Italy Italy

Comune di Palermo

40,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-04-15.

Rank · Sector
#75
of 356 in Public Sector and Education
Rank · Italy
#132
of 543
Rank · All fines
#790
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-04-15
Controller / Processor
Comune di Palermo
Sector
Public Sector and Education
Quoted Articles
Art. 5 (1) f) GDPR, Art. 25 GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA (Garante) has imposed a fine of EUR 40,000 on the municipality of Palermo. A data subject had filed a complaint with the Italian DPA against the municipality of Palermo. His complaint was based on the fact that his personal data from a food subsidy application he had submitted had been acquired by an unauthorized person and processed for his own purposes. As the DPA determined in the course of its investigations, such processing had occurred because the municipality had not implemented adequate technical and organizational measures to ensure the security and confidentiality of the processing.

Open original source Links to the regulator's original publication or another source.

Related fines