La Risorsa Umana s.r.l. – €40,000 Fine (Italy, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
La Risorsa Umana was fined for not following several data protection rules. This is important because it shows that companies must be transparent and responsible when handling personal information. Small businesses should review their data practices to avoid penalties.
What happened
La Risorsa Umana failed to comply with multiple GDPR data protection rules.
Who was affected
Employees whose personal data was monitored by La Risorsa Umana were affected.
What the authority found
The Italian data protection authority found that La Risorsa Umana violated several GDPR provisions regarding data processing and transparency.
Why this matters
This ruling highlights the need for companies to be clear about their data practices. Businesses should ensure they provide proper information to users about data monitoring.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
The data subject worked as a labour consultant for the controller and for its subsidiary under two parallel professional engagement contracts running from 3 June 2019 to 2 June 2020. The controller assigned him an individualised email account with an extension that linked to the controller's contact details On 31 December 2020, the data subject filed a complaint with the DPA. They claimed that the company director was monitoring his email correspondence on a daily basis from her own account, and that several shared accounts (such as admin@, somministrazione@ and sicurquality@) were also visible to management. They attached numerous emails showing the director regularly stepping into ongoing threads to issue instructions and comment on the work of staff and external collaborators, keeping all original recipients in copy. They also stated that no written information had ever been provided about this monitoring. The controller replied that the data subject had never been its employee. It argued that the shared accounts existed for operational reasons, that the information had been given "verbally", and that the director was authorised to act for both companies. During the investigation, the DPA also found that, on 10 July 2018, the controller and Form-App had designated each other as data processors using identical and generic deeds, which did not specify the processing operations entrusted nor contain concrete instructions. A similar reciprocal designation already existed since November 2017. The DPA noted that the controller had not provided the data subject with any written information about the systematic visibility of email exchanges by management, neither for the individualised account assigned to him nor for the shared accounts through which his correspondence transited. The privacy notices and internal codes produced by the controller either post-dated the facts of the complaint or contained no reference whatsoever to email management. The DPA also held that
Related Enforcement Actions (0)
No other enforcement actions found for La Risorsa Umana s.r.l. in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
23 March 2023
Authority
Garante per la protezione dei dati personali
Fine Amount
€40,000
GDPRhub ID
gdprhub-9975About this data
Cite as: Cookie Fines. La Risorsa Umana s.r.l. - Italy (2023). Retrieved from cookiefines.eu
Last updated: