Italy Italy

City of Rome (Roma capitale)

10,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-01-27.

Rank · Sector
#184
of 357 in Public Sector and Education
Rank · Italy
#273
of 543
Rank · All fines
#1,368
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-01-27
Controller / Processor
City of Rome (Roma capitale)
Sector
Public Sector and Education
Quoted Articles
Art. 5 (1) a), c) GDPR, Art. 6 (1) c), e) Art. 6 (2) GDPR, Art. 6 (3) b) GDPR GDPR, Art. 2-ter (1), (3) Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 10,000 on the city of Rome (Roma capitale). The city had published a document on the municipal website stating that a mother had not paid canteen fees. The document contained personal data of the mother and her minor child. The city stated that, in the absence of a permanent address of the mother to which the notice could have been sent, it had published the document to notify the homeless mother of the debt. However, the DPA found that this could not be considered a sufficient legal basis for processing the personal data, and thus the city unlawfully processed the data.

Open original source Links to the regulator's original publication or another source.

Related fines