Italian Data Protection Authority (Garante) · 3 July 2026
University of Pisa
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 3 July 2026
- Country
- Italy
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/091
What happened
The Italian DPA has imposed a fine of EUR 15,000 on the University of Pisa. On the controller's website other students could access a list of students registered for exams and change information on the exam registration session. In some cases this led to the cancellation of the registration. Inadequate controls on the student IDs of the website's users made this possible.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a)Read →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Accountability
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/091.