Italy Italy

Clio S.r.l.

10,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-07-21.

Rank · Sector
#223
of 597 in Industry and Commerce
Rank · Italy
#278
of 543
Rank · All fines
#1,375
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-07-21
Controller / Processor
Clio S.r.l.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 30 (2) GDPR, Art. 2-ter Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 10,000 on Clio S.r.l.. Clio provides and manages a whistleblowing reporting application for various private and public entities. As part of its investigation, the DPA found that Clio had not adequately regulated its relationship with customers. In addition, Clio provided data on whistleblowing reports to customers without a valid legal basis. The DPA considered this to be a violation of Art. 5 (1) a) GDPR and Art. 6 GDPR.
Further, the DPA found that Clio had failed to maintain a register of activity carried out in its role as a processor. The DPA considered this to be a violation of Art. 30 (2) GDPR.

Open original source Links to the regulator's original publication or another source.

Related fines