Italy Italy

Lepida S.c.p.A.

100,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2026-04-29.

Rank · Sector
#112
of 370 in Media, Telecoms and Broadcasting
Rank · Italy
#85
of 544
Rank · All fines
#498
of 3,068

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2026-04-29
Controller / Processor
Lepida S.c.p.A.
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 5 (1) c), e), f) GDPR, Art. 13 (1) a) GDPR, Art. 25 GDPR, Art. 32 GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 100,000 on Lepida S.c.p.A. The controller is a provider of personal identification software. The DPA found multiple GDPR infringements. In 1,800 cases operators of the controller's ID software copied documentation originally used to verify the data subjects' identity. Around 3,000 operators were able to view the transactions of 10,000 data subjects using their ID. In 258 cases operators were able to download documentation containing personal data that was not connected to any ID verification process. Furthermore during the verification process operators of the controller's software had to download documentation, such as health cards and identity documents needed to verify the data subject's identity, onto their computer. This documentation remained on the operator's computer unless it was deleted. The controller further failed to implement adequate automatic checks to ensure the security of the personal data used in the verification process. The controller also failed to implement measures to guarantee the limitation of retention of transaction data. The controller also initially failed to transparently communicate who was responsible for the personal data, stating that joint data controllers were acting for certain types of accounts when they were the sole controller.

Open original source Links to the regulator's original publication or another source.

Related fines