Back to Feed
PolicySep 28, 2026

Garante per la protezione dei dati personali (Italy) - 615/2026

Italian DPA fines controller €5,000 for unlawful personal data disclosure.

Summary

The Italian Data Protection Authority (Garante) has fined a controller €5,000 for unlawfully disclosing a data subject's personal data to their employer without a proper legal basis. The DPA found violations of GDPR Articles 5 and 6, citing a lack of adequate legal grounds, breach of purpose limitation, and infringement of data minimization principles. The controller forwarded a complaint and the data subject's identity, leading to the disclosure of unrelated disciplinary history.

Full text

Help Garante per la protezione dei dati personali (Italy) - 615/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 14:24, 28 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators95 edits Tag: Decisions [1.0] Latest revision as of 14:26, 28 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators95 editsmTag: Visual edit Line 114: Line 114: === Holding ====== Holding === The DPA found that the controller had unlawfully disclosed the data subject's personal data without an appropriate legal basis, in violation of Articles 5(1)(a), (b) and (c) and 6(1)(c) and (e), (2) and (3)(b) GDPR, as well as Article 2-ter of the Italian Data Protection Code.The DPA found that the controller had unlawfully disclosed the data subject's personal data without an appropriate legal basis, in violation of [[Article 5 GDPR|Articles 5(1)(a), (b) and (c)]] and [[Article 6 GDPR|6(1)(c) and (e), (2) and (3)(b) GDPR]]. First, the DPA held that the controller's general administrative and supervisory powers did not provide an adequate legal basis for disclosing the data subject's complaint and identity to his employer. The provisions invoked by the controller did not authorise the specific processing operation, contrary to the requirements of [[Article 6 GDPR|Article 6 GDPR]] and Article 2-ter of the Italian Data Protection Code.First, the DPA held that the controller's general administrative and supervisory powers did not provide an adequate legal basis for disclosing the data subject's complaint and identity to his employer. The provisions invoked by the controller did not authorise the specific processing operation, contrary to the requirements of [[Article 6 GDPR]]. Second, the DPA found a violation of the purpose limitation principle under [[Article 5 GDPR|Article 5(1)(b) GDPR]]. The controller had not demonstrated that forwarding the complaint to the employer was necessary to investigate the allegations. Instead, the employer provided information concerning the data subject's disciplinary history, which was unrelated to the matters he intended to report.Second, the DPA found a violation of the purpose limitation principle under [[Article 5 GDPR|Article 5(1)(b) GDPR]]. The controller had not demonstrated that forwarding the complaint to the employer was necessary to investigate the allegations. Instead, the employer provided information concerning the data subject's disciplinary history, which was unrelated to the matters he intended to report. Line 122: Line 122: Third, the DPA held that the disclosure infringed the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The controller could have requested further information from the data subject or contacted the employer without revealing his identity. The DPA emphasised that, even without an explicit confidentiality request, the controller should have taken precautions against the foreseeable risk of retaliation.Third, the DPA held that the disclosure infringed the data minimisation principle under [[Article 5 GDPR|Article 5(1)(c) GDPR]]. The controller could have requested further information from the data subject or contacted the employer without revealing his identity. The DPA emphasised that, even without an explicit confidentiality request, the controller should have taken precautions against the foreseeable risk of retaliation. The DPA imposed a €5,000 fine, considering the significant impact on the data subject, the negligent nature of the infringement and the absence of previous violations. It also ordered the publication of the decision. No further corrective measures were imposed because the unlawful processing had ceased to have effect.The DPA imposed a €5,000 fine, considering the significant impact on the data subject, the negligent nature of the infringement and the absence of previous violations. == Comment ==== Comment == Latest revision as of 14:26, 28 September 2026 Garante per la protezione dei dati personali - 615/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(c) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Type: Complaint Outcome: n/a Started: Decided: Published: 03.09.2026 Fine: 5000.0 EUR Parties: Comune di Aprilia National Case Number/Name: 615/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined a municipality €5,000 for unlawfully disclosing an employee’s complaint to his employer without a legal basis, violating the principles of lawfulness, purpose limitation and data minimisation. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission to report alleged mismanagement and workplace bullying. Instead of arranging the meeting or seeking further information, the controller forwarded the email, including the data subject's identity and email address, to his employer. The controller requested a report on the employee and the allegations raised. Following the disclosure, the employer initiated disciplinary proceedings against the data subject, resulting in his dismissal. The controller subsequently decided not to arrange the requested meeting. The data subject lodged a complaint with the DPA. The controller argued that the disclosure was necessary to assess the credibility of the allegations and exercise its supervisory powers under Article 6(1)(e) GDPR. It also maintained that the employer's subsequent disciplinary decisions were independent of its disclosure. Holding The DPA found that the controller had unlawfully disclosed the data subject's personal data without an appropriate legal basis, in violation of Articles 5(1)(a), (b) and (c) and 6(1)(c) and (e), (2) and (3)(b) GDPR. First, the DPA held that the controller's general administrative and supervisory powers did not provide an adequate legal basis for disclosing the data subject's complaint and identity to his employer. The provisions invoked by the controller did not authorise the specific processing operation, contrary to the requirements of Article 6 GDPR. Second, the DPA found a violation of the purpose limitation principle under Article 5(1)(b) GDPR. The controller had not demonstrated that forwarding the complaint to the employer was necessary to investigate the allegations. Instead, the employer provided information concerning the data subject's disciplinary history, which was unrelated to the matters he intended to report. Third, the DPA held that the disclosure infringed the data minimisation principle under Article 5(1)(c) GDPR. The controller could have requested further information from the data subject or contacted the employer without revealing his identity. The DPA emphasised that, even without an explicit confidentiality request, the controller should have taken precautions against the foreseeable risk of retaliation. The DPA imposed a €5,000 fine, considering the significant impact on the data subject, the negligent nature of the infringement and the absence of previous violations. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10296755] Decision of September 3, 2026 Register of Decisions No. 615 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale

Entities

Garante per la protezione dei dati personali (vendor)