Università Commerciale “Luigi Bocconi” di Milano – €200,000 Fine (Italy, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The University of Milan was fined €200,000 for improperly handling students' personal data during online exams. This is significant because it shows that educational institutions must follow strict data protection rules. Schools and universities should ensure they have the right legal basis for processing student data.
What happened
The university required students to consent to the processing of sensitive personal data to take online exams.
Who was affected
Students at the University of Milan whose data was improperly handled.
What the authority found
The Italian Data Protection Authority found that the university did not comply with GDPR's requirements for lawful data processing.
Why this matters
This case highlights that educational institutions must adhere to data protection laws like any other organization. It serves as a warning for schools to review their data practices, especially during emergencies like the COVID-19 pandemic.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
A student at the 'Luigi Bocconi' Commercial University of Milan filed a complaint to the Italian DPA (Garante) regarding possible violations of the GDPR by the academic institution. They alleged that it unlawfully requested students' consent to the processing of special categories of personal data. If they refused, students would not be able to carry out online exams. In response to a 'request for clarification' about this processing by the complainant, the university's DPO informed them it considered this processing to be necessary to carry out exams at a distance given the COVID-19 pandemic. The Italian DPA considered a range of issues in this case. First, it assessed the general conditions of lawfulness of the processing of personal data in the university environment. It held the same data protection framework applies to public and private universities. Consequently, the processing of student data aimed at issuing university qualifications could not be based on legal bases such as consent and/or contract, and the data controller was required to comply with general principles of data protection per Article 5 GDPR. It also had to guarantee and be able to demonstrate that the processing was carried out in accordance with the GDPR, and in particular take into account the principle of data protection by design and default per Article 25 GDPR. Second, the DPA considered whether the university could generally process of student data through the 'Respondus' software it used to monitor students during their exams. The software "captures the video images and the student's screen by identifying and marking with a flag the moments in which unusual and/or suspicious behaviour is detected by video recording and snapshots taken at random intervals to keep track of anomalous behaviour such as: look not turned towards the monitor, face partially absent from the photo, missing face". It then flags such behaviour for further review. The Garante held the use of such software by u
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Università Commerciale “Luigi Bocconi” di Milano in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
16 September 2021
Authority
Garante per la protezione dei dati personali
Fine Amount
€200,000
GDPRhub ID
gdprhub-4253About this data
Cite as: Cookie Fines. Università Commerciale “Luigi Bocconi” di Milano - Italy (2021). Retrieved from cookiefines.eu
Last updated: