Comune di Bolzano – €84,000 Fine (Italy, 2021)

€84,000Garante per la protezione dei dati personali13 May 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The municipality of Bolzano was fined EUR 84,000 for monitoring employees' internet use without proper notice and for collecting unnecessary personal data. This case is significant because it underscores the need for employers to respect employee privacy and inform them about data collection. It also shows that less intrusive methods should be used to monitor internet use at work.

What happened

The municipality of Bolzano monitored employees' internet usage without proper notification and collected excessive personal data.

Who was affected

Employees of the municipality whose internet activities were tracked without adequate notice.

What the authority found

The Italian DPA found that the municipality violated GDPR by not minimizing data collection and failing to inform employees about internet monitoring.

Why this matters

This ruling emphasizes that employers must balance security needs with employee privacy rights. Companies should ensure transparency and use less invasive methods for monitoring workplace internet use.

GDPR Articles Cited

Art. 6 GDPR
Art. 9 GDPR
Art. 13 GDPR
Art. 35 GDPR
Art. 5(1)(a) GDPR
Full Legal Summary
Detailed

The Italian DPA (Garante) has fined the municipality of Bolzano EUR 84,000. A former employee of the municipality filed a complaint with the DPA against the municipality. In particular, the former employee complained that the municipality processed personal data related to his internet use during working hours and that he later received a notice of initiation of disciplinary proceedings accusing him of accessing Facebook for more than 40 minutes and YouTube for more than 3 hours during his working hours and of using the municipality's computer for private purposes. The DPA's investigation revealed that the municipality had been using a system to control and filter employees' internet browsing for about a decade, with monthly retention of data and creation of special reports for network security purposes. The system also collected information that had nothing to do with professional activities and, in any case, concerned the private life of the person in question. The DPA finds that the controller thus violated the principle of data minimization, lawfulness and purpose limitation. The controller should rather have taken less intrusive measures to prevent the private use of the Internet. The DPA pointed out that the need to reduce the risk of misuse of Internet navigation cannot lead to the complete elimination of any privacy of the data subject at the workplace, even in cases where the employee uses network services provided by the employer. In addition, the controller had not adequately informed employees about the collection of Internet history, in violation of its obligation under Article 13 of the GDPR. Furthermore, the investigation identified other violations in the processing of data related to employees' requests for extraordinary medical examinations, which were made using a special form. The form provided by the controller had to be checked by the head of the organizational unit, a circumstance that led to the unlawful processing of health data.

Related Enforcement Actions (0)

No other enforcement actions found for Comune di Bolzano in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

13 May 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€84,000

Enforcement Tracker ID

ETid-747

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Comune di Bolzano - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: