Comune di Palermo

€40,000

Insufficient technical and organisational measures to ensure information security

Decision Date

15 de abril de 2021

Authority

Italian Data Protection Authority (Garante)

IT

Sector

Public Sector and Education

Country

IT

Law

GDPR

Status

FINAL

Description

The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of Palermo. His complaint was based on the fact that his personal data from a food subsidy application he had submitted had been acquired by an unauthorized person and processed for his own purposes. As the DPA determined in the course of its investigations, such processing had occurred because the municipality had not implemented adequate technical and organizational measures to ensure the security and confidentiality of the processing.

Legal Citations

Art. 5 (1)Art. 25Art. 32

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.