Region of Lombardy
€20,000
Insufficient legal basis for data processing
決定日期
2023年10月26日
權限
Italian Data Protection Authority (Garante)
IT
部門
Public Sector and Education
國家
IT
法律
GDPR狀態
FINAL說明
The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the companies were unlawfully disclosed. Employees discovered that when they entered their first name and surname in a search engine, a link appeared to the draft contract between the Region and the acquiring company, containing personal data such as income information, employment information, etc. of employees.
法律引文
Art.5Art. 6 (1)Art. 9Art. 2Art. 2
問題與違規
Insufficient legal basis for data processing