[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw7ld_1j2tfOKItqsVSOdoJasnNbwCEXC9_C_GoYIyj4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"b903126d-e920-453a-973f-f9f094697c8a","italian-municipality-fined-for-gdpr-violations-in-traffic-camera-data-collection","677b6651-6365-4184-934e-b65ccff569f1","Italian Municipality Fined for GDPR Violations in Traffic Camera Data Collection","The Municipality of Vasto violated the GDPR data minimisation principle by capturing more personal data than necessary through its traffic camera system, going beyond the intended purpose of recording license plates. Additionally, the municipality failed to conduct a Data Protection Impact Assessment (DPIA) prior to deploying a high-risk processing activity, a mandatory requirement under GDPR Article 35. This case highlights how public sector bodies often underestimate the privacy implications of surveillance technologies. Non-compliance not only results in financial penalties but also erodes public trust in how governments handle citizen data.","**Immediate actions:**\n- Audit all active data collection systems to verify that only the minimum necessary personal data is being captured and retained.\n- Conduct or update DPIAs for any existing processing activities that involve surveillance, biometrics, or large-scale personal data before continuing operations.\n\n**Long-term improvements:**\n- Embed a 'privacy by design and by default' process into all procurement and deployment workflows for new technologies, including cameras and sensors.\n- Establish a mandatory DPIA review gate for any new public-facing data processing project before project sign-off.\n- Train all staff involved in technology procurement and deployment on GDPR obligations, particularly data minimisation and DPIA requirements.\n\n**Governance & oversight measures:**\n- Appoint or empower a qualified Data Protection Officer (DPO) to review and approve all data collection initiatives involving public spaces.\n- Implement a regular compliance calendar that schedules periodic reviews of data processing activities, data subject notices, and existing DPIAs.",[12,13,14,15,16,17,18,19],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 35 – Data Protection Impact Assessment","GDPR Article 13 – Information to be provided to data subjects","NIST Privacy Framework PR.DS-P1 – Data Processing Ecosystem Management","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","ISO\u002FIEC 29134 – Guidelines for Privacy Impact Assessment","published","2026-07-21T20:20:21.991001+00:00","2026-07-21T20:20:21.689+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_457\u002F2026&diff=52430&oldid=52427","garante-per-la-protezione-dei-dati-personali-italy-457-2026-53a425","Garante per la protezione dei dati personali (Italy) - 457\u002F2026",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]