The Italian authority sanctions the municipality of Villaputzu for the unlawful publication of an employee's personal data
The publication of an administrative decision mentioning the registration number and the reason for the termination of a public agent's employment contract, even in the absence of their name, constitutes unlawful disclosure of personal data, as the agent remains identifiable by the context.
Facts and context
The Italian data protection authority (Garante) has today published a sanction decision against the municipality of Villaputzu (including the imposition of a fine of €2,000) for breaches related to the online publication of personal data of one of its agents.
The case originated from a complaint by a municipal agent who reported the publication on the municipality's website of a decision containing their registration number and the reason for the termination of their employment contract following an unsuccessful probation period.
Reasons for the decision
The authority found the following breaches:
- Obligation of lawfulness, fairness, transparency, and data minimisation (Article 5(1)(a) and (c) of the GDPR): The authority ruled that the publication of the administrative decision was not compliant with these principles. It emphasized that even without the agent's name, they were easily identifiable by their registration number combined with contextual information (small municipality, reason for contract termination). The indication of the registration number was all the more superfluous as the decision mentioned an unpublished annex containing the full name of the person concerned, demonstrating a failure to minimise data.
- Obligation to have a legal basis for processing (Article 6 of the GDPR and Article 2-ter of the Italian Code): The municipality could not demonstrate the existence of a specific legal or regulatory provision authorising it to disclose personal data relating to the termination of an employment contract. The authority recalled that the general obligations of publicity of administrative acts, notably those provided for by Article 124 of Legislative Decree 267/2000, do not constitute a sufficient legal basis to derogate from data protection principles and cannot justify online disclosure of such information.
Authority's decision
Consequently, the authority imposed a fine of €2,000 on the municipality of Villaputzu.
Lessons learned
This decision confirms that:
- A registration number, combined with contextual information (such as the reason for a decision or the size of the entity), does not constitute an anonymisation measure and allows identification of a person, making the processing subject to the GDPR.
- General legal obligations to publish administrative acts do not create an automatic right and cannot serve as a legal basis for online disclosure of personal data, which must be provided for by a specific provision and respect the principle of minimisation.
- Before any publication, the controller must assess the necessity of each personal data included in the document and ensure that no superfluous information is disclosed, in accordance with data protection principles by design and by default.
- Good faith or the mistaken belief of acting in compliance with the law does not exempt the controller from liability in case of breach, although it may be considered as a mitigating factor in determining the amount of the sanction.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire