The Italian Garante imposes a 15,000 euro fine on the University of Pisa for its non-compliant exam platform
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against the University of Pisa, including the imposition of a fine of €15,000, for breaches related to data security and the lawfulness of processing on its exam registration portal.
The case began with a report indicating that it was possible, via the exam registration portal, to view the list of registrants, see their information, and even cancel their registrations.
Reasons for the decision
Following an investigation, the authority found a malfunction on the "EVALUATE-ME" platform used for managing exam registrations. An update to an Application Programming Interface (API) caused a technical defect: the field containing the student's registration number was returned as an empty string instead of a null value. For about an hour, this anomaly allowed logged-in students to view data (name, first name, institutional email address) of other students simultaneously authenticated and to intervene on their registrations, resulting in the erroneous cancellation of 156 registrations for 137 affected students. The university subsequently restored the cancelled registrations.
- Obligation of lawfulness, fairness, and transparency of processing (Article 5(1)(a) of the GDPR and Article 6 of the GDPR): The authority found that the malfunction led to the communication of personal data to unauthorized third parties (other students) without any valid legal basis. The university's argument based on the principle of exam publicity was dismissed. The authority emphasized that this incident was not part of the normal operation of the platform but an indiscriminate access to data of students registered for different exam sessions, which is not covered by any legal or regulatory provision.
- Obligation of data protection by design and by default (Article 25 of the GDPR): The authority considered that the university had not implemented appropriate technical and organizational measures from the design of the system. The absence of robustness checks to verify data consistency, notably to handle the case of an empty string returned by the API, was considered a failure in integrating the necessary safeguards to protect the rights of data subjects.
- Obligation of security of processing (Article 32 of the GDPR): The lack of validation and anomaly management mechanisms was qualified as an inadequate security measure. This deficiency directly compromised the confidentiality of data by exposing it to unauthorized persons, as well as its integrity and availability by allowing illegitimate modifications (cancellations of registrations). The security level was therefore not appropriate to the risk.
Authority's decision
Consequently, the authority imposed a fine of €15,000 on the University of Pisa.
Furthermore, the authority ordered the publication of its decision on its website.
Lessons learned
This decision reminds that:
- The robustness of application code, notably the ability to handle error scenarios even deemed unlikely such as receiving an empty string instead of a null value, is an essential component of the technical measures under Article 32 of the GDPR.
- A legal basis authorizing the publicity of certain information (such as the list of exam registrants) cannot justify a broader communication of data resulting from a technical malfunction.
- Data protection by design requires integrating consistency and validity checks of data, particularly when interacting between different systems or when using application programming interfaces (APIs).
- Cooperation with the authority, absence of prior infringements, the non-intentional nature of the violation, and the prompt implementation of corrective measures are significant mitigating factors in determining the amount of the fine.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire