Italian Data Protection Authority (Garante) · 18 June 2026
Edizioni Grandangolo di Giuseppe Castaldo
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 18 June 2026
- Country
- Italy
- Sector
- Individuals and Private Associations
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/088
What happened
The Italian DPA has imposed a fine of EUR 2,075 on Edizione Grandangolo di Giuseppe Castaldo. The data subject filed a complaint stating that even after requesting the deletion of their personal data their name and images remained accessible in an online news publication. The publication had published this personal data while the data subject was still a minor. The subsequent investigation found that the publication had been the victim of a cyber attack due to inadequate technical security measures, a fact which it had not reported to the relevant authority. The publication also lacked a privacy policy.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 24Responsibility of the controllerRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Accountability
- Data breach
- Data principles
- Data security
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/088.