Italy Italy

Lazio Region

100,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-12-01.

Rank · Sector
#23
of 213 in Employment
Rank · Italy
#76
of 543
Rank · All fines
#475
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-12-01
Controller / Processor
Lazio Region
Sector
Employment
Quoted Articles
Art. 5 (1) a) GDPR, Art. 6 GDPR, Art. 113 Codice della privacy, Art. 114 Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has fined Lazio Region EUR 100,000. A trade union had filed a complaint with the DPA alleging that the Region had monitored the e-mail accounts of employees of the Region's legal department. The Region had initiated such monitoring on suspicion of possible disclosure of information protected by official secrecy to third parties. The Region stored and analyzed the employees' data for 180 days. The data included not only information related to work, but also personal data of the data subjects concerning their private sphere. During its investigation, the DPA found that the Region at the time did not have a valid legal basis for such a large-scale collection of personal data.

Open original source Links to the regulator's original publication or another source.

Related fines