Roma Capitale
- Country
- Italy
- Fine
- 350,000 EUR
- Date
- 2021-02-11
- Sector
- Public administration
- Articles
- Art. 5art. 6art. 28 andart. 32 of GDPR
Failure to comply with general data processing principles, insufficient legal basis for data processing, failure to stipulate a data processing agreement, insufficient l measures to ensure information security.
The case is related to the the permits for access and parking issued by Roma Capitale through its provider. These permits, to be displayed on the vehicles, were provided with a QR code, which allows anyone, through the use of a generic application for mobile device, to decode the code and to access personal data relating to the holder of the permit or its user, without a proper legas basis. For this reason, Roma Capitale has been found responsible for the failure to adopt technical and organisational measures suitable to guarantee a level of security adequate to the risks, for the illegitimate diffusion of pesonal data and for the failure to stipulate a data processing agreement pursuant to article 28 GDPR with its provider/data processor.
