The Italian authority imposes a €5,000 fine on the municipality of Vasto for transparency and data minimization failures in video processing
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against the municipality of Vasto (including the imposition of a €5,000 fine) for breaches related to the use of a video enforcement system for traffic code violations.
The case originated from a complaint by an individual who received a fine for a traffic code violation recorded by a video device, without prior information signage and without masking passengers or other vehicles.
Reasons for the decision
- Transparency and information obligation (Article 5(1)(a), Article 12(1) and Article 13 of the GDPR): The authority found that the municipality did not prove the existence of first-level information (signage) at the time of the violation. Furthermore, the signs provided later were non-compliant: they mixed several distinct purposes (urban security, judicial police, traffic control) without differentiation, indicated a generic retention period, and contained incorrect references to data subject rights. The authority also judged that the second-level information was difficult to access on the municipality's website and that the information on the fine was outdated and inaccurate, notably regarding the identity of the data controller. The authority recalls that, according to the European Data Protection Board (EDPB) Guidelines 3/2019, information must be layered, clear, and specific to the purposes pursued.
- Data minimization obligation (Article 5(1)(c) of the GDPR): The authority noted that the images of the violation communicated to the complainant showed other vehicles and their license plates without any masking. Although the municipality invoked a "purely technical error," the authority concluded a violation of the minimization principle. It relied on its previous doctrine (decision of 8 April 2010) which requires masking irrelevant elements for the violation detection, such as passengers or other road users.
- Obligation to carry out a data protection impact assessment (Article 35 of the GDPR): The authority established that the impact assessment was carried out after the video enforcement system was put into service, violating the obligation to perform it before processing begins. Moreover, the document produced was deemed incomplete (undated, unsigned, and without the opinion of the data protection officer) and too generic, as it grouped all the city's video surveillance systems without distinct and precise analysis of the specific risks related to traffic violation enforcement.
Authority's decision
Consequently, the authority imposed a €5,000 fine on the municipality of Vasto.
Furthermore, the authority ordered the municipality to bring its processing into compliance, notably by providing adequate and easily accessible first- and second-level information, and by completing its impact assessment with elements specific to each processing. The municipality must communicate the measures taken within 30 days.
Lessons learned
This decision confirms / specifies / recalls that:
- Information provided to data subjects by a video surveillance system must be specific to the pursued purpose; a generic sign covering "urban security" is not sufficient for automated enforcement processing.
- The impact assessment must imperatively be carried out before deploying a high-risk processing and must contain a detailed and specific risk analysis, not a generic evaluation for a set of similar processing operations.
- The minimization principle requires that image capture systems be configured to mask by default any information not strictly necessary for the purpose, such as passengers, pedestrians, or other vehicles not involved in the violation.
- Accessibility of second-level information is an essential transparency criterion; it must be easily found on the data controller's website via an intuitive navigation path.
- All information supports (signs, website, official documents such as fines) must be consistent, up to date, and accurate regarding GDPR requirements.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire