Istat โ€“ Violation Found (Italy, 2020)

Violation Found
Garante per la protezione dei dati personali23 January 2020Italy
final
ePrivacy
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Italy's data protection authority found that Istat did not properly handle data processing authorization related to pseudonymisation. This is important because it shows that organizations must follow strict rules when processing personal data. Although no fines were imposed, the authority emphasized the need for compliance with data protection standards.

What happened

Istat was found to have issues with data processing authorization and pseudonymisation techniques.

Who was affected

Individuals whose data was processed by Istat.

What the authority found

The authority identified shortcomings in Istat's data processing practices, although no specific violations were classified.

Why this matters

This finding serves as a reminder for organizations to ensure they have proper authorization and techniques in place when handling personal data, reinforcing the importance of compliance with data protection laws.

GDPR Articles Cited

Art. 83(5) GDPR

National Law Articles

AI-identified

Art. 2-quinquiesdecies Codice Privacy
Source verified 9 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

With the provision No. 10 of 23 january 2020, the Italian Data Protection Authority assessed Istat's request for authorization to process data, pursuant to article 2-quinquiesdecies of the Privacy Code (Legislative Decree 196/2003). The Authority: *has informed Istat that, from a methodological point of view, the data controller is required to implement adequate technical and organizational measures to guarantee and demonstrate that the treatment carried out is in compliance with the discipline; *has prescribed to adopt suitable pseudonymisation techniques to guarantee the effectiveness of the principles of minimization and limitation of conservation; *has prescribed to integrate the general census plan with an indication of the methods for returning to the municipalities, in aggregate form, the information collected according of the census; *has prescribed to integrate the impact assessment on the protection of personal data relating to statistical works related to the creation of the permanent Census with the indication of the probabilities, through specific metrics, of re-identification of the interested parties. *required to Istat to communicate, within 120 days from the notification of this provision, what initiatives it has undertaken or intends to undertake to implement the prescriptions indicated in this provision, especially regarding the techniques of pseudonymisation, and to still provide adequately documented feedback; any lack of feedback may result in the application of the administrative fine pursuant to art. 83, par. 5 of the Regulation. The Authority authorized Istat to carry out the processing of personal data necessary for the creation of the permanent census, highlighting the persistence of problems and giving explicit warning and prescriptions. The Data Protection Authority indicates to Istat (national census body) that, in order to carry out the permanent census, it must adopt adequate pseudonymisation techniques within 4 months to avoid ide

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Istat in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

23 January 2020

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-2084

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Istat - Italy (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: