Territorial Agency of the Puglia Region for the waste management service (AGER) – €6,000 Fine (Italy, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Territorial Agency of the Puglia Region for Waste Management (AGER) was fined €6,000 for mishandling a performance evaluation document. The agency mistakenly labeled a confidential document as ordinary, allowing unauthorized access. This case highlights the importance of proper data classification and management.
What happened
AGER was penalized for incorrectly filing a confidential performance evaluation document as ordinary, leading to unauthorized access.
Who was affected
An employee of AGER whose confidential performance evaluation sheet was mistakenly made accessible to unauthorized individuals.
What the authority found
The Italian data protection authority found that AGER failed to implement sufficient organizational measures to protect confidential information, violating GDPR's requirements.
Why this matters
This ruling stresses the need for organizations to properly classify and manage sensitive documents. Companies should review their data handling practices to prevent similar mistakes.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Garante received a complaint from an employee of the Territorial Agency of the Puglia Region for Waste Management (AGER) alleging that her performance evaluation sheet of 2019, was mistakenly recorded as a non-confidential document, making it accessible to individuals authorized to use the Agency’s protocol system, but not directly involved in the matter. The data subject also highlighted the lack of adequate information or consultation regarding data processing policies by the Agency's DPO. The data controller acknowledged that the evaluation sheet was mistakenly filed as “ordinary” instead of “confidential.” However, it provided system logs showing that only individuals directly involved in the process accessed the document. Garante considered that the data controller's mistake in filed the document as "ordinary" instead of "confidential", even with the system logs showing that only individuals directly involved in the process accessed the document, was a failure to implement sufficient organizational measures to prevent such risks. The agency appointed its DPO in 2020, significantly later than the May 25, 2018, deadline set by GDPR. This delay constituted a violation of Article 37 GDPR. Also, Garante highlighted that the data controller failed to timely publish or communicate the DPO's contact details, violating Article 13 and Article 37 GDPR. The data controller cited organizational challenges and difficulties stemming from the COVID-19 pandemic as contributing factors. For this reason, Garante fined the data controller 6,000 EUR for not having designated the DPO timely, neither informing the data subjects of the DPO's contact details and communicating these data to the DPA.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Territorial Agency of the Puglia Region for the waste management service (AGER) in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
8 February 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€6,000
GDPRhub ID
gdprhub-8628About this data
Cite as: Cookie Fines. Territorial Agency of the Puglia Region for the waste management service (AGER) - Italy (2024). Retrieved from cookiefines.eu
Last updated: