The Italian authority sanctions the Istituto Omnicomprensivo Scuola Europea di Brindisi for forgetting to use blind carbon copy in its emailing

Sending an email to multiple recipients with their personal addresses visible constitutes a communication of data to unauthorized third parties, and therefore a data breach, even if it results from a simple human error.

Facts and context

The Italian data protection authority (Garante) published a decision issuing a warning against the Istituto Omnicomprehensivo Scuola Europea di Brindisi for failures related to the unauthorized communication of personal email addresses of its employees.

The case originated from a complaint by a member of the institute's technical-administrative staff, who reported that the personal email addresses of many recipients were visible in a bulk sending.

Reasons for the decision

The authority found the following breaches against the educational institution:

  • Obligation of lawfulness, fairness and transparency (Article 5(1)(a) of the GDPR) and having a legal basis for processing (Article 6(1)(c) and (e) of the GDPR): The institute sent, on 12 April 2025, an email regarding the elections of unitary union representatives (RSU) to forty-three employees and seven trade union organizations. The personal email addresses of all recipients were clearly listed in the "To:" field, making them visible to everyone. The authority qualified this disclosure as a communication of personal data to third parties, carried out without an appropriate legal basis. Although the institute invoked an unintentional human error in a context of work overload, the authority concluded that this error resulted in unlawful processing. However, the authority dismissed the qualification of a breach of Article 9 of the GDPR, initially considered, because the communication was addressed to all staff as potential voters and not to a restricted group of union members, thus not allowing to infer union membership.

Decision of the authority

Consequently, the authority issued a warning against the Istituto Omnicomprensivo Scuola Europea di Brindisi, pursuant to Article 58(2)(b) of the GDPR.

Furthermore, the authority ordered the publication of its decision on its website.

Lessons learned

This decision reminds that:

  • Sending bulk email communications by listing recipients' addresses in the "To" or "Cc" fields instead of "Bcc" constitutes an unauthorized communication of data to third parties, and therefore a breach of the principles of lawfulness and minimization.
  • Cooperation with the supervisory authority and the rapid implementation of corrective measures (staff training, request for email deletion, procedure modification) are key factors to mitigate the sanction, potentially allowing to avoid a fine in favor of a simple warning, even when the breach is established.
  • Communicating information related to union elections to all staff (electoral college) does not necessarily reveal the union membership of recipients and therefore does not systematically imply processing of special category data within the meaning of Article 9 of the GDPR.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire