Lisbon City Council

€1,250,000

Insufficient legal basis for data processing

Ngày ra quyết định

21 tháng 12, 2021

Thẩm quyền

Portuguese Data Protection Authority (CNPD)

PT

Ngành

Public Sector and Education

Quốc gia

PT

Luật

GDPR

Trạng thái

FINAL

Mô tả

The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since 2018. The municipality had sent 111 notifications about demonstrations to various departments and offices within the municipality, as well as to third parties, to ensure that they could properly perform their public duties. The notices contained, among other things, sensitive data of the demonstrators and organizers of the demonstrations. The data revealed, among other things, the political opinion , religious or philosophical beliefs or sexual orientation of the data subjects. The DPA found that the transfer of the data would not have been necessary for the entities to properly perform their public tasks. Thus, the processing took place without a sufficient legal basis. In addition, the DPA found that the municipality had carried out the processing without informing the data subjects, without establishing a policy for the retention of their personal data, and without conducting a data protection impact assessment.

Trích dẫn pháp lý

Art. 5 (1)Art. 6Art. 9 (1)Art. 13 (1)Art. 35 (3)

Vấn đề & Vi phạm

Insufficient legal basis for data processing

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.