Municipality of Nichelin – €18,000 Fine (Italy, 2025)

€18,000Garante per la protezione dei dati personali11 September 2025Italy
final
ePrivacy
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Municipality of Nichelino was fined for publishing personal data of a former employee without proper consent. The employee complained that the information was inaccurate and harmful. This ruling shows that even good intentions can't justify sharing personal data without a solid legal basis.

What happened

The Municipality of Nichelino published personal data about a former employee, including details of her termination, without a valid legal basis.

Who was affected

The former employee whose personal data was incorrectly published by the Municipality of Nichelino.

What the authority found

The authority found that the Municipality violated GDPR rules by publishing personal data without a valid legal basis and not ensuring fairness and transparency.

Why this matters

This ruling serves as a reminder that organizations must carefully assess their legal grounds for sharing personal data. Companies should strengthen their data protection practices to prevent similar issues.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 16(GDPR)
Art. 6(1)(f) GDPR
Art. 12(3) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 12(3) GDPR
Art. 16(GDPR)

Original data from scraper before AI verification against source document.

Source verified 5 April 2026
articles corrected
scope corrected
Full Legal Summary
Detailed

A former employee (the data subject) of the Municipality of Nichelino (the controller) filed a complaint against the Municipality under the GDPR. The data subject asked the controller to correct her employment records to remove the phrase “failure to pass the probationary period,” which she argued was inaccurate and harmful. She also challenged the publication of decisions regarding her termination and the hiring of a replacement, as well as competition rankings that included personal data and scores of other candidates. The controller stated that it acted in good faith, removed the information, and published a rectification agreed with the data subject. The controller also argued that transparency obligations justified the publication and highlighted measures to limit data exposure, correct technical errors, train staff, and involve the Data Protection Officer. The DPA found that the Municipality violated Article 5 GDPR and Article 6(1)(f) GDPR by publishing personal data without a valid legal basis and failing to respect the principles of lawfulness, fairness, transparency, and data minimisation. Transparency obligations did not authorise the publication of employment or competition records containing personal information, and even if there was an authorisation, the documents remained online longer than permitted by law. The Municipality had not assessed which data were necessary for publication or implemented measures to prevent indirect identification. The published documents allowed the identification of the data subject and other candidates through employment and competition details. The DPA emphasised that even partial anonymisation or later corrections could not justify the original unlawful disclosure. The DPA also found that the Municipality failed to respond adequately to the data subject’s request to exercise their rights under Articles 15-22 GDPR. The Municipality did not provide timely feedback, explain the reasons for non-compliance, or inform the

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Municipality of Nichelin in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

11 September 2025

Authority

Garante per la protezione dei dati personali

Fine Amount

€18,000

GDPRhub ID

gdprhub-9603

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Municipality of Nichelin - Italy (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: