Municipality – €3,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Another municipality was fined €3,000 for sharing a sick note of an employee with unauthorized parties. This ruling highlights the critical need for confidentiality when handling personal health information.
What happened
The municipality forwarded a full copy of an employee's sick note to multiple unauthorized third parties.
Who was affected
An employee whose personal health information was shared without consent.
What the authority found
The Italian DPA ruled that the municipality illegally shared personal data, violating GDPR's confidentiality and lawful processing requirements.
Why this matters
This case emphasizes the importance of protecting sensitive health information. Organizations must ensure that personal data is only shared with authorized individuals to avoid legal issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The Italian DPA has imposed a fine of EUR 3,000 on a municipality. The controller forwarded a full copy of an employee's sick note to multiple unauthorised third parties. Additionally, the controller obtained the personal data illegally by extracting it from the INPS database.
Related Enforcement Actions (2)
Other enforcement actions involving Municipality in IT
Fine
€3K
Details
Fine Date
26 March 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€3,000
Enforcement Tracker ID
ETid-3164
About this data
Cite as: Cookie Fines. Municipality - Italy (2026). Retrieved from cookiefines.eu
Last updated: