Italy Italy

Vimar S.p.A.

15,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2025-09-25.

Rank · Sector
#191
of 597 in Industry and Commerce
Rank · Italy
#232
of 543
Rank · All fines
#1,216
of 3,051

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2025-09-25
Controller / Processor
Vimar S.p.A.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) a), b), c), d) GDPR, Art. 6 GDPR, Art. 13 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without their knowledge. Multiple people within the controller's company used this account for three years.

Open original source Links to the regulator's original publication or another source.

Related fines