Italian Data Protection Authority (Garante) · 22 July 2021
Roma Capitale
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 22 July 2021
- Country
- Italy
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2021/IT/034
What happened
The Italian DPA fined the Municipality of Rome €800.000 for failing to inform users of its parking meters about the processing of their data, and private companies acting as processors of how to adequately process data collected through them. It also held the municipality acted in violation of the principles of limitation of conservation and data protection by design and default.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 28ProcessorRead →
- Art. 32Security of processingRead →
- Accountability
- Data principles
- Data security
- Processor obligations
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/IT/034.