Italian Data Protection Authority (Garante) · 11 April 2024
Innova Camara
Insufficient technical and organisational measures to ensure information security
Fine€25,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 11 April 2024
- Country
- Italy
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2024/IT/040
What happened
The DPA fined a processor €25,000 for not deleting a backup copy containing personal data of over 22,000 users after a system update and for using weak password encryption.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
The source doesn’t list which GDPR articles were involved.
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/IT/040.