XX (data subject) – Complaint Upheld (Italy, 2022)

Complaint Upheld
Garante per la protezione dei dati personali9 June 2022Italy
final
Complaint Upheld

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A person complained about their and their son's personal data being published on a municipal website after a school incident. The Italian data protection authority found that the municipality had acted quickly to remove most of the information but still retained some by mistake. This case is important because it shows how sensitive data about minors must be handled with care.

What happened

A complaint was made regarding the publication of personal data about a minor on a municipality's website.

Who was affected

The person who complained, concerning their minor son's identity and health information.

What the authority found

The authority determined that the municipality had removed most of the contested data but retained some due to an error.

Why this matters

This case underscores the need for organizations to be vigilant in protecting minors' personal information and to act promptly to correct any mistakes.

GDPR Articles Cited

AI-verified

Art. 4(1) GDPR
Art. 5(1)(c) GDPR
Art. 6(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 6(2) GDPR
Art. 6(3) GDPR
View original scraped data
Art. 4(1) GDPR
Art. 5(1)(c) GDPR
Art. 6(1)(c) GDPR
Art. 6(1)(e) GDPR
Art. 6(2) GDPR
Art. 6(3) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Codice in materia di protezione dei dati personali (Testo coordinato)
Legislative Decree no. 267/2000

Entities Involved

XX (data subject)
Il Comune di Brindisi (controller)
Source verified 9 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

The Italian DPA received a complaint from the data subject concerning the dissemination of personal data concerning him and his son as well as information on his son’s injuries following a fall inside his school. These pieces of information were published in a Council resolution on the municipality of Brindisi’s website. The data subject had already requested the controller to remove any data from its website which could directly trace back to his minor son’s identity and pathology and republish it in compliance with the rules in force. The controller directly acted upon this request and deleted the resolution from its Municipal Notice Board. However, information on the legal proceedings including names and the circumstance of the existence of these legal proceedings could still be found in the subject of the resolution on the controller’s website. 2 years later there was no contest from the data subject to the controller, however the data subject lodged a complaint with the Italian DPA. The Italian DPA considered the fact that the controller had already removed the full text of the contested resolution from the web as requested by the data subject and that it kept the contested personal data included in the subject of the resolution only by mere mistake. Moreover, the controller asked to take into consideration the objective difficulty of sometimes balancing transparency and the protection of personal data. It pointed out the existence of a need, for the purposes of transparency of administrative action, to leave public the subject of the resolution with the names of the parties in clear; as well as the large number of acts to be published online. The Italian DPA held that the need for transparency could be achieved without disseminating online the personal data of the parties involved in the proceedings and therefore held that the controller breached Article 5(1)(c) in that it was inconsistent with the principle of data minimisation since the data were not li

Outcome

Complaint Upheld

A data subject complaint that was upheld by the DPA.

Related Enforcement Actions (0)

No other enforcement actions found for XX (data subject) in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

9 June 2022

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-5343

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. XX (data subject) - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: