Comune di Portici – €6,000 Fine (Italy, 2024)
The Comune di Portici was fined for using traffic cameras without informing residents about the data collection. This ruling is significant because it underscores the importance of transparency in public surveillance. Local governments should ensure they communicate clearly about how they monitor public spaces.
What happened
Comune di Portici operated traffic cameras to monitor red light violations without informing residents.
Who was affected
Residents living near the traffic cameras who were unaware of the surveillance.
What the authority found
The Italian DPA ruled that Comune di Portici violated GDPR by failing to inform residents about the traffic cameras and not conducting a data protection impact assessment.
Why this matters
This case stresses the importance of informing the public about surveillance practices, encouraging local governments to be more transparent about data collection.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The municipality of Portici (the data controller) installed and operated traffic cameras near traffic lights in order to record red lights violations. The controller did not install information signs for the cameras and did not provide residents with any information on the processing of personal data. Additionally, the controller did not carry out a data protection impact assessment (DPIA) for the processing of personal data. Several residents later complained to the Italian supervisory authority that the cameras were installed without information signs. In an early communication with the authority, the controller claimed that the law authorizing the use of traffic cameras did not require informing the data subject in the specific case of traffic light violations. The controller also claimed that a DPIA was not needed due to the limited scope of the video surveillance and to some privacy-preserving safeguards of the processing of the footage (such as the limitation of storage times and the obfuscation of car windshields). Nonetheless, the controller addressed the authority’s concerns in several ways. It installed information signs near the cameras to provide residents with the essential information on the processing of their data. It also drafted a privacy notice addressing the use of traffic cameras. The notice was published on the controller’s website and was made available at the police station. Finally, the controller carried out a DPIA for the use of the cameras and updated the municipal regulation on video surveillance. The supervisory authority held that the controller violated Articles 5(1)(a), 12, and 13 GDPR by failing to inform residents about the use of traffic cameras. The authority also held that the controller violated Article 35 GDPR by failing to carry out a DPIA. The authority considered that its concerns were entirely addressed during the procedure and fined the controller €6,000.
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Comune di Portici in IT
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
12 December 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€6,000
GDPRhub ID
gdprhub-8889About this data
Cite as: Cookie Fines. Comune di Portici - Italy (2024). Retrieved from cookiefines.eu
Last updated: