The Italian authority imposes a 1000 euro fine on a cooperative for failing to respect data subject access rights

A data controller was sanctioned for completely ignoring a data subject access request and subsequently the supervisory authority's inquiries, illustrating a compounded failure to comply with obligations to respond to the data subject and to cooperate with the authority.

Facts and context

The Italian data protection authority (Garante) has today published a sanction decision against the Cooperativa Sociale Leontinoi, including the imposition of a €1,000 fine, for breaches related to the failure to comply with a data subject access request and lack of cooperation with its services.

The case originated from a complaint by a person who received no response to their request for access to their personal data.

Grounds for the decision

  • Obligation to respond to rights exercise requests (Article 12 and Article 15 of the GDPR): The authority found that the data controller provided no response to the access request made by the complainant. By doing so, it failed to meet its obligation to provide information on the actions taken in response to the request within one month, in violation of Article 12(3) of the GDPR. Furthermore, it also failed to inform the data subject of the reasons for its inaction and the available remedies, as required by Article 12(4) of the GDPR.
  • Obligation to cooperate with the supervisory authority (Article 31 of the GDPR): The data controller did not respond to the information request sent by the authority during the complaint investigation. The authority recalls that this cooperation obligation, provided for by Article 31 of the GDPR and Article 157 of the Italian Data Protection Code, is a fundamental duty, as confirmed by the case law of the Italian Court of Cassation (Cass. 12 June 2018, no. 15332).
  • Obligation of lawfulness and fairness of processing (Article 5(1)(a) and Article 6 of the GDPR): The authority considered that the overall conduct of the data controller, ignoring both the data subject and the supervisory authority, constituted a violation of the fundamental principles of fairness and lawfulness of processing.

Authority's decision

Consequently, the authority imposed a €1,000 fine on the Cooperativa Sociale Leontinoi.

Furthermore, the authority ordered the data controller to comply with the complainant's access request within thirty days and to provide proof thereof.

Lessons learned

This decision reminds that:

  • The total absence of response to a rights exercise request constitutes an autonomous violation of the GDPR, regardless of the legitimacy of the underlying processing.
  • The duty to cooperate with the supervisory authority is a distinct and imperative obligation; non-compliance is considered an aggravating factor when determining the sanction.
  • Even small or socially oriented organizations are required to comply with the fundamental procedural obligations of the GDPR, notably responding to data subjects and cooperating with the authority.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire