aiComply S.r.l. – €20,000 Fine (Italy, 2021)
aiComply S.r.l. was fined €20,000 for failing to secure personal data in a whistleblowing application it provided to Guglielmo Marconi Airport. The company did not inform the airport about its use of shared access profiles, which increased the risk of data exposure. This ruling stresses the importance of transparency and security in data processing.
What happened
aiComply S.r.l. did not encrypt personal data and used shared access profiles for its whistleblowing application, compromising data security.
Who was affected
Whistleblowers and employees whose data was processed through the application were at risk due to these security failures.
What the authority found
The Italian DPA found that aiComply S.r.l. violated data protection rules by not adequately securing personal data and failing to disclose its relationships with sub-processors.
Why this matters
This case highlights the need for service providers to maintain high security standards and transparency in their data handling practices to protect client data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The company 'aiComply Srl' (the ‘Processor’) provided the Airport of Bologna (the ‘Controller’) with the whistleblowing application “WB confidential” for the organizational acquisition and management of reports on illegal conduct by its employees and other stakeholders. The processor further offered maintenance of the application through two other companies, ‘Agic Technology Srl’ carrying specialist assistance activities and ‘A1Tech Srl’ carrying out the management of the IT-infrastructure. Investigations of the DPA found, that personal data transferred and stored within the application was not encrypted. Furthermore, it was verified that all three processing companies shared a non-nominal “System-Administrator” profile for the application. In this regard, aiComply had never informed the airport about this relationship with the two sub-processors. aiComply argued, that suitable security measures and especially encryption, had not be considered due to an extraordinarily limited amount of processing relating to only few reports transmitted through the system. Accordingly, the application was sufficiently protected by a firewall and an only internal or VPN access. It was negotiated with the airport that no further security measures shall be adopted. The processor also argued, that both involved companies for the maintenance did not process any personal data due to carrying out only technical activities and were generally appointed as suppliers of system administration tasks by aiComply. The DPA decided that both the controller and the processor are obliged to implement adequate technical and organizational measures to ensure a level of security within their scope and competencies. The missing encryption and sharing of a non-nominal ‘Admin-User’ with two other companies therefore lack the implementation of such adequate safeguards and violate Article 32 GDPR. In this regard, the controller has not received any communications or requests for authorization from the pr
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving aiComply S.r.l. in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
10 July 2021
Authority
Garante per la protezione dei dati personali
Fine Amount
€20,000
GDPRhub ID
gdprhub-3765About this data
Cite as: Cookie Fines. aiComply S.r.l. - Italy (2021). Retrieved from cookiefines.eu
Last updated: