Region of Lombardy

€20,000

Insufficient legal basis for data processing

Dato for beslutning

26. oktober 2023

Myndighet

Italian Data Protection Authority (Garante)

IT

Sektor

Public Sector and Education

Land

IT

Lov og rett

GDPR

Status

FINAL

Beskrivelse

The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the companies were unlawfully disclosed. Employees discovered that when they entered their first name and surname in a search engine, a link appeared to the draft contract between the Region and the acquiring company, containing personal data such as income information, employment information, etc. of employees.

Juridiske henvisninger

Art.5Art. 6 (1)Art. 9Art. 2Art. 2

Problemer og overtredelser

Insufficient legal basis for data processing

Hold deg oppdatert om håndheving av personvern

Vi respekterer personvernet ditt. Én e-post per måned, ingen spam, avmelding når som helst.