Italy Italy

Dedalus Italia S.p.A.

32,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-02-26.

Rank · Sector
#128
of 597 in Industry and Commerce
Rank · Italy
#158
of 543
Rank · All fines
#877
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2026-02-26
Controller / Processor
Dedalus Italia S.p.A.
Sector
Industry and Commerce
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA has imposed a fine of EUR 32,000 on Dedalus Italia S.p.A. The controller, who operates an employee portal used in the healthcare sector, carried out maintenance work on the application, but failed to implement adequate technical and organisational security measures. This resulted in employees of the portal's users being able to access the personal data of their colleagues that they should not have been able to access.

Open original source Links to the regulator's original publication or another source.

Related fines