[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjYB3IXHhlul8inO25ovURyhJWRCAIpWWSm7kbvzhoQw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"d4b2b2c5-0931-4be4-84a2-ac9ea0e95390","italian-dpa-fines-public-entity-for-unlawful-publication-of-sensitive-personal-data","c37f877f-bc06-4751-b12b-dcbf2e3b3352","Italian DPA Fines Public Entity for Unlawful Publication of Sensitive Personal Data","A public sector entity in Italy was fined €10,000 after publishing a ranking list that exposed personal data of 90 individuals, including information inferring disability and financial status, without a lawful basis. The entity incorrectly assumed national law justified the publication, failing to properly assess whether that legal basis applied to ineligible candidates or the specific publication context. This case highlights that a legal mandate to publish data does not automatically extend to all personal data within a document, and organisations must conduct granular lawfulness assessments before disclosure. Sensitive categories of data — such as those revealing disability or financial hardship — carry heightened protection obligations under GDPR Articles 9 and 10, making erroneous publication particularly serious.","**Immediate actions:**\n- Conduct a data minimisation review of all documents intended for public publication to ensure only legally required personal data is disclosed.\n- Remove or redact sensitive inferred data (e.g., disability status, financial situation) from any publicly accessible ranking lists or similar documents before release.\n\n**Policy and process improvements:**\n- Establish a formal legal basis checklist that staff must complete before publishing any document containing personal data, explicitly verifying applicability to all data subjects included.\n- Create and enforce a data publication policy that distinguishes between eligible and ineligible candidates to prevent over-disclosure.\n- Appoint or engage a Data Protection Officer (DPO) to review all public-facing data releases involving special category data.\n\n**Training and governance:**\n- Deliver targeted GDPR training to administrative staff responsible for preparing and publishing public records, focusing on lawful basis and data minimisation principles.\n- Implement a mandatory pre-publication sign-off process requiring DPO or legal counsel approval for documents containing sensitive or special category personal data.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 6 – Lawfulness of Processing","GDPR Article 9 – Processing of Special Categories of Personal Data","GDPR Article 10 – Processing Relating to Criminal Convictions","NIST SP 800-53 PL-4 (Rules of Behaviour)","NIST SP 800-53 RA-3 (Risk Assessment)","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ITIL – Information Security Management (Confidentiality Controls)","ISO\u002FIEC 27001 Annex A.8.2 – Information Classification","published","2026-09-08T14:20:24.629449+00:00","2026-09-08T14:20:23.38+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_551\u002F2026&diff=52963&oldid=52956","garante-per-la-protezione-dei-dati-personali-italy-551-2026-d3529f","Garante per la protezione dei dati personali (Italy) - 551\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]