Roma Capitale – €800,000 Fine (Italy, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Roma Capitale was fined €800,000 for not protecting personal data collected through parking meters. This ruling is important because it shows that municipalities must also follow data protection laws when collecting personal information.
What happened
The municipality failed to provide adequate information and security for data collected by parking meters.
Who was affected
Users of the parking meters who had their personal data collected.
What the authority found
The authority found that Roma Capitale violated multiple GDPR requirements regarding data processing.
Why this matters
This case sets a precedent for public entities to comply with data protection laws. Companies and municipalities must ensure they inform users and protect their data properly.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The DPA launched an investigation into the parking meters operated by the Municipality of Rome. According to a report, users had to enter the license plate of their vehicle to obtain the parking ticket. It found some parking meters under management had recently been modernised to allow card payments and the personalisation of payments to stop users of the service from needing to display tickets. The latter required users to enter their license plates into the meters. The system underpinning this was operated by Atac s.p.a. The company collected information (e.g. the time, the start and end date of the stop, the amount paid and the license plate) relating to the payment of the parking, which was facilitated by more intermediary companies, and made it available both to traffic auxiliaries for the purposes of verifying the payment of the parking as well as to the company's internal staff for administrative management purposes. The DPA notified Roma Capitale that it had discovered some breaches and invited the municipality to produce defensive writings. It stated that the municipality had effectively put in place a system that (1) processed the personal data collected through the new parking meters installed in the area (2) without providing data subjects adequate information, (3) without defining the roles of the external companies involved in the processing, (4) without defining the storage times of the data collected and (5) without having adopted appropriate security measures, in violation of Articles 5, 12, 13, 25, 28 and 32 GDPR. The DPA held that Roma Capitale unlawfully carried out the the processing of personal data. This processing "took place in a manner that does not comply with the general principles of processing, in the absence of adequate information and appointment of data processors, as well as in the absence of suitable technical and organizational measures to guarantee a level of security adequate to the risk presented by the processing". It high
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (2)
Other enforcement actions involving Roma Capitale in IT
Fine
€800K
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
22 July 2021
Authority
Garante per la protezione dei dati personali
Fine Amount
€800,000
GDPRhub ID
gdprhub-4040About this data
Cite as: Cookie Fines. Roma Capitale - Italy (2021). Retrieved from cookiefines.eu
Last updated: