InfoCert S.p.A. – Complaint Upheld (Italy, 2024)

Complaint Upheld
Garante per la protezione dei dati personali9 May 2024Italy
final
ePrivacy
Complaint Upheld

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

InfoCert S.p.A. reported a data breach where hackers accessed personal information of over 26,000 users. This incident highlights the importance of strong security measures to protect sensitive data. The company has since improved its security practices, but the breach raises concerns about data safety for all online businesses.

What happened

Hackers accessed around 40,623 user credentials and disclosed personal information of 26,921 members online.

Who was affected

Users of the 'Ordine degli Avvocati di Roma' whose personal data was compromised during the breach.

What the authority found

The authority found that InfoCert failed to implement adequate security measures and did not properly notify affected individuals about the breach, violating GDPR rules.

Why this matters

This case emphasizes that companies must prioritize data security and proper breach notification procedures. It serves as a reminder for all businesses to regularly assess their security measures.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
View original scraped data
Art. 5(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 122 Codice Privacy

Entities Involved

InfoCert S.p.A.
Tinexta S.p.A.
Source verified 13 April 2026
national law identified
Full Legal Summary
Detailed

Data Breach Notification: The breach was reported on May 8, 2019, by InfoCert to the Italian Data Protection Authority, detailing the unauthorized access to personal data through hacking. Extent of Breach: Hackers accessed about 40,623 user credentials from the portal of the "Ordine degli Avvocati di Roma," leading to the further unauthorized disclosure of personal information of 26,921 members online. Security Measures Post-Breach: Post-incident, InfoCert implemented numerous security measures to enhance data protection and address the vulnerabilities exploited by the hackers. Violations of GDPR Article 32 - Failure to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk. This includes issues with password management and security breaches that were not adequately addressed or remedied. Violations of GDPR Article 33 and 34 - Inadequate handling of data breach notifications to both the supervisory authority and the affected individuals. The timing, content, and completeness of these notifications did not meet the regulatory requirements. Violation of GDPR Article 28 - Inadequate contractual arrangements with processors, lacking detailed descriptions of data processing roles and responsibilities. Violation of GDPR Article 5 - Principles relating to processing of personal data were not adhered to, particularly concerning data security and the integrity and confidentiality of personal data.

Outcome

Complaint Upheld

A data subject complaint that was upheld by the DPA.

Related Enforcement Actions (0)

No other enforcement actions found for InfoCert S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

9 May 2024

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-8677

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. InfoCert S.p.A. - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: