The Italian authority fines the Sardinia Region €3,000 for mistakenly disclosing a former employee's evaluation report to her new employer

The Italian data protection authority (GPDP) sanctions a regional administration for mistakenly disclosing a former employee's evaluation report to her new employer, considering that neither the protective measures applied to the transmission nor the absence of actual damage suffice to exclude a breach of the lawfulness principle.

Facts and context


The Italian data protection authority (GPDP) today published a sanction decision against the Autonomous Region of Sardinia, including the imposition of a €3,000 fine, for breaches related to the unauthorized disclosure of personal data of a former employee.


The case originated from a complaint by a former agent concerning two distinct incidents of data disclosure within the scope of her employment relationship.



Reasons for the decision


The authority first analyzed the transmission of a note concerning a disciplinary sanction to several internal services of the Region. It concluded no breach on this point, considering that the recipient services were legitimate to process this information given their respective functions (payroll management, evaluation, personnel monitoring) and the internal organization of the administration. The recipients were thus considered authorized persons within the meaning of Article 29 of the GDPR.


However, the authority found a breach regarding the second incident, which involved the transmission of the complainant's performance evaluation report to her new employer.



  • Obligation of lawfulness, fairness and transparency (Article 5(1)(a) of the GDPR) and to have a legal basis (Article 6 of the GDPR): The authority found that the Region, in response to a request for access to the complainant's documents, mistakenly sent her performance evaluation report not only to the data subject but also to the administration that had just recruited her. This transmission was qualified as disclosure of data to an unauthorized third party, lacking any legal basis. The authority rejected the Region's arguments, specifying that neither the marking "Personal and confidential" on the transmission, nor the containment measures taken afterwards, nor even the fact that the recipient's document management system limited internal access, could erase the unlawful nature of the initial disclosure. The GPDP also recalled that data protection regulations are based on a risk prevention logic, and that the absence of actual damage suffered by the data subject is not a condition to establish a violation.



Authority's decision


Consequently, the authority imposed a €3,000 fine on the Autonomous Region of Sardinia.


Furthermore, the authority ordered the publication of its decision on its website.



Lessons learned


This decision confirms that:



  • Access to employee data within an organization must be strictly limited to persons whose specific functions and duties justify such access, based on the need-to-know principle.

  • The disclosure of an employee's personal data to a third party, such as a new employer, constitutes a violation if it is not based on a valid legal basis, even if it results from human error.

  • Technical or organizational measures aimed at limiting the consequences of unlawful disclosure (e.g., confidentiality markings or post-incident containment actions) may be taken into account to mitigate the sanction but do not negate the initial violation.

  • A GDPR principles violation can be sanctioned based on the risk it poses to the rights and freedoms of individuals, without the need to demonstrate actual material or moral damage.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire