The Italian authority imposes a €1,000 fine on Istituto Professionale Statale Pietro d'Abano for unlawful communication of a student's personal data
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against the Istituto Professionale Statale Pietro d'Abano (including the imposition of a €1,000 fine) for breaches related to the unlawful communication of a student's personal data.
The case originated from a parent's complaint following the publication of a note concerning their son in a section of the electronic register accessible to the entire class and the parents of students.
Grounds for the decision
- Obligation of lawfulness of processing (Article 5(1)(a) of the GDPR and Article 6 of the GDPR): The authority found that a teacher had published a note about a student in the "Agenda" section of the electronic register, making it visible to the entire class and parents. Although resulting from a handling error, this action constitutes communication of data to unauthorized third parties. The authority deemed this processing unlawful, as it was not based on any valid legal basis within the meaning of Article 6(1)(c) and (e), 2 and 3 of the GDPR, and specific provisions of national law (Article 2-ter of the Italian Code) which only allow communication of data by public entities if provided for by a legal or regulatory norm. The authority emphasized that responsibility lay with the institution as the controller, not the teacher, referring to the European Data Protection Board (EDPB) Guidelines 07/2020 and the CJEU ruling C-741/21.
Authority's decision
Consequently, the authority imposed a €1,000 fine on the Istituto Professionale Statale Pietro d'Abano.
Furthermore, the authority ordered the publication of its decision on its website, justifying this measure by the fact that the violation concerned the data of a minor, considered a particularly vulnerable person.
Lessons learned
This decision confirms / specifies / recalls that:
- The responsibility for a data breach caused by an employee's error lies with the organization as the controller, which cannot exempt itself by invoking mere negligence of its staff.
- The provision of personal information about a student, even to a restricted group such as their class and parents, constitutes a "communication" of data that must be based on a solid legal basis and cannot be justified by a simple error.
- Personal data of minors, notably those relating to assessments or disciplinary measures, require enhanced protection due to their particular vulnerability, as emphasized in Recital 38 of the GDPR.
- Cooperation with the authority, absence of prior infringements, the non-intentional nature of the violation, and prompt corrective measures are determining factors for reducing the amount of an administrative fine.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire