Clio S.r.l.

€10,000

Insufficient legal basis for data processing

Päätöspäivä

21. heinäkuuta 2022

Viranomainen

Italian Data Protection Authority (Garante)

IT

Ala

Industry and Commerce

Maa

IT

Laki

GDPR

Tila

FINAL

Kuvaus

The Italian DPA has imposed a fine of EUR 10,000 on Clio S.r.l.. Clio provides and manages a whistleblowing reporting application for various private and public entities. As part of its investigation, the DPA found that Clio had not adequately regulated its relationship with customers. In addition, Clio provided data on whistleblowing reports to customers without a valid legal basis. The DPA considered this to be a violation of Art. 5 (1) a) GDPR and Art. 6 GDPR. Further, the DPA found that Clio had failed to maintain a register of activity carried out in its role as a processor. The DPA considered this to be a violation of Art. 30 (2) GDPR.

Oikeudelliset viittaukset

Art. 5 (1)Art. 6Art. 30 (2)Art. 2

Asiat ja rikkomukset

Insufficient legal basis for data processing

Pysy ajan tasalla yksityisyyden suojan valvonnasta

Kunnioitamme yksityisyyttäsi. Yksi sähköpostiviesti kuukaudessa, ei roskapostia, peruuta tilaus milloin tahansa.