Italy Italy

Ica s.r.l.

30,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2021-12-02.

Rank · Sector
#130
of 597 in Industry and Commerce
Rank · Italy
#165
of 543
Rank · All fines
#897
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2021-12-02
Controller / Processor
Ica s.r.l.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for traffic violations. However, due to a lack of security precautions, it was theoretically possible for unauthorized persons to access personal data stored via the program. For this reason, the DPA found that ICA had failed to implement appropriate technical and organizational measures providing a level of security commensurate with the risk posed to the data subject.

Open original source Links to the regulator's original publication or another source.

Related fines