Region of Lombardy

€20,000

Insufficient legal basis for data processing

Datum odločitve

26. oktober 2023

Organ

Italian Data Protection Authority (Garante)

IT

Sektor

Public Sector and Education

Država

IT

Zakon

GDPR

Status

FINAL

Opis

The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the companies were unlawfully disclosed. Employees discovered that when they entered their first name and surname in a search engine, a link appeared to the draft contract between the Region and the acquiring company, containing personal data such as income information, employment information, etc. of employees.

Pravne navedbe

Art.5Art. 6 (1)Art. 9Art. 2Art. 2

Vprašanja in kršitve

Insufficient legal basis for data processing

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.