Associazione Rousseau - Movimento 5 stelle (Italian political party)
- Country
- Italy
- Fine
- 50,000 EUR
- Date
- 2019-04-04
- Sector
- Public sector - political association
- Articles
- Art. 32 GDPR
This fine concerns insufficient technical and organisational measures
The Rousseau platform, created by the Italian political party "Movimento 5 Stelle" (“5 Stelle”), where registered users were able to designate, among others, candidates for the EU parliamentary election, had suffered a data breach during the summer 2017, that led the Italian data protection authority ("Italian DPA") to require to 5 Stelle the implementation of a number of security measures, in addition to the obligation to update the privacy information notice, in order to guarantee transparency to the data processing activities performed. While the update of the privacy information notice was timely completed, the Italian DPA found the lack of implementation of the security measures provided by GDPR. In particular, the Italian DPA ascertained that the tracking of log files was not active for all the sections of the Rousseau Platform; the managing of said website, moreover, was allowed through a system administrator account shared among 5 people, a circumstance that implied the impossibility for the data controller to monitor the activities done by each person involved in said processing and that was qualified as very serious and unacceptable, considering the possibility for such persons to access to special categories of personal data, such as those on political opinion. Finally, also the security measures aimed at anonymizing the activities performed through the e-voting system were considered not to be adequate. Authority: Italian Data Protection Authority
