Italy Italy

Benetton Group S.r.l.

240,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-04-27.

Rank · Sector
#59
of 595 in Industry and Commerce
Rank · Italy
#55
of 543
Rank · All fines
#323
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-04-27
Controller / Processor
Benetton Group S.r.l.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) c), e) GDPR, Art. 32 (1) b), d) GDPR, Art. 32 (2) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 240,000 on Benetton Group S.r.l.. The controller had stored a large amount of customer data indefinitely. The DPA also found that the administrative database of employees of stores from 7 countries were accessible with a single password. The DPA considered this to be a breach of the obligation to implement appropriate technical and organizational measures to protect personal data. In assessing the fine, the DPA considered the fact that a very large number of people were affected by the data protection violations as an aggravating factor.

Open original source Links to the regulator's original publication or another source.

Related fines