Italian political party Movimento 5 Stelle – €50,000 Fine (Italy, 2019)

€50,000Garante per la protezione dei dati personali17 April 2019Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Italian political party Movimento 5 Stelle's platform, Rousseau, was fined EUR 50,000 for not implementing required security measures after a data breach. This highlights the importance of following through on security updates to protect user data. The fine was issued to the platform's operator, not the political party itself.

What happened

The Rousseau platform failed to implement necessary security measures after a data breach, leading to a fine.

Who was affected

Users of the Rousseau platform, which is affiliated with the Italian political party Movimento 5 Stelle, were affected.

What the authority found

The Italian data protection authority fined the platform's operator for not adopting required security measures under GDPR.

Why this matters

This case emphasizes that even if a data breach occurs before GDPR, failing to implement security measures afterward can still result in fines. It serves as a reminder for organizations to prioritize data security and comply with regulatory orders.

GDPR Articles Cited

Art. 32 GDPR
Full Legal Summary
Detailed

A number of websites affiliated to the Italian political party Movimento 5 Stelle are run, by means of a data processor, through the platform named Rousseau. The platform had suffered a data breach during the summer 2017 that led the Italian data protection authority, the Garante, to require the implementation of a number of security measures, in addition to the obligation to update the privacy information notice in order to give additional transparency to the data processing activities performed.While the update of the privacy information notice was timely completed, the Italian data protection authority, raised its concerns as to the lack of implementation on the Rousseau platform of some of GDPR related security measures. It is worth it to mention that the proceeding initiated before May 2018, but the Italian data protection authority issued a fine under the GDPR since the Rousseau platform had not adopted security measures required by means of an order issued after the 25th of May 2018. Interestingly, the fine was not issued against the Movimento 5 Stelle that is the data controller of the platform, but against the Rousseau association that is the data processor.

Related Enforcement Actions (0)

No other enforcement actions found for Italian political party Movimento 5 Stelle in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

17 April 2019

Authority

Garante per la protezione dei dati personali

Fine Amount

€50,000

Enforcement Tracker ID

ETid-39

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Italian political party Movimento 5 Stelle - Italy (2019). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: