Lepida S.c.p.A.
GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-04-29.
Case details
- Authority
- Italian Data Protection Authority (Garante)
- Date
- 2026-04-29
- Controller / Processor
- Lepida S.c.p.A.
- Sector
- Media, Telecoms and Broadcasting
- Quoted Articles
- Art. 5 (1) c), e), f) GDPR, Art. 13 (1) a) GDPR, Art. 25 GDPR, Art. 32 GDPR
- Type of violation
- Non-compliance with general data processing principles
Summary
The Italian DPA has imposed a fine of EUR 100,000 on Lepida S.c.p.A. The controller is a provider of personal identification software. The DPA found multiple GDPR infringements. In 1,800 cases operators of the controller's ID software copied documentation originally used to verify the data subjects' identity. Around 3,000 operators were able to view the transactions of 10,000 data subjects using their ID. In 258 cases operators were able to download documentation containing personal data that was not connected to any ID verification process. Furthermore during the verification process operators of the controller's software had to download documentation, such as health cards and identity documents needed to verify the data subject's identity, onto their computer. This documentation remained on the operator's computer unless it was deleted. The controller further failed to implement adequate automatic checks to ensure the security of the personal data used in the verification process. The controller also failed to implement measures to guarantee the limitation of retention of transaction data. The controller also initially failed to transparently communicate who was responsible for the personal data, stating that joint data controllers were acting for certain types of accounts when they were the sole controller.