controller forwarded the email, including the data subject's identity and email address, to his employer. The controller requested a report on the employee and the allegations raised. Following the disclosure, the employer initiated disciplinary proceedings against the data subject, resulting in his dismissal. The controller subsequently decided not to arrange the requested meeting. The data subject lodged a complaint with the DPA. The controller argued that the disclosure was necessary to assess the credibility of the allegations and exercise its supervisory powers under Article 6(1)(e) GDPR. It also maintained that the employer's subsequent disciplinary decisions were independent of its disclosure. Holding The DPA found that the controller had unlawfully disclosed the data subject's personal data without an appropriate legal basis, in violation of Articles 5(1)(a), (b) and (c) and 6(1)(c) and (e), (2) and (3)(b) GDPR, as well as Article 2-ter of the Italian Data Protection Code. First, the DPA held that the controller's general administrative and supervisory powers did not provide an adequate legal basis for disclosing the data subject's complaint and identity to his employer. The provisions invoked by the controller did not authorise the specific processing operation, contrary to the requirements of Article 6 GDPR and Article 2-ter of the Italian Data Protection Code. Second, the DPA found a violation of the purpose limitation principle under Article 5(1)(b) GDPR. The controller had not demonstrated that forwarding the complaint to the employer was necessary to investigate the allegations. Instead, the employer provided information concerning the data subject's disciplinary history, which was unrelated to the matters he intended to report. Third, the DPA held that the disclosure infringed the data minimisation principle under Article 5(1)(c) GDPR. The controller could have requested further information from the data subject or contacted the employer without revealing his identity. The DPA emphasised that, even without an explicit confidentiality request, the controller should have taken precautions against the foreseeable risk of retaliation. The DPA imposed a €5,000 fine, considering the significant impact on the data subject, the negligent nature of the infringement and the absence of previous violations. It also ordered the publication of the decision. No further corrective measures were imposed because the unlawful processing had ceased to have effect. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10296755] Decision of September 3, 2026 Register of Decisions No. 615 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, setting forth provisions for the alignment of national law with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having reviewed the documentation in the case file; Having considered the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, Web Doc. No. 1098801; Rapporteur: Prof. Ginevra Cerrina Feroni; PREAMBLE 1. Introduction. In a complaint filed on XX, supplemented on XX, Mr. XX alleged a data breach by the Municipality of Aprilia (hereinafter, the “Municipality”), stating, in particular, that on XX, he had sent a certified email (PEC) to the Municipality’s registry “requesting a meeting with the Special Commissioner […] in which he highlighted the reckless and XX management of the […] XX,” and that the aforementioned certified email requesting the meeting had been “forwarded first to two City officials […] and then directly to the Board of Liquidators [of XX, hereinafter also “XX”], which on XX […] in its capacity as employer, notified [the complainant] of the initiation of disciplinary proceedings.” In a subsequent note dated XX, the data subject supplemented the complaint initially filed by providing, in particular, evidence of the termination imposed by XX, which was notified to him “on XX, ref. no. XX, [regarding] the outcome of the disciplinary proceedings, which concluded with dismissal for just cause.” 2. The Preliminary Investigation In a letter dated XX, ref. no. XX, to which reference is made in its entirety, the Municipality responded to a request for information made by this Authority in a letter dated XX, ref. no. XX, stating, in particular, that: - “by Decree of the President of the Republic dated April 23, 2025, the Aprilia City Council was […] dissolved due to mafia infiltration pursuant to Art. 143 of Legislative Decree 267/2000, and the resulting Extraordinary Commission was appointed”; - “The processing of the complainant’s personal data was carried out by the Municipality of Aprilia in the course of performing tasks in the public interest and exercising public authority conferred by law, pursuan

Entities

GDPR (product)Garante per la protezione dei dati personali (vendor)certified email (product)