Federpol – Court Ruling (Italy, 2026)

Court Ruling
DPA21 May 2026Italy
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An Italian court upheld a fine against a private investigators' association for sharing a newsletter that included a member's name involved in a defamation case. This ruling is crucial as it emphasizes the need for organizations to handle personal data carefully and respect privacy rights.

What happened

The association sent a newsletter that disclosed the name of a member involved in a legal case without a valid legal basis.

Who was affected

The member of the association whose name was disclosed in the newsletter.

What the authority found

The court confirmed that the association violated privacy rules by including the member's name in the newsletter, which was deemed unnecessary.

Why this matters

This ruling serves as a reminder for organizations to consider privacy when sharing information, even internally. Companies should train staff on data protection to avoid similar violations.

GDPR Articles Cited

AI-verified

Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 6(1) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 6(1) GDPR

Original data from scraper before AI verification against source document.

Decision AuthoritySupreme Court of Cassation
Reviewed AuthorityItalian Data Protection Authority
Source verified 17 June 2026
authority corrected
Full Legal Summary
Detailed

Federpol (the controller) is an association of private investigators. In 2021, the DPA fined the controller for distributing a newsletter to all members containing the minutes of a meeting with its executive board. The minutes concerned a case against a member who had sent a defamatory letter. The member was identified by name. The DPA found a violation of Articles 5(1)(a) and (c), and 6(1) GDPR as the controller did not have a legal basis to process the data (including the name of the member in the newsletter). The DPA fined the controller €5,000. In 2022, the controller appealed the decision to the court of Rome. The controller argued that the processing was lawful under legitimate interest, and in any case, contractual obligation. The court dismissed the appeal and ordered the controller to pay the fine. The court considered that the controller could have informed members without naming the data subject. The controller filed an appeal to the Supreme Court. The court dismissed the appeal and upheld the reasoning of the lower court. The court followed the reasoning of the lower court, and stated that the controller could have informed its members of the case without including the data subject’s name. The court considered this processing to be disproportionate in relation to the goal. The court dismissed the controller’s argument that there was a difference between disseminating the information and communicating it to members. The court stated that, while the data subject’s name did not fall under the scope of Article 9 GDPR, the controller needed the consent of the data subject to process their data. Therefore, a resolution adopted by a general meeting or generic consent for statutory purposes did not meet the requirements of consent. The court also dismissed the controller’s argument that the fine was disproportionate. The court held that the DPA had correctly applied and justified the fine in accordance with Article 83(2) GDPR.

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Federpol in IT

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

21 May 2026

Authority

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Federpol - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: