Encore Thermoengineering s.r.l.

€20,000

Non-compliance with general data processing principles

Decision Date

13 de março de 2025

Authority

Italian Data Protection Authority (Garante)

IT

Sector

Industry and Commerce

Country

IT

Law

GDPR

Status

FINAL

Description

The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The controller never hired those subjects. However, the controller failed to comply with the principle of data minimization by storing the data without a time limit, and failed to adequately respond to a request for erasure by the data subjects.

Legal Citations

Art. 5 (1)Art. 6Art. 17

Issues & Violations

Non-compliance with general data processing principles

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.