Aeroporto Guglielmo Marconi di Bologna S.p.a. – €40,000 Fine (Italy, 2021)

€40,000Garante per la protezione dei dati personali10 June 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Italian Data Protection Authority fined Aeroporto Guglielmo Marconi di Bologna S.p.a. EUR 40,000 for not securing sensitive whistleblower data. The airport failed to encrypt personal information and did not use secure network protocols, risking exposure of sensitive information.

What happened

Aeroporto Guglielmo Marconi di Bologna S.p.a. failed to encrypt whistleblower data and used insecure network protocols.

Who was affected

Whistleblowers whose sensitive information was not properly secured by the airport's systems.

What the authority found

The authority found that the airport did not take adequate security measures to protect sensitive data, violating GDPR requirements.

Why this matters

This case highlights the importance of securing sensitive data, especially for whistleblower systems. Businesses must ensure robust encryption and secure data transmission to comply with GDPR and protect individuals from potential harm.

GDPR Articles Cited

Art. 25 GDPR
Art. 32 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and discrimination in the work environment is high. In this context, the controller is obliged to comply with the principles of data protection and to ensure the integrity and security of the data. Against this background, the Italian DPA (Garante) fined Aeroporto Guglielmo Marconi di Bologna S.p.a. EUR 40,000 and its software supplier EUR 20,000 for violations of the GDPR. In the course of the DPA's investigation, it was found that the application for collecting and managing criminal reports was accessed without the use of a secure network protocol (e.g., the link protocol) and that the application itself did not provide for encryption of the reporting party's identification data, the information about the report and the attached documents. The DPA considered this to be a violation of the obligation to take technical and organizational measures that ensure a level of security appropriate to the risk to the data subjects. In addition, the DPA found that the controller should have conducted an impact assessment, given the sensitivity of the information processed and the risks and vulnerability of the data subjects.

Related Enforcement Actions (0)

No other enforcement actions found for Aeroporto Guglielmo Marconi di Bologna S.p.a. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 June 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€40,000

Enforcement Tracker ID

ETid-807

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Aeroporto Guglielmo Marconi di Bologna S.p.a. - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: