Magna PT S.p.A. – €50,000 Fine (Italy, 2025)

€50,000Garante per la protezione dei dati personali10 July 2025Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Magna PT S.p.A. was fined for conducting 'return to work interviews' that didn't follow the rules for handling health data. This matters because it shows that companies must have a valid reason to process sensitive information and must inform employees properly. The fine of EUR 50,000 highlights the importance of compliance with data protection laws.

What happened

Magna PT S.p.A. conducted interviews with employees returning from illness without a valid legal basis for processing their health data.

Who was affected

Employees of Magna PT S.p.A. who returned to work after illness or hospitalization were affected.

What the authority found

The Italian data protection authority ruled that the company lacked a valid legal basis for processing health data and failed to inform employees about this processing.

Why this matters

This case emphasizes the need for companies to ensure they have valid reasons for processing sensitive data, especially health information. It serves as a reminder for businesses to review their data handling practices to avoid similar penalties.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 9(GDPR)
Art. 13(GDPR)
Art. 5(1)(a) GDPR
Art. 88(GDPR)
View original scraped data
Art. 5(1) a) GDPR
c)
e) GDPR
Art. 6(GDPR)
Art. 9(GDPR)
Art. 13(GDPR)
Art. 88(GDPR)

Original data from scraper before AI verification against source document.

Source verified 12 March 2026
articles corrected
national law identified
Full Legal Summary
Detailed

The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or hospitalisation. These interviews lacked a sufficient legal basis, particularly with regard to the processing of health data. Additionally, the controller failed to adequately inform the data subjects regarding the processing. Furthermore, the controller failed to minimise the amount of data processed and the retention period to only what was necessary.

Related Enforcement Actions (0)

No other enforcement actions found for Magna PT S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 July 2025

Authority

Garante per la protezione dei dati personali

Fine Amount

€50,000

Enforcement Tracker ID

ETid-2768

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Magna PT S.p.A. - Italy (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: