The Italian authority sanctions Edizioni Grandangolo for security and transparency failures
Facts and context
The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) today published a sanction decision against the sole proprietorship Edizioni Grandangolo of Giuseppe Castaldo (including the imposition of a fine of €2,075) for breaches related to the notification of a data breach, processing security, and transparency of information.
The case originated from a complaint by an individual concerning the online persistence of an article reporting their disappearance when they were a minor and the lack of response to their deletion request.
Reasons for the decision
- Obligation to notify a data breach to the supervisory authority (Article 33 of the GDPR): The controller did not notify the authority of a cyberattack that compromised an editorial email account. The authority rejected the argument that the risk was unlikely, considering that such an account, especially in a journalistic context, contained a significant amount of varied personal data (identity documents, financial information). Relying on Recitals 75 and 76 of the GDPR and the "Guidelines 9/2022 on personal data breach notification" of the European Data Protection Board (EDPB), the authority judged that the nature and combination of the exposed data presented a non-negligible risk to the rights and freedoms of individuals, making notification mandatory.
- Obligation to ensure processing security (Article 5(1)(f) and Article 32 of the GDPR): The authority concluded that the technical and organizational measures were insufficient before the incident. The very fact that unauthorized access occurred and that the controller only implemented enhanced security measures after the authority's intervention demonstrates a prior failure to ensure the integrity and confidentiality of data.
- Obligation to provide transparent information (Article 12(1) and (2), and Article 13 of the GDPR): The publisher's website lacked a privacy policy. The authority refuted the argument of a "temporary technical malfunction" by using the web archive service (WayBack Machine), which proved the absence of any information on data processing over a five-year period (2020-2025). This prolonged deficiency constituted a substantial obstacle to the principle of transparency and to the ability of data subjects to exercise their rights.
- Obligation of accountability (Article 5(2), Article 24 and Article 25 of the GDPR): The totality of the breaches led the authority to conclude a general negligence and a violation of the accountability principle. The controller failed to demonstrate compliance, thus failing its obligations of data protection by design and by default.
Authority's decision
Consequently, the authority imposed a fine of €2,075 on Edizioni Grandangolo of Giuseppe Castaldo.
Furthermore, the authority ordered the publication of its decision on its website.
Lessons learned
This decision reminds that:
- The risk assessment of a data breach must be objective and documented; unauthorized access to an email account, especially in a journalistic context, is unlikely to present an "unlikely" risk justifying no notification to the authority.
- The implementation of enhanced security measures only after an incident does not relieve the controller of responsibility for prior failures that allowed the incident to occur.
- The prolonged absence of a privacy policy constitutes a serious breach, and supervisory authorities can use technical tools, such as web archives, to verify the truthfulness of a controller's claims.
- General negligence in compliance management, demonstrated by an accumulation of breaches (security, transparency, notification), characterizes a violation of the accountability principle.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire