Municipality of Bologna

€40,000

Insufficient technical and organisational measures to ensure information security

Decision Date

April 29, 2025

Authority

Italian Data Protection Authority (Garante)

IT

Sector

Public Sector and Education

Country

IT

Law

GDPR

Status

FINAL

Description

The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process data, including health data, of childreen with disabilities and special needs. The controller failed to ensure, that the processor had sufficient technical and organisational measures to ensure data security, resulting in a data leak.

Legal Citations

Art. 5 (1)Art. 6 (1)Art. 9 (1)

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.