Italian Data Protection Authority (Garante) · 23 January 2020
Sapienza Università di Roma
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 23 January 2020
- Country
- Italy
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/IT/041
What happened
On December 2020, 23rd the Italian Data Protection Authority imposed a fine of 30 000 Euro on the university of Rome “la Sapienza”, acting as a data controller under the GDPR. The data controller did not process personal data with an appropriate level of security, as required by article 32, read in conjunction with article 33 GDPR.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/041.