Territorial Agency of the Puglia Region for the waste management service (AGER) – €6,000 Fine (Italy, 2024)

€6,000Garante per la protezione dei dati personali8 February 2024Italy
final
ePrivacy
Fine

The Territorial Agency of the Puglia Region for Waste Management was fined for mishandling personal data and failing to appoint a data protection officer on time. This case is significant because it reinforces the need for organizations to follow data protection rules and deadlines.

What happened

The agency mistakenly filed a confidential document as ordinary, making it accessible to unauthorized individuals.

Who was affected

An employee whose performance evaluation sheet was improperly classified and accessed by others.

What the authority found

The authority ruled that the agency violated GDPR by not properly protecting personal data and failing to appoint a data protection officer on time.

Why this matters

This case serves as a reminder for organizations to implement strong data protection measures and adhere to legal timelines to avoid penalties.

GDPR Articles Cited

AI-verified

Art. 83(GDPR)
Art. 13(1)(b) GDPR
Art. 37(1)(a) GDPR
Art. 37(7) GDPR
Art. 58(2) GDPR
View original scraped data
Art. 13(1)(b) GDPR
Art. 37(1)(a) GDPR
Art. 37(7) GDPR
Art. 58(2) GDPR
Art. 83(GDPR)

Original data from scraper before AI verification against source document.

Source verified 6 April 2026
articles corrected
Full Legal Summary
Detailed

Garante received a complaint from an employee of the Territorial Agency of the Puglia Region for Waste Management (AGER) alleging that her performance evaluation sheet of 2019, was mistakenly recorded as a non-confidential document, making it accessible to individuals authorized to use the Agency’s protocol system, but not directly involved in the matter. The data subject also highlighted the lack of adequate information or consultation regarding data processing policies by the Agency's DPO. The data controller acknowledged that the evaluation sheet was mistakenly filed as “ordinary” instead of “confidential.” However, it provided system logs showing that only individuals directly involved in the process accessed the document. Garante considered that the data controller's mistake in filed the document as "ordinary" instead of "confidential", even with the system logs showing that only individuals directly involved in the process accessed the document, was a failure to implement sufficient organizational measures to prevent such risks. The agency appointed its DPO in 2020, significantly later than the May 25, 2018, deadline set by GDPR. This delay constituted a violation of Article 37 GDPR. Also, Garante highlighted that the data controller failed to timely publish or communicate the DPO's contact details, violating Article 13 and Article 37 GDPR. The data controller cited organizational challenges and difficulties stemming from the COVID-19 pandemic as contributing factors. For this reason, Garante fined the data controller 6,000 EUR for not having designated the DPO timely, neither informing the data subjects of the DPO's contact details and communicating these data to the DPA.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Territorial Agency of the Puglia Region for the waste management service (AGER) in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

8 February 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€6,000

GDPRhub ID

gdprhub-8628

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Territorial Agency of the Puglia Region for the waste management service (AGER) - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: