Autostrade per l'Italia spa

€1,000,000

Non-compliance with general data processing principles

결정 날짜

2023년 6월 22일

권한

Italian Data Protection Authority (Garante)

IT

섹터

Transportation and Energy

국가

IT

법률

GDPR

상태

FINAL

설명

The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx. 100,000 registered users of the toll reimbursement app 'Free to X.' A consumer organization reported problems with the service, which provides toll refunds for delays caused by roadworks, to the DPA. The DPA found that Autostrade held the position of the data controller, instead of a processor, as stated in the documents governing the relationship between 'ASPI' and 'Free to X', the company that develops and operates the app, as well as in the information notice given to users. In fact, 'ASPI', as the operator of the highway network, was responsible for determining the reimbursement mechanism, the type of compensation measures, the processing and the causes of delays due to road works. 'Free to X' was only tasked with implementing the service. This incorrect assignment of privacy roles resulted in the notice to users being incorrect. The notice should have included the actual identity of the controller, namely ASPI, as well as all the necessary information for proper and transparent processing in accordance with data protection laws. The DPA finally found that ASPI also violated the GDPR by not designating Free to X as a processor.

법적 인용

Art. 5 (1)Art. 13Art. 28

문제 및 위반 사항

Non-compliance with general data processing principles

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.