Municipality of Vasto – €5,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Municipality of Vasto was fined for not providing proper information about traffic cameras that recorded violations. This is important because it shows that public entities must inform people about how their data is being used. Local governments should ensure they communicate clearly about data collection practices to avoid fines.
What happened
The Municipality of Vasto failed to provide adequate information near traffic cameras about data processing.
Who was affected
Drivers who were recorded by the traffic cameras and fined were affected.
What the authority found
The data protection authority found that the Municipality of Vasto violated GDPR by not being transparent about the data processing related to traffic violations.
Why this matters
This case underscores the need for transparency in data collection practices, especially for public entities. Governments should ensure they inform citizens about how their data is used to comply with regulations.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A data subject filed a complaint against the controller after being fined for running a red light. The data subject argued that there were no signs or warnings near the cameras installed to detect violations, and that the controller did not obscure the windows to make data subjects unrecognisable. The controller argued that it provided warning signs of the presence of cameras. In addition, the cameras only capture data subjects’ license plates to comply with the principle of data minimisation (Article 5(1)(c) GDPR), and that the case of the data subject was a technical error. The DPA first noted that, in principle, a public entity can process this data if it is necessary to fulfil a legal obligation or for the public interest (Article 6(1)(c) and (e) GDPR). However, the controller still has the obligation to provide information to data subjects regarding the processing, in accordance with the principle of transparency (Article 5(1)(a) GDPR). The DPA found that, at the time of the complaint, the controller had not included any information near the cameras. In addition, the first level privacy policy did not comply with the requirements of Article 13 GDPR and were not provided in concise and transparent manner. Therefore, the DPA found a violation of Articles 5(1)(a), 12(1) and 13 GDPR. The DPA also found a violation of Article 5(1)(c) GDPR, as the controller failed to comply with the principle of data minimisation. The DPA stated that the controller had failed to ensure that the cameras only captured the vehicles’ license plates, and had therefore processed more data than necessary. Finally, the DPA found a violation of Article 35 GDPR, as the controller had prepared a data protection impact assessment (DPIA) only after the processing activities began. The DPA noted that the DPIA was also no
Related Enforcement Actions (0)
No other enforcement actions found for Municipality of Vasto in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
18 June 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€5,000
GDPRhub ID
gdprhub-10142About this data
Cite as: Cookie Fines. Municipality of Vasto - Italy (2026). Retrieved from cookiefines.eu
Last updated: