Atac s.p.a. – €400,000 Fine (Italy, 2021)

€400,000Garante per la protezione dei dati personali22 July 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Italy fined Atac s.p.a. EUR 400,000 for not securing parking meter data in Rome. The company didn't keep a data processing register or specify how long they'd keep the data, and some data was sent through insecure channels. This matters because businesses must protect personal data and be clear about how they handle it.

What happened

Atac s.p.a. failed to secure parking meter data and did not maintain a data processing register.

Who was affected

People using parking meters in Rome, whose data was managed by Atac s.p.a.

What the authority found

The Italian authority found Atac s.p.a. violated GDPR by not securing data and lacking a data processing register.

Why this matters

This case highlights the importance of securing data and maintaining clear records of data processing activities. Businesses should ensure they have robust security measures and transparent data handling practices.

GDPR Articles Cited

AI-verified

Art. 30 GDPR
Art. 32 GDPR
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
View original scraped data
Art. 5 GDPR
Art. 6 GDPR
Art. 30 GDPR
Art. 32 GDPR

Original data from scraper before AI verification against source document.

Source verified 6 March 2026
verified correct
Full Legal Summary
Detailed

The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had complained about the new parking meters installed in the in the city of Rome. In fact, the company Atac s.p.a., which was contracted by the city to manage the parking lots, had initiated a technical upgrade of the parking meters in order to offer new services (e.g., the payment of fines/fees or the purchase/renewal of public transport tickets) and introduce new payment methods that also take into account the vehicle's license plate number. All parking information was then managed through a centralized system, which could also be accessed through an app by the employees responsible for controlling parking fees. Irregularities were then identified during the investigation. It was found that Atac had not established a data processing register. Also, the retention periods for the collected data were not specified, and appropriate security measures were not taken. For example, it was found that at the time of the audit, some data flows to and from the system implemented by were going through insecure channels. In addition, officials could have checked any license plate en masse and repeatedly over time, for example, to find out a person's habits and parking location.

Related Enforcement Actions (0)

No other enforcement actions found for Atac s.p.a. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

22 July 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€400,000

Enforcement Tracker ID

ETid-829

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Atac s.p.a. - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: