Regione Lazio

€75,000

Insufficient data processing agreement

Date de décision

14 janvier 2021

Autorité

Italian Data Protection Authority (Garante)

IT

Secteur

Public Sector and Education

Pays

IT

Droit

GDPR

Statut

FINAL

Description

The Italian DPA (Garante) has fined Regione Lazio (Lazio Region) EUR 75,000 for failing to designate Capodarco, the company it entrusted with the management of reservations for healthcare services in 1999, as a data processor. The controller had not entered into a contract with Capodarco that would have governed its role as data processor in accordance with the requirements of data protection law. Thus, a proper contract for commissioned processing had not been concluded until 2019, which meant that data had been processed unlawfully for a period of about 20 years.

Citations légales

Art. 5 (2)Art. 28

Questions et violations

Insufficient data processing agreement

Restez informé sur l'application de la législation en matière de protection de la vie privée

Nous respectons votre vie privée. Un courriel par mois, pas de spam, désabonnement à tout moment.