Sanction RGPD Italian Data Protection Authority (Garante) — aiComply S.r.l. : 40 k€ (2021)

Autorité de contrôle
Italian Data Protection Authority (Garante)
Pays
Italie
Entreprise / secteur
aiComply S.r.l.
Montant de l'amende
40 k€
Date de la décision
10 juin 2021
Fondement juridique
Art. 28, Art. 32
Manquement
Mesures techniques et organisationnelles insuffisantes

Résumé des faits

The identity of whistleblowers must be protected by special confidentiality rules, as the information processed is particularly sensitive and the risk of retaliation and discrimination in the work environment is high. In this context, the controller is obliged to comply with the principles of data protection and to ensure the integrity and security of the data. Against this background, the Italian Data Protection Authority (Garante) fined Aeroporto Guglielmo Marconi di Bologna S.p.a. EUR 40,000 and its software supplier aiComply S.r.l. EUR 20,000 for violations of the GDPR. In the course of the DPA's investigation, it was found that the application for collecting and managing criminal reports was accessed without the use of a secure network protocol (e.g., the <a class='blau' href='https' target='_blank'>link</a> protocol) and that the application itself did not provide for encryption of the reporting party's identification data, the information about the report and the attached documents. The DPA considered this to be a violation of the obligation to take technical and organizational measures that ensure a level of security appropriate to the risk to the data subjects. In addition, the DPA found that aiComply failed to contractually regulate the relationships with two other companies that processed data on its behalf.

Décision officielle

Italian Data Protection Authority (Garante)

Évaluer votre conformité RGPD avec Data Comply One