Italian Data Protection Authority (Garante) · 14 July 2026
Municipality of Rieti
Non-compliance with general data processing principles
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 14 July 2026
- Country
- Italy
- Sector
- Public Sector and Education
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/104
What happened
The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Rieti. A file containing the personal data of 2,000 citizens was published on the controller's website. This file contained the personal data of 50 employees and approximately 31,000 tax accounts belonging to both individuals and legal entities. The data included tax IDs, names, places of residence, and land registered in their name. The controller published details of the data breach in the local newspaper, but this failed to meet the standard by which data subjects affected by a breach should be informed. The authority stated that these incidents are to be regarded as a single act and that they no longer affect the data subjects..
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(1)Read →
- Art. 24Responsibility of the controllerRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Accountability
- Data breach
- Data principles
- Data security
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/104.