GTL s.r.l. – €3,000 Fine (Italy, 2020)
GTL s.r.l. was fined for not responding to a person's request for access to their data. This matters because it shows the importance of companies being responsive to such requests. If businesses ignore these requests, they can face penalties.
What happened
GTL s.r.l. failed to respond to a data access request from an individual.
Who was affected
Individuals who requested access to their personal data held by GTL s.r.l. were affected.
What the authority found
The Garante per la protezione dei dati personali found that GTL s.r.l. did not comply with the requirement to respond to data access requests under GDPR.
Why this matters
This case highlights that companies must take data access requests seriously. Failing to do so can lead to fines, emphasizing the need for businesses to have proper procedures in place.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
On 26 November 2018, a former employee of GTL sent a request to have access to its personal data related to some 'registration sheets and printouts' extracted from the tachograph and those 'downloaded from the driver card relating to the journeys made' by the complainant himself during his previous work activities. The company did not respond to this specific access request, so the employee made a complaint to the Garante in order to have access to the mentioned information. Thus the Italian DPA sent a letter with some queries in order to investigate its compliance with the GDPR. Since the company did not respond to the DPA, the DPA sent another letter to demand more information on the data subject request. However, neither this time GTL provided any response. On that basis, the DPA put in place a proper on-site investigation and found out that GTL did not provide the information requested by the complainant because they did not have the mentioned information available either in their paper or digital database. The company affirmed that it replied to the complainant 'orally', without any proof or recording of it. The Italian DPA had to understand whether there was a breach of art. 12 and 15 of the GDPR in relation to an access request of the complainant. The Garante confirmed that, even if there was no information to provide, the company should have responded to the data subject in writing and, if appropriate, with electronic means.
Related Enforcement Actions (0)
No other enforcement actions found for GTL s.r.l. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
2 July 2020
Authority
Garante per la protezione dei dati personali
Fine Amount
€3,000
GDPRhub ID
gdprhub-2634About this data
Cite as: Cookie Fines. GTL s.r.l. - Italy (2020). Retrieved from cookiefines.eu
Last updated: