Fino

Italian Data Protection Authority (Garante) · 24 April 2024

Rossi Carta S.r.l.

Insufficient fulfilment of data subjects rights

Fine€30,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
24 April 2024
Country
Italy
Sector
Industry and Commerce
Regulator’s reference
Not recorded
Fino case number
2024/IT/019
Export as PDF

What happened

The DPA fined a controller €30,000 after a data breach occurred due to the usage of an outdated CMS tool that was highly vulnerable to cyber-attacks.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Consent
  • Data subject rights
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/IT/019.