aiComply S.r.l. – €20,000 Fine (Italy, 2021)

€20,000Garante per la protezione dei dati personali10 July 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

aiComply was fined €20,000 for not securing personal data in a whistleblowing app used by Bologna Airport. This matters because it shows that companies must take data security seriously, even for small amounts of data.

What happened

aiComply did not encrypt personal data stored in its whistleblowing application.

Who was affected

Employees and whistleblowers whose data was processed by the application.

What the authority found

The authority determined that aiComply failed to meet GDPR security requirements.

Why this matters

This ruling serves as a reminder that all companies, regardless of size, must prioritize data security. Businesses should regularly assess their data protection practices.

GDPR Articles Cited

AI-verified

Art. 28(GDPR)
Art. 32(GDPR)
View original scraped data
Art. 28(GDPR)
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

Source verified 4 April 2026
verified correct
Full Legal Summary
Detailed

The company 'aiComply Srl' (the ‘Processor’) provided the Airport of Bologna (the ‘Controller’) with the whistleblowing application “WB confidential” for the organizational acquisition and management of reports on illegal conduct by its employees and other stakeholders. The processor further offered maintenance of the application through two other companies, ‘Agic Technology Srl’ carrying specialist assistance activities and ‘A1Tech Srl’ carrying out the management of the IT-infrastructure. Investigations of the DPA found, that personal data transferred and stored within the application was not encrypted. Furthermore, it was verified that all three processing companies shared a non-nominal “System-Administrator” profile for the application. In this regard, aiComply had never informed the airport about this relationship with the two sub-processors. aiComply argued, that suitable security measures and especially encryption, had not be considered due to an extraordinarily limited amount of processing relating to only few reports transmitted through the system. Accordingly, the application was sufficiently protected by a firewall and an only internal or VPN access. It was negotiated with the airport that no further security measures shall be adopted. The processor also argued, that both involved companies for the maintenance did not process any personal data due to carrying out only technical activities and were generally appointed as suppliers of system administration tasks by aiComply. The DPA decided that both the controller and the processor are obliged to implement adequate technical and organizational measures to ensure a level of security within their scope and competencies. The missing encryption and sharing of a non-nominal ‘Admin-User’ with two other companies therefore lack the implementation of such adequate safeguards and violate Article 32 GDPR. In this regard, the controller has not received any communications or requests for authorization from the pr

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

10 July 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€20,000

GDPRhub ID

gdprhub-3765

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. aiComply S.r.l. - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: