Federpol – Court Ruling (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
An Italian court upheld a fine against a private investigators' association for sharing a newsletter that included a member's name involved in a defamation case. This ruling is crucial as it emphasizes the need for organizations to handle personal data carefully and respect privacy rights.
What happened
The association sent a newsletter that disclosed the name of a member involved in a legal case without a valid legal basis.
Who was affected
The member of the association whose name was disclosed in the newsletter.
What the authority found
The court confirmed that the association violated privacy rules by including the member's name in the newsletter, which was deemed unnecessary.
Why this matters
This ruling serves as a reminder for organizations to consider privacy when sharing information, even internally. Companies should train staff on data protection to avoid similar violations.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Federpol (the controller) is an association of private investigators. In 2021, the DPA fined the controller for distributing a newsletter to all members containing the minutes of a meeting with its executive board. The minutes concerned a case against a member who had sent a defamatory letter. The member was identified by name. The DPA found a violation of Articles 5(1)(a) and (c), and 6(1) GDPR as the controller did not have a legal basis to process the data (including the name of the member in the newsletter). The DPA fined the controller €5,000. In 2022, the controller appealed the decision to the court of Rome. The controller argued that the processing was lawful under legitimate interest, and in any case, contractual obligation. The court dismissed the appeal and ordered the controller to pay the fine. The court considered that the controller could have informed members without naming the data subject. The controller filed an appeal to the Supreme Court. The court dismissed the appeal and upheld the reasoning of the lower court. The court followed the reasoning of the lower court, and stated that the controller could have informed its members of the case without including the data subject’s name. The court considered this processing to be disproportionate in relation to the goal. The court dismissed the controller’s argument that there was a difference between disseminating the information and communicating it to members. The court stated that, while the data subject’s name did not fall under the scope of Article 9 GDPR, the controller needed the consent of the data subject to process their data. Therefore, a resolution adopted by a general meeting or generic consent for statutory purposes did not meet the requirements of consent. The court also dismissed the controller’s argument that the fine was disproportionate. The court held that the DPA had correctly applied and justified the fine in accordance with Article 83(2) GDPR.
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Federpol in IT
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Federpol - Italy (2026). Retrieved from cookiefines.eu
Last updated: