an unnamed data subject – €3,000 Fine (Italy, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The municipality of Monte Sant'Angelo was fined for publishing the names of candidates who were excluded from a competition on its website. This is important because it emphasizes the need for proper legal grounds before sharing personal information.
What happened
Monte Sant'Angelo published the names of excluded candidates from a competition on its website without a legal basis.
Who was affected
Candidates who were excluded from the competition and had their names publicly listed.
What the authority found
The Italian data protection authority found that the municipality violated GDPR by processing personal data without a valid legal basis.
Why this matters
This ruling underlines that public entities must carefully consider privacy laws before sharing personal information. Other municipalities should review their practices to avoid similar issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Entities Involved
The municipality of Monte Sant'Angelo is the controller. The data subject is an excluded candidate from a competition procedure. The municipality published the results for a competition procedure on its website. The information included the names of the candidates who were excluded from the procedure. The web page was indexed on search engines. An excluded candidate asked the municipality to remove their name from the website. The municipality rejected the request. It claimed that public disclosure of the information was mandatory under Italian law (legislative decree 33/2013https://www.gazzettaufficiale.it/eli/id/2013/04/05/13G00076/sg). The candidate later submitted a complaint to the Italian DPA. The controller removed the data subject's name from its website after receiving an information request from the DPA. The DPA held that the controller violated Article 5(1)(a) (principle of lawfulness) and 6 (lawfulness of processing) GDPR by processing personal data without a legal basis. Specifically, the controller violated paragraphs (1)(c), (1)(e), (2), and (3) of Article 6. The DPA noted that legislative decree 33/2013, (and Italian administrative law in general) only require public administrations to publicly disclose the identity of the winners of competition procedures. The controller was under no legal obligation to disclose the name of the data subject, who was excluded from the procedure. The DPA pointed out that its own guidelineshttps://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/3134436 and case lawhttps://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9581028https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9681778https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9732406 endorse the same approach. The DPA also held that the controller violated Article 2-ter(1)(3)https://www.gazzettaufficiale.it/dettaglio/codici/datiPersonali/1_0_1 of the Italian Privacy Cod
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (3)
Other enforcement actions involving an unnamed data subject in IT
Fine
€3K
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
28 April 2022
Authority
Garante per la protezione dei dati personali
Fine Amount
€3,000
GDPRhub ID
gdprhub-5037About this data
Cite as: Cookie Fines. an unnamed data subject - Italy (2022). Retrieved from cookiefines.eu
Last updated: