Il Sole 24 Ore S.p.a. – €40,000 Fine (Italy, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Il Sole 24 Ore S.p.a. published an article that mistakenly included personal information about a homosexual couple and their child. This breach of privacy matters because it highlights the importance of protecting sensitive personal data, especially in journalism.
What happened
Il Sole 24 Ore S.p.a. published an article that included personal data of a couple and their child without their consent.
Who was affected
The affected individuals were a homosexual couple and their adopted child whose personal information was disclosed in the article.
What the authority found
The Italian data protection authority found that the company violated GDPR rules by not properly handling sensitive personal data.
Why this matters
This case emphasizes the need for media companies to be careful with personal data, especially sensitive information. It serves as a reminder for all businesses to ensure they have proper data protection measures in place.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller was a daily newspaper. The data subjects were a homosexual couple and their adopted child. The controller published an article covering a court case relating to the data subjects, mistakenly attaching documents that contained the data subjects' personal data. The data subjects requested that the data be deleted, and the controller complied a day later. Before the article was removed from the controller's website, it received nineteen unique visitors. The controller did not respond to further data access requests regarding the identities of the recipients of the personal data, arguing that its prompt removal of the article made any further response unnecessary. The Italian DPA (Garante per la protezione dei dati personali - GDPD) found that the controller had violated Article 5 and Article 9 GDPR; it fined the controller €40,000, balancing, among other things, the sensitive nature of the data disclosed (sexual orientation, data relating to the adoption of a minor) and the negligent nature of the infringement against the controller's journalistic purpose and prompt measures to eliminate the consequences of the breach. The GDPD also issued a warning for failure to respond to the data subjects' requests for access, inviting the controller to implement additional measures to guarantee the effective exercise of future data subjects' rights under Article 12 GDPR.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving Il Sole 24 Ore S.p.a. in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
28 April 2022
Authority
Garante per la protezione dei dati personali
Fine Amount
€40,000
GDPRhub ID
gdprhub-4984About this data
Cite as: Cookie Fines. Il Sole 24 Ore S.p.a. - Italy (2022). Retrieved from cookiefines.eu
Last updated: