GTL s.r.l. – €3,000 Fine (Italy, 2020)

€3,000Garante per la protezione dei dati personali2 July 2020Italy
final
ePrivacy
Fine

GTL s.r.l. was fined for not responding to a person's request for access to their data. This matters because it shows the importance of companies being responsive to such requests. If businesses ignore these requests, they can face penalties.

What happened

GTL s.r.l. failed to respond to a data access request from an individual.

Who was affected

Individuals who requested access to their personal data held by GTL s.r.l. were affected.

What the authority found

The Garante per la protezione dei dati personali found that GTL s.r.l. did not comply with the requirement to respond to data access requests under GDPR.

Why this matters

This case highlights that companies must take data access requests seriously. Failing to do so can lead to fines, emphasizing the need for businesses to have proper procedures in place.

GDPR Articles Cited

AI-verified

Art. 15(GDPR)
Art. 12(1) GDPR
View original scraped data
Art. 12(1) GDPR
Art. 15(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 157 Codice Privacy
Source verified 7 April 2026
national law identified
Full Legal Summary
Detailed

On 26 November 2018, a former employee of GTL sent a request to have access to its personal data related to some 'registration sheets and printouts' extracted from the tachograph and those 'downloaded from the driver card relating to the journeys made' by the complainant himself during his previous work activities. The company did not respond to this specific access request, so the employee made a complaint to the Garante in order to have access to the mentioned information. Thus the Italian DPA sent a letter with some queries in order to investigate its compliance with the GDPR. Since the company did not respond to the DPA, the DPA sent another letter to demand more information on the data subject request. However, neither this time GTL provided any response. On that basis, the DPA put in place a proper on-site investigation and found out that GTL did not provide the information requested by the complainant because they did not have the mentioned information available either in their paper or digital database. The company affirmed that it replied to the complainant 'orally', without any proof or recording of it. The Italian DPA had to understand whether there was a breach of art. 12 and 15 of the GDPR in relation to an access request of the complainant. The Garante confirmed that, even if there was no information to provide, the company should have responded to the data subject in writing and, if appropriate, with electronic means.

Related Enforcement Actions (0)

No other enforcement actions found for GTL s.r.l. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

2 July 2020

Authority

Garante per la protezione dei dati personali

Fine Amount

€3,000

GDPRhub ID

gdprhub-2634

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. GTL s.r.l. - Italy (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: