Bar association – €20,000 Fine (Italy, 2023)

€20,000Garante per la protezione dei dati personali31 August 2023Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An Italian bar association was fined €20,000 for not removing sensitive court documents from its website. These documents could be viewed and downloaded by anyone, violating privacy rights. This case highlights the importance of protecting personal information online.

What happened

The bar association failed to delete court documents that could be accessed publicly despite requests from individuals.

Who was affected

Individuals involved in a court case whose documents were publicly accessible on the bar association's website.

What the authority found

The Italian DPA found that the bar association did not comply with privacy rules by failing to remove sensitive documents.

Why this matters

This ruling emphasizes that organizations must take immediate action to protect personal data when requested. It serves as a reminder for all businesses to regularly review their data handling practices.

GDPR Articles Cited

Art. 2-octies Codice della privacy GDPR
Art. 5 GDPR
Full Legal Summary
Detailed

The Italian DPA has imposed a fine of EUR 20,000 on a bar association. Two individuals had filed a complaint with the DPA against the controller because documents relating to a court case concerning them could be viewed and downloaded in non-anonymous form on the association's website. In addition, the documents were available to be found via Google search. The association had failed to delete the documents even after repeated requests for deletion by the data subjects.

Related Enforcement Actions (0)

No other enforcement actions found for Bar association in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

31 August 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€20,000

Enforcement Tracker ID

ETid-2083

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Bar association - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: