Italy Italy

Region of Lombardy

20,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-10-26.

Rank · Sector
#126
of 357 in Public Sector and Education
Rank · Italy
#203
of 543
Rank · All fines
#1,089
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-10-26
Controller / Processor
Region of Lombardy
Sector
Public Sector and Education
Quoted Articles
Art.5 GDPR, Art. 6 (1) c), e) GDPR, Art. 9 GDPR, Art. 2-ter Codice della privacy, Art. 2-septies (8) Codice della privacy
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 20,000 on the Region of Lombardy. In the context of the sale of company shares held by the region, personal data of employees of the companies were unlawfully disclosed. Employees discovered that when they entered their first name and surname in a search engine, a link appeared to the draft contract between the Region and the acquiring company, containing personal data such as income information, employment information, etc. of employees.

Open original source Links to the regulator's original publication or another source.

Related fines