Back to Feed
PolicySep 14, 2026

Garante per la protezione dei dati personali (Italy) - 619/2026

Italy's Garante fines a sports facility €8,000 for installing surveillance cameras in pool dressing rooms.

Summary

Italy's Garante per la protezione dei dati personali has fined the Special Company for the Management of Sports Facilities of the Municipality of Trento €8,000. The fine was issued because surveillance cameras were installed in the dressing rooms of a public swimming pool without a proper legal basis, violating GDPR principles. The Garante found that the company failed to demonstrate the necessity and proportionality of the surveillance, and that the signage provided was inadequate, especially for an area with a high expectation of privacy.

Full text

Help Garante per la protezione dei dati personali (Italy) - 619/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:18, 14 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:18, 14 September 2026 Garante per la protezione dei dati personali - 619/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(e) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Article 12 GDPR Article 13 GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: Fine: 8000.0 EUR Parties: Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento National Case Number/Name: 619/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the controller €8,000 for installing surveillance cameras inside dressing rooms of a swimming pool without a proper legal basis, against the principles, and inadequate information about the processing operations. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA investigated the Special Company for the Management of Sports Facilities of the Municipality of Trento (the controller) after press reports revealed the implementation and use of surveillance cameras in the dressing room of a public swimming pool. During its investigation, the DPA found that the controller installed surveillance cameras after repeated incidents of wallet and phone theft of individuals using the pool. The controller disclosed the use of surveillance by cameras through signage at the entrance of the pool, and on their website. The controller had installed the cameras to record the lockers where personal items are stored. No recording of the changing rooms, showers or toilets was undertaken, and footage was stored for 72 hrs. The controller emphasised that the processing of such data was designated to two individuals who are authorised only to process the recordings at the request of judicial or public security authorities. The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12/24hrs and updated the signage. Holding The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves. The DPA further found that for the principles of necessity, storage limitation and proportionality, the controller failed to demonstrate that it assessed, prior to the use of such surveillance, the potential use of less intrusive alternatives which could have been equally effective in protecting the assets of users, and a necessary retention period. In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality. Therefore, the DPA held that the controller was in violation of Articles 5(1)(a), and (e), Article 6(1)(c) and (e), Article 12 and Article 13 GDPR and fined the controller €8,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Newsletter of September 11, 2026 [Web Doc. No. 10294255] Decision of September 3, 2026 Register of Decisions No. 619 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection,” which sets forth provisions for the adaptation of the national legal system to Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC” (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at the performance of the tasks and the exercise of the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation of the Data Protection Authority No. 1/2019”); Having regard to the documentation on file; Having regard to the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, web doc. No. 1098801; Rapporteur: Dr. Agostino Ghiglia; WHEREAS 1. Introduction. The Authority has learned from press reports and several complaints that video surveillance cameras were allegedly found inside a locker room, intended for use by users, at a swimming pool managed by the Special Agency for the Management of Sports Facilities of the Municipality of Trento (A.S.I.S. — hereinafter, the “Agency”). 2. The Preliminary Investigation. In response to two requests for information made pursuant to Article 157 of the Code (see letters dated October 29, 2025, Ref. No. 0143564, and January 13, 2026, Ref. No. 0003526), the Company, in notes Ref. Nos. 19111 dated November 5, 2025, and 1057 dated January 19, 2026, stated, in particular, that: - “[…] the incident pertains to the Trento Nord Sports Center—Gardolo district, managed [by the Company]. Video surveillance at this facility, indicated by appropriate signage at the entrance […], covers the lockers […] designated for users, where they store their personal belongings for the time necessary to engage in sports activities”; - “this is in no way a matter of monitoring employees […], who are incidentally ‘captured’ by this video system, but rather of Users […] of the outdoor pool”; - “The changing rooms, showers, and restrooms are not subject to video recording in any way”; - “near the lockers […] there are no benches or chairs that might encourage those undressing to sit there and thus be captured on video”; - there are “signs posted at the entrance to the facility [… and] the data is retained for 72 hours”; - “These recordings are not viewed in real time on a peripheral monitor, and […] the controller […] has designated two individuals responsible for processing personal data from the video surveillance system […]. These two officials may engage in data processing only at the reques

Entities

Garante per la protezione dei dati personali (vendor)surveillance cameras (product)