Istat โ Violation Found (Italy, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Italy's data protection authority found that Istat did not properly handle data processing authorization related to pseudonymisation. This is important because it shows that organizations must follow strict rules when processing personal data. Although no fines were imposed, the authority emphasized the need for compliance with data protection standards.
What happened
Istat was found to have issues with data processing authorization and pseudonymisation techniques.
Who was affected
Individuals whose data was processed by Istat.
What the authority found
The authority identified shortcomings in Istat's data processing practices, although no specific violations were classified.
Why this matters
This finding serves as a reminder for organizations to ensure they have proper authorization and techniques in place when handling personal data, reinforcing the importance of compliance with data protection laws.
GDPR Articles Cited
National Law Articles
With the provision No. 10 of 23 january 2020, the Italian Data Protection Authority assessed Istat's request for authorization to process data, pursuant to article 2-quinquiesdecies of the Privacy Code (Legislative Decree 196/2003). The Authority: *has informed Istat that, from a methodological point of view, the data controller is required to implement adequate technical and organizational measures to guarantee and demonstrate that the treatment carried out is in compliance with the discipline; *has prescribed to adopt suitable pseudonymisation techniques to guarantee the effectiveness of the principles of minimization and limitation of conservation; *has prescribed to integrate the general census plan with an indication of the methods for returning to the municipalities, in aggregate form, the information collected according of the census; *has prescribed to integrate the impact assessment on the protection of personal data relating to statistical works related to the creation of the permanent Census with the indication of the probabilities, through specific metrics, of re-identification of the interested parties. *required to Istat to communicate, within 120 days from the notification of this provision, what initiatives it has undertaken or intends to undertake to implement the prescriptions indicated in this provision, especially regarding the techniques of pseudonymisation, and to still provide adequately documented feedback; any lack of feedback may result in the application of the administrative fine pursuant to art. 83, par. 5 of the Regulation. The Authority authorized Istat to carry out the processing of personal data necessary for the creation of the permanent census, highlighting the persistence of problems and giving explicit warning and prescriptions. The Data Protection Authority indicates to Istat (national census body) that, in order to carry out the permanent census, it must adopt adequate pseudonymisation techniques within 4 months to avoid ide
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Istat in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Decision Date
23 January 2020
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-2084About this data
Cite as: Cookie Fines. Istat - Italy (2020). Retrieved from cookiefines.eu
Last updated: