[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fy9s_ubGYOn_-XtSiEH8d_KbqZsoxlDFm-jK1PlHsMT4":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"2f5ffb78-b267-479b-b3f2-ef4d2b61f9fd","Garante per la protezione dei dati personali (Italy) - 619\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-619-2026-cd9547","← Older revision Revision as of 12:19, 14 September 2026 Line 118: Line 118: The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12\u002F24hrs and updated the signage. The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12\u002F24hrs and updated the signage. === Holding === === Holding === The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves. The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves. Line 127: Line 125: In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality. In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality. Therefore, the DPA held that the controller was in violation of Articles 5(1)(a), and (e), Article 6(1)(c) and (e), Article 12 and [[Article 13 GDPR|Article 13 GDPR]] and fined the controller €8,000. Therefore, the DPA held that the controller was in violation of [[Article 5 GDPR|Articles 5(1)(a), and (e)]], [[Article 6 GDPR|Article 6(1)(c) and (e)]], [[Article 12 GDPR|Article 12]] and [[Article 13 GDPR]] and fined the controller €8,000. == Comment == == Comment ==","Italy's Garante per la protezione dei dati personali has fined an entity managing sports facilities €8,000 for violating GDPR. The DPA found that the processing of swimming pool user data via camera surveillance was not justified, even with a union agreement, and lacked transparency, particularly in sensitive areas like dressing rooms. The controller has since deactivated cameras, revised retention periods, and updated signage.","Italian DPA fines swimming pool operator €8,000 for GDPR violations related to camera surveillance.","Help Garante per la protezione dei dati personali (Italy) - 619\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:18, 14 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 edits Tag: Decisions [1.0] Latest revision as of 12:19, 14 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators70 editsmTag: Visual edit Line 118: Line 118: The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12\u002F24hrs and updated the signage.The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12\u002F24hrs and updated the signage. === Holding ====== Holding === The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves.The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves. Line 127: Line 125: In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality.In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality. Therefore, the DPA held that the controller was in violation of Articles 5(1)(a), and (e), Article 6(1)(c) and (e), Article 12 and [[Article 13 GDPR|Article 13 GDPR]] and fined the controller €8,000.Therefore, the DPA held that the controller was in violation of [[Article 5 GDPR|Articles 5(1)(a), and (e)]], [[Article 6 GDPR|Article 6(1)(c) and (e)]], [[Article 12 GDPR|Article 12]] and [[Article 13 GDPR]] and fined the controller €8,000. == Comment ==== Comment == Latest revision as of 12:19, 14 September 2026 Garante per la protezione dei dati personali - 619\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(e) GDPR Article 6(1)(c) GDPR Article 6(1)(e) GDPR Article 12 GDPR Article 13 GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: Fine: 8000.0 EUR Parties: Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento National Case Number\u002FName: 619\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA fined the controller €8,000 for installing surveillance cameras inside dressing rooms of a swimming pool without a proper legal basis, against the principles, and inadequate information about the processing operations. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA investigated the Special Company for the Management of Sports Facilities of the Municipality of Trento (the controller) after press reports revealed the implementation and use of surveillance cameras in the dressing room of a public swimming pool. During its investigation, the DPA found that the controller installed surveillance cameras after repeated incidents of wallet and phone theft of individuals using the pool. The controller disclosed the use of surveillance by cameras through signage at the entrance of the pool, and on their website. The controller had installed the cameras to record the lockers where personal items are stored. No recording of the changing rooms, showers or toilets was undertaken, and footage was stored for 72 hrs. The controller emphasised that the processing of such data was designated to two individuals who are authorised only to process the recordings at the request of judicial or public security authorities. The DPA contacted the controller about the possible violation of the GDPR, and the controller implemented technical and organisational measures to comply with the instructions given. Particularly, the controller deactivated the cameras and the subsequent processing operations, revised the retention periods of the footage from 72 hrs to 12\u002F24hrs and updated the signage. Holding The DPA found that although the controller entered a union agreement, the controller’s purpose of protecting the assets of individuals and the protection of fundamental rights and freedoms of data subjects does not justify the processing of the swimming pool user’s personal data. Particularly, because data subjects are not able to regulate the matter themselves. The DPA further found that for the principles of necessity, storage limitation and proportionality, the controller failed to demonstrate that it assessed, prior to the use of such surveillance, the potential use of less intrusive alternatives which could have been equally effective in protecting the assets of users, and a necessary retention period. In addition to the above, the DPA found that the signage containing the general privacy notice found at the entrance of the controller’s premises does not achieve the necessary level of transparency. This is especially the case where the surveillance is being undertaken in areas such as dressing rooms where there is a greater legitimate expectation of confidentiality. Therefore, the DPA held that the controller was in violation of Articles 5(1)(a), and (e), Article 6(1)(c) and (e), Article 12 and Article 13 GDPR and fined the controller €8,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Newsletter of September 11, 2026 [Web Doc. No. 10294255] Decision of September 3, 2026 Register of Decisions No. 619 of September 3, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC, “General Data Protection Regulation” (hereinafter “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection,” which sets","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_619\u002F2026&diff=53007&oldid=53006","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-14T12:19:00+00:00","2026-09-14T14:00:18.621214+00:00",7,[18,21],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor",{"name":22,"type":23},"GDPR","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,34,39],{"category":31},{"id":32,"icon":26,"name":22,"slug":33},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":35},{"id":36,"icon":26,"name":37,"slug":38},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":40},{"id":41,"icon":26,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]