Autostrade per l'Italia spa – €1,000,000 Fine (Italy, 2023)

€1,000,000Garante per la protezione dei dati personali22 June 2023Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Autostrade per l'Italia spa was fined €1 million for mishandling user data from its toll reimbursement app, 'Free to X.' The company failed to properly inform users about who was in charge of their data, which is important for transparency and trust.

What happened

Autostrade per l'Italia spa unlawfully processed the data of about 100,000 users of its toll reimbursement app.

Who was affected

Registered users of the 'Free to X' app who sought toll refunds for delays caused by roadworks.

What the authority found

The Italian data protection authority ruled that Autostrade was incorrectly identified as a data processor instead of the data controller, violating GDPR's transparency requirements.

Why this matters

This case highlights the need for companies to clearly define their roles in data processing and ensure users receive accurate information. It serves as a reminder for businesses to review their data handling practices to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 13 GDPR
Art. 28 GDPR
Art. 5(1)(a) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 13 GDPR
Art. 28 GDPR

Original data from scraper before AI verification against source document.

Source verified 5 March 2026
articles corrected
Full Legal Summary
Detailed

The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx. 100,000 registered users of the toll reimbursement app 'Free to X.' A consumer organization reported problems with the service, which provides toll refunds for delays caused by roadworks, to the DPA. The DPA found that Autostrade held the position of the data controller, instead of a processor, as stated in the documents governing the relationship between 'ASPI' and 'Free to X', the company that develops and operates the app, as well as in the information notice given to users. In fact, 'ASPI', as the operator of the highway network, was responsible for determining the reimbursement mechanism, the type of compensation measures, the processing and the causes of delays due to road works. 'Free to X' was only tasked with implementing the service. This incorrect assignment of privacy roles resulted in the notice to users being incorrect. The notice should have included the actual identity of the controller, namely ASPI, as well as all the necessary information for proper and transparent processing in accordance with data protection laws. The DPA finally found that ASPI also violated the GDPR by not designating Free to X as a processor.

Related Enforcement Actions (0)

No other enforcement actions found for Autostrade per l'Italia spa in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

22 June 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€1,000,000

Enforcement Tracker ID

ETid-2023

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Autostrade per l'Italia spa - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: