Ministero dello sviluppo economico (Ministry of Economic Development) – €75,000 Fine (Italy, 2021)

€75,000Garante per la protezione dei dati personali11 February 2021Italy
final
ePrivacy
Fine

Italy's Ministry of Economic Development published a list of over 5,000 managers with personal details online without proper consent. This breach of privacy rules led to a fine of €75,000. The case highlights the importance of protecting personal information and following legal guidelines when sharing data.

What happened

The Ministry of Economic Development uploaded a publicly accessible list of managers containing their personal data without proper consent.

Who was affected

Managers whose personal information, including names and contact details, was published online by the Ministry of Economic Development.

What the authority found

The Italian data protection authority found that the Ministry lacked a valid legal basis for processing personal data, violating GDPR's requirements.

Why this matters

This ruling emphasizes that public bodies must adhere to data protection laws just like private companies. Organizations should ensure they have proper consent and legal grounds before sharing personal data.

GDPR Articles Cited

AI-verified

Art. 5(1) GDPR
Art. 6(2) GDPR
Art. 37(1) GDPR
Art. 37(7) GDPR
View original scraped data
Art. 5(1) GDPR
Art. 6(2) GDPR
Art. 37(1) GDPR
Art. 37(7) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

art. 2-ter of the Italian Privacy Code
Source verified 3 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

Following some reports, the Italian DPA ascertained that the MISE uploaded on its website a list of more than 5,000 managers containing their personal data, including name, tax code, e-mail address, CV, mobile phone and, in some cases, ID and health card. All this data was freely visible and downloadable. The MISE published that list to help SMEs in booking advice from experienced business professionals on the technological and digital processes to manage vouchers provided in compliance with the 2019 Budget Law. The DPA has also found that the MISE did not appoint a DPO by May 25, 2018, as required for all public bodies according to art. 37 GDPR. The Italian DPA noted that MISE failed to appoint a DPO by the established deadline (May 25, 2018). Furthermore, it has found that there was no adequate legal basis for the online publication of managers' personal data, as there were less intrusive methods to ensure that SMEs would have access to the managers' consultancy services, such as ensuring restricted access to said information through the use of passwords and usernames. As such, the Authority found that the dissemination of their personal information also consisted of disproportionate processing of data. In light of the above and given that the MISE has appointed a DPO then, the Italian DPA issued a fine of €75,000.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Ministero dello sviluppo economico (Ministry of Economic Development) in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 February 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€75,000

GDPRhub ID

gdprhub-3265

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Ministero dello sviluppo economico (Ministry of Economic Development) - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: