Liguria Health Protection Agency – €6,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Liguria Health Protection Agency was fined for tracking employees' locations without proper notice. This is important because it shows that companies must inform employees about how their data is being used. Businesses should be transparent about data collection practices to maintain trust and avoid penalties.
What happened
Liguria Health Protection Agency tracked employees' locations through company vehicles without adequately informing them.
Who was affected
Employees of Liguria Health Protection Agency who were tracked were affected.
What the authority found
The authority found that the agency did not sufficiently inform employees about the tracking, violating GDPR requirements.
Why this matters
This ruling highlights the necessity for companies to be transparent about data collection practices. Small businesses should ensure they communicate clearly with employees about any monitoring activities.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the controller initiated discliplinary proceedings and suspended them based on data collected unlawfully through a tracking system in the company vehicle. The data subject also argued that the controller did not sufficiently inform employees that their location was being tracked through the company vehicles. The DPA received several complaints from other data subjects, and joined the complaints. The controller argued that the geolocation system was a measure to protect its assets, to optimise the management of its vehicles, and to ensure worker safety (e.g. to ensure that an employee followed the route while carrying hazardous materials). The controller argued that it did not process employees’ personal data, as it tracked the vehicles themselves and did not link the vehicle with the employee. Finally, the controller argued that the tracking was in compliance with its workers’ statutes. The DPA first stated that the controller had complied with its information obligations. Following the collective bargaining agreement, the controller informed data subjects of how their data was going to be processed. In addition, the controller had included a notice on how their location data was processed. Therefore, the DPA did not find a violation of Article 13 GDPR. The DPA found a violation of Article 5(1)(c) GDPR. The DPA found that the controller systematically and continuously monitored employees assigned company vehicles, as they were tracked at very frequent intervals without allowing them to deactivate the tracking. The DPA found this frequent tracking particularly detrimental to data subjects’ rights and freedoms, because the controller was able to access real-time information on vehicle m
Related Enforcement Actions (0)
No other enforcement actions found for Liguria Health Protection Agency in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
28 May 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€6,000
GDPRhub ID
gdprhub-10104About this data
Cite as: Cookie Fines. Liguria Health Protection Agency - Italy (2026). Retrieved from cookiefines.eu
Last updated: