GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Roma Capitale

Country
Italy
Fine
500,000 EUR
Date
2020-12-17
Sector
Public administration
Articles
Art. 5, par.1, lett a)art.13art. 14art. 28, par.3 andart. 32 of GDPR

Failure to comply with general data processing principles, the obligation to provide sufficient information to the data subject, provide a contract or other legal act for the processing by the processor, measures to ensure information security.

The case regards the improper use cof the app for the reservation of appointments and the provision of services carried out by the public administration. The app made it possible, in fact, to acquire and store on the servers of Roma Capitale, for a long period of time, numerous data of the users relating to bookings and of the staff employed in the management of appointments. All the operations were carried out without either the users or the employees having received full information on the processing carried out by the app. The Italian DPA also found inadequate the technical and organisational measures implemented by the Public administration, which had not regulated the relationship with the company providing the app.

Additional information

RP Legal and Tax