The Italian authority imposes a €6,000 fine on the Comune di Sciacca for unlawful dissemination of personal data
Facts and context
The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) published a sanction decision against the Comune di Sciacca, including the imposition of a €6,000 fine, for breaches related to the online publication of personal data of a former employee.
The case originated from a complaint by a former employee of the municipality, who challenged the publication on the institutional website of an administrative decision concerning him, entitled "Acknowledgment of voluntary resignation and quantification of the compensatory notice indemnity of employee XX".
Grounds for the decision
The authority found the following breaches against the municipality:
- Obligation of lawfulness and having a legal basis (Article 5(1)(a) of the GDPR and Article 6(1)(c) and (e) of the GDPR): The authority ruled that the publication of the decision constituted dissemination of personal data without an appropriate legal basis. The municipality invoked a regional law to justify the publication, but the authority considered this provision too generic and not specifically providing for the obligation to publish acts relating to an employee's resignation. It recalled that transparency obligations for public administrations are strictly defined by specific texts and do not allow the dissemination of additional personal data not provided for by these texts.
- Obligation of data minimization (Article 5(1)(c) of the GDPR): The authority emphasized that, even in the presence of a legal obligation to publish, the data controller must ensure that only strictly necessary data are disseminated. In this case, the publication of the employee's first and last name in the very subject of the act, making him directly identifiable, was excessive. The masking of his date and place of birth was deemed insufficient, as the identity of the data subject and the details of the termination of his employment contract remained public, violating the minimization principle, as specified in the "Guidelines on the processing of personal data, also contained in acts and administrative documents, carried out for publicity and transparency purposes on the web by public entities and other obliged entities" of 2014.
Decision of the authority
Consequently, the authority imposed a €6,000 fine on the Comune di Sciacca.
Furthermore, the authority ordered the publication of its decision on its website.
Lessons learned
This decision confirms that:
- A general legal obligation of transparency does not constitute a sufficient legal basis for the online dissemination of detailed personal data concerning personnel management.
- The publication of information relating to the termination of an employment relationship, including the employee's name, must be based on a specific and explicit legal or regulatory provision.
- The principle of minimization requires public entities to systematically verify the relevance of personal data before any publication, even if an act must be made public, and to mask any non-essential information.
- Partial anonymization of a document is ineffective if the data subject remains directly or indirectly identifiable by other information, such as their full name in the title of the act.
- The use of automated publication processes does not relieve the data controller of their obligation to verify the compliance of each processing with the GDPR.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire