XXX – €70,000 Fine (Italy, 2022)

€70,000Garante per la protezione dei dati personali16 June 2022Italy
final
ePrivacy
Fine

Unicredit was fined EUR 70,000 for not properly handling an employee's request to access their personal data. The Italian authority found that the company required the employee to fill out a form, which was not necessary for accessing the data. This case highlights the importance of responding to data access requests without unnecessary hurdles.

What happened

Unicredit required an employee to fill out a form to access their personal data, which was not necessary.

Who was affected

An employee of Unicredit who wanted to access their personal data.

What the authority found

The Italian authority ruled that Unicredit violated GDPR by making it unnecessarily difficult for the employee to access their data.

Why this matters

This decision emphasizes that companies must make it easy for individuals to access their personal data and cannot impose unnecessary conditions. Businesses should ensure their data access procedures are straightforward and comply with GDPR requirements.

GDPR Articles Cited

AI-verified

Art. 12(GDPR)
Art. 15(GDPR)
Art. 5(1)(a) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 12(GDPR)
Art. 15(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

PERSONAL DATA PROTECTION CODE enacted via Law No 178 of 23 November 2021

Entities Involved

XXX
Unicredit S.p.A.
Source verified 12 March 2026
articles corrected
Full Legal Summary
Detailed

The case focused on a right of access issue where the data subject claimed insufficient information was provided by the controller.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for XXX in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

16 June 2022

Authority

Garante per la protezione dei dati personali

Fine Amount

€70,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. XXX - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: