The Italian authority sanctions the unlawful processing of personal data by the Comune of Aprilia in a case of non-compliant communication

The communication of a complainant's identity to the entity concerned, without an adequate legal basis and even before collecting the elements of the complaint, constitutes a violation of the principles of lawfulness and minimization, even if the controller is a public authority acting within its supervisory powers.

Facts and context

The Italian data protection authority (Garante per la protezione dei dati personali - GPDP) published a decision against the municipality of Aprilia for unlawfully communicating the personal data of an employee to their employer, a public company, following the employee's request for a meeting aimed at denouncing the management of the latter.

The case originated from a complaint by an employee who reproached the municipality for transmitting to their employer their confidential meeting request, which led to the opening of disciplinary proceedings and their dismissal.

Grounds of the decision

The authority found several breaches against the municipality:

  • Obligation of lawfulness, fairness and transparency (Article 5(1)(a) of the GDPR) and to have an appropriate legal basis (Article 6 of the GDPR): The authority held that the communication of the complainant's data to their employer was not based on a valid legal basis. Although the municipality invoked the performance of a task carried out in the public interest (Article 6(1)(e) of the GDPR) within its enhanced supervisory powers, the authority considered that the general legal provisions invoked did not constitute a sufficient legal basis within the meaning of Article 2-ter of the Italian Data Protection Code to justify the communication of a complainant's identity to the very entity they intended to denounce.
  • Purpose limitation obligation (Article 5(1)(b) of the GDPR): The municipality collected the complainant's data for the purpose of receiving information about the management of the public company. However, by immediately transmitting their request to said company to obtain "a report on the employee," it diverted the processing towards an incompatible purpose, namely an investigation into the complainant rather than the facts they proposed to denounce.
  • Data minimization obligation (Article 5(1)(c) of the GDPR): The authority considered that the communication of the complainant's identity and request was neither adequate, relevant nor limited to what was necessary. The employee's request being generic and aimed solely at obtaining an interview, the municipality should have first collected information directly from them before considering any communication to third parties, making the disclosure of their identity to their employer premature and excessive.

Authority's decision

Consequently, the authority concluded that the municipality had unlawfully communicated the complainant's personal data in violation of Articles 5 and 6 of the GDPR.

Lessons learned

This decision reminds that:

  • Handling a complaint or report requires the controller, even if a public authority, to first collect elements from the complainant before considering communicating their identity to the entity concerned.
  • Invoking a public interest task as a legal basis does not exempt demonstrating the specific necessity of communicating data to a third party; general supervisory powers do not automatically justify such disclosure.
  • The minimization principle is assessed in light of the purpose and stage of the procedure; prematurely communicating a complainant's identity constitutes a breach, even if the data transmitted are quantitatively limited (name and surname).

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire