The Italian authority sanctions the Ministry of Education for unlawful communication of personal data related to a disciplinary dismissal
The proactive and generalized communication of data related to the disciplinary dismissal of an employee to multiple administrative entities, in anticipation of a possible future application by the employee, is deemed unlawful and contrary to the principle of data minimization, since sectoral legislation provides for an ex post control mechanism based on self-declaration.
Facts and context
The Italian data protection authority (GPDP) published a decision noting breaches against the Ministry of Education and Merit for the communication of data related to the disciplinary dismissal of an employee.
The case originated from a complaint by an administrative, technical, and auxiliary (ATA) staff member of the ministry, who contested the dissemination by email of her disciplinary dismissal to numerous administrative entities.
Reasons for the decision
The authority identified a single breach encompassing several violations:
- Violation of the principles of lawfulness, fairness, and data minimization and lack of an appropriate legal basis (Article 5(1)(a) and (c) and Article 6 of the GDPR): The Disciplinary Procedures Office of the Territorial School Office of Monza and Brianza communicated by email the disciplinary dismissal of the complainant to all regional school offices, all schools under its jurisdiction, as well as to internal offices responsible for rankings, appointments, and pensions. This communication mentioned the name, first name, place and date of birth of the employee, as well as the nature of the sanction and the references of the provvedimento. The ministry justified this dissemination by the need to prevent the employee, dismissed for disciplinary reasons, from reapplying within the school administration without declaring her situation, which is a condition for exclusion. The authority rejected this argument, emphasizing that the processing of data by a public authority must be based on a precise legal basis, in accordance with Article 6(1)(c) and (e) of the GDPR, and that Italian legislation (Article 2-ter of the Data Protection Code) strictly regulates the communication of data by public entities. However, the ministry could not produce any legal provision obliging it to proactively disseminate this information. On the contrary, the regulatory texts it invoked (D.P.R. n. 487/1994 and O.M. n. 21/2009) base the recruitment procedure on the candidate's self-declaration, with the administration reserving the right to verify the truthfulness of the declarations ex post, "even by sampling" and "in case of reasonable doubt." The systematic and generalized communication, based on the mere possibility of a future fraudulent application, was therefore deemed without legal basis and disproportionate, violating the principles of lawfulness and data minimization.
Authority's decision
Consequently, the authority found that the data processing carried out by the Ministry of Education and Merit - Regional School Office for Lombardy was unlawful, in violation of Articles 5(1)(a) and (c), and 6 of the GDPR.
Lessons learned
This decision reminds that:
- The proactive and generalized communication of data related to a disciplinary dismissal to multiple entities, even within the same administration, is not justified by the mere possibility that an employee might fraudulently reapply.
- When an administrative procedure relies on a self-declaration system followed by ex post controls (even by sampling), the data controller cannot substitute it with a preventive and systematic communication of data, which would be contrary to the principle of data minimization.
- The notion of "need to know" must be interpreted strictly: mere belonging of an office to the same administration does not grant it a right of access to all personal data managed by another entity of that administration.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire