Region of Tuscany

€10,000

Insufficient legal basis for data processing

Tanggal Keputusan

10 Februari 2022

Wewenang

Italian Data Protection Authority (Garante)

IT

Sektor

Public Sector and Education

Negara

IT

Hukum

GDPR

Status

FINAL

Deskripsi

The Italian DPA has imposed a fine of EUR 10,000 on the Region of Tuscany. The region had notified the DPA of a data breach pursuant to Art. 33 GDPR. The region stated that it had inadvertently published personal data of 3,548 applicants for administrative assistant positions. The data concerned information that the applicants had shared as part of a pre-selection test for the application. The region had mistakenly published a URL through which personal data and the results of the test could be viewed.

Kutipan Hukum

Art. 5Art. 6Art. 2

Masalah & Pelanggaran

Insufficient legal basis for data processing

Tetap Terupdate tentang Penegakan Privasi

Kami menghormati privasi Anda. Satu email per bulan, tidak ada spam, berhenti berlangganan kapan saja.