Garante per la protezione dei dati personali (Italy) - 10146337

From GDPRhub
Garante per la protezione dei dati personali - 10146337
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 28(3) GDPR
Article 32(1) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 29.04.2025
Published:
Fine: 20,000 EUR
Parties: Cooperativa Quadrifoglio s.c. Onlus
National Case Number/Name: 10146337
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: cci

The DPA fined a social enterprise €20,000 over a data breach involving sensitive data of special needs children.

English Summary

Facts

Cooperativa Quadrifoglio (the processor) was a social enterprise with a staff of about 3,000 people. The processor provided support and educational services to special need students (the data subjects) as a subcontractor of the municipality of Bologna (the controller). In order for the provider to provide its services, the controller shared information about the data subjects with the processor.

The processor was unable to provide some of its services for one day due to a worker strike. The processor emailed the controller about the interruption of certain services. In turn, the controller forwarded the communication to numberous staff members and to 53 families of children who attended two schools within the municipality[1].

Due to a human error, the processor attached unnecessary documents to the email, including a list of 61 data subjects who relied on the controller’s services. The list was not pseudonymized and included the data subjects' name and other information, such as detailed information about their health status and the accomodations they needed in school. The controller did not notice the attachment and forwarded it to the families along with the email.

The DPA received a complaint related to the incident. Aside from the procedure with the DPA, the processor agreed to cover €2,000 in damages in favor of a data subjects' family, following an amicable settlement between the family and the controller.

Holding

The DPA held that the documents contained sensitive data from the data subjects. Furthermore, the DPA held that including the data in the documentation was unnecessary for informing the controller about the service interruptions. On these grounds, the DPA held that the processor violated its duty to process data securely, in violation of Articles 28(3) and 32(1) GDPR.

The DPA fined the processor for €20,000. In this regard, the DPA considered that the incident was due to a human error and that the processor later implemented stricter data policies, including the pseudonymization of the subjects' data in its communications with the controller.

Comment

The decision includes a reminder that processors must take an active role to ensure an adequate level of security for the processing- if necessary, by supplementing the security measures explicitly listed in the data processing agreement.

The DPA also fined the controller €40,000 over the same incident: see Garante per la protezione dei dati personali, provv. 10146543. As mentioned in the footnotes, this decision includes a more detailed explanation of the facts leading to the breach.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10146337]

Provision of April 29, 2025

Register of Provisions
No. 274 of April 29, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Claudio Filippi, Acting Secretary General;

CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. The Complaint.

In a complaint filed with the Authority, Ms. XX complained that the Quadrifoglio social cooperative (hereinafter "the cooperative"), "which manages certain school services on behalf of the Municipality," had "sent to the Municipality of Bologna, preschool office (ServiziZeroSei), an Excel file with three worksheets: the first indicating that its workers had joined a strike; the other two sheets (Disability and Exceptions), with a list of children with disabilities and special needs, with detailed and sensitive information (pathology and various notes).

2. The preliminary investigation.

With a note dated XX (ref. no. XX), to which reference is made in full, the cooperative responded to the request for information made by the Guarantor on XX (ref. no. XX), stating, in particular, that:

- "On XX, the Municipality of Bologna awarded the service of managing educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the qualification of the curriculum in the city's preschools to the TEMPORARY CONSOLIDATION OF JOINT VENTURES between COOPERATIVA SOCIALE QUADRIFOGLIO (Agent) and O.R.S.A. SOCIAL COOPERATIVE COMPANY (Client) for period XX with the option of renewal for an additional two school years”;

- “pursuant to the Tender Specifications, the Quadrifoglio Social Cooperative (hereinafter the "Agent") is required to inform the Municipality of Bologna (hereinafter the "Client") of any disruptions to service (e.g., strikes). The Agent undertakes to notify the Client of any union strikes resulting in staff absences and the consequent need to reorganize services. Subsequently, the Client shall inform the respective school services; Finally, the communication was sent by school services to families.

- "For service management, the Client shall send the Agent's pedagogical coordination service, before the start of the school year, a document containing the sensitive data relating to the minors in their care (name, surname, date and place of birth, citizenship, type of disability, ICD-IO code), necessary for the activation and management of the school inclusion service for minors with disabilities."

- "On the occasion of a general strike called for the XXth day, the Agent sent an email to the Client (dated XX), according to the procedure described above, to report the services not provided for the strike day. It is noted that the email, signed by (...) coordinator of the integrative and school inclusion services of the municipal preschools in the Borgo-Reno, Navile, and Porto-Saragozza areas, contained six attached files relating to the services available in the six Bologna neighborhoods. The files relating to the Borgo-Reno, Navile, and Porto-Saragozza areas contained two sheets: the first, updated in content, starting from the document received from the Municipality at the beginning of the year (...) containing only information regarding the closure/opening of supplementary services on the strike day indicated above; the second sheet, however, incorrectly maintained, contained information relating only to the school inclusion service, thus retaining sensitive data relating to minors in its care.

- "The aforementioned email contained the following notice at the bottom: 'ATTENTION: The content of this message is intended solely for the persons to whom it is addressed and may contain information whose confidentiality is legally protected under the terms of the current European Regulation 679/2076 on privacy - GDPR.'"

- "On XX, the Mandatory Cooperative became aware of a personal data breach, through an official notification from the Bologna Services Coordinator."

- "After verifying the incident, the Agent promptly proceeded (...), sending a service complaint against the worker (...), due to gross negligence in her duties, inviting her to submit her counterarguments within 5 days (...). The response received from the worker (...) identified that the communication regarding the June 11 strike had been sent only to individuals already in possession of the sensitive data erroneously transmitted by the coordinator";

- "Following a coordination meeting between the Client Entity (...) and the Mandatory Cooperative (...) to review the facts and provide an overview of the measures to be implemented, it was agreed to establish implementing measures for the processing of personal data (...). In response, the Mandatory Cooperative's Privacy Management Office developed a "Privacy Measures Implementation Plan";

- "On XX, the Client conducted a privacy and IT security audit at the Mandatory Cooperative's headquarters, in order to verify the management system at issue":

- "On XX, the Client sent a report (...) requesting the imposition of a penalty of €2,000 against the Mandatory Cooperative (...). Following a request for compensation made by one of the families affected by the accident, of which the Client had communicated to the Agent as the party involved and required to respond (…), the penalty previously applied was revoked by the Client; In fact, compensation was awarded to the family who had requested it for the incident.

Based on the information acquired, the Office notified, pursuant to Article 166, paragraph 5 of the Code, with note dated XX (prot. no. XX), the cooperative, as the data controller designated by the Municipality of Bologna pursuant to Article 28 of the Regulation, of the initiation of the procedure for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, concerning the alleged violations of Articles 28 and 32 of the Regulation, inviting the aforementioned entity to submit written defenses or documents to the Guarantor or to request a hearing by the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of 24 November 1981).

The cooperative submitted its defense briefs, with Note of XX, to which reference is made in full, stating, in particular, that:

- "is entrusted with the management of educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the qualification of the curriculum in preschools in the Municipality of Bologna (...) since the month of XX";

- "In order to perform this service, it was necessary to process sensitive and health data, among other things, of minors receiving educational support. In relation to this purpose, the Municipality of Bologna assumes the role of Data Controller and the undersigned Cooperative assumes the role of Data Processor. Within the scope of this relationship, the Municipality of Bologna, in fulfillment of its obligations related to the role, has issued instructions for data processing to the Data Processor (...). No specific requirements regarding the need to use data encryption tools have been issued by the Data Controller. The agreement is limited to a general reference to the provisions of art. 28 GDPR";

- "In order to enable the planning of the services requested from the Cooperative, the Municipality of Bologna, through its authorized data processors (both sensitive and health-related), sends the heads of the individual Territorial Units, before the start of the school year, files containing the names of the minors receiving support, along with an indication of the conditions justifying the support. This documentation is essential for the provision of the service.The files containing the names of minors and their respective medical conditions are transmitted by the Municipality of Bologna to the undersigned Cooperative, via the Local Managers, without any coding;

- "On the occasion of the general strike called for the 20th, the Cooperative sent an email to the Municipality of Bologna (dated 20th), (...) to report the services not provided for the strike day."

- "The Cooperativa Quadrifoglio s.c. Onlus has been providing services to minors, disabled people, and the elderly for over 40 years. This has involved the processing of a huge amount of sensitive and health data. They have always been processed in accordance with the provisions of the applicable regulations, and the undersigned had never, prior to the current dispute, received a complaint regarding the alleged undue communication and/or loss and/or destruction of data protected by the aforementioned regulations.

- "The Guarantor's attention is drawn to the fact that the Cooperative, as Data Processor, managed the data provided to it by the Data Controller in compliance with the instructions received from the latter. The files subject to communication (deemed undue) were processed by the Data Processor and returned to the Data Controller in the manner in which they were received."

- "It would be unjustified to assume that the Data Processor should have used organizational measures superior to those defined and used by the Data Controller, especially considering that the Data Processor has always and exclusively dealt with the Data Controller."

- "It should be noted that the obligations set forth in Article 28 of the aforementioned Legislative Decree no. generically attributes to the Data Controller, are deemed to be fulfilled by the precautions adopted, as they appear proportionate to the risk inherent in sharing data solely with the Data Controller";

- "it is noted that a data breach cannot automatically be identified from the mere sending of a single email to multiple recipients (the heads of territorial units), as each of them was authorized to process the data. The respective file was clearly identified by name;

- "the data was processed in accordance with the purposes indicated by the Data Controller, namely, to communicate the strike that would have affected child support services."

- "in light of the above, it is clear that the conduct described does not constitute a subjective element of negligence (much less intent), given that the communication was made to individuals already authorized to process the data and in compliance with the instructions issued by the Data Controller."

- "the Cooperative promptly took action to mitigate the effects of the breach and to adopt the necessary technical and organizational measures to improve the security of personal data processing in compliance with applicable legislation. The Cooperative, also as a result of its collaboration with the Client, awarded compensation to the family who had requested it in light of the incident;

- "The Cooperative subsequently developed a 'Privacy Measures Implementation Plan' (...), including an information/training session on the management system for all affected personnel."

- "The Cooperative also initiated disciplinary proceedings against the operator responsible for data processing."

- "Any violation, which was not substantiated, would have had no detrimental effects on the minors, as communication was limited to individuals within the Data Controller's organization."

During the hearing held on XX, the cooperative stated, among other things, that:

- "At the beginning of each school year, the Municipality, the data controller, sends the cooperative a single file, divided into various tables corresponding to the different neighborhoods, containing the data of students with disabilities; The file contains the names of the schools, student data, the number of hours covered by the educational service, and the types of conditions the students with disabilities have.

- "Whenever the cooperative needs to notify the Municipality of a service interruption/change, it must use this file, indicating the staff members who are absent from the service, for example, on strike. The Municipality will send this file to the various schools in the various districts to let them know that, on a certain date, the staff member assigned to that particular student will not be available."

- "Following the report in question, the data controller has engaged the cooperative to identify measures to prevent further data leakage and better protect privacy. A data encryption mechanism has therefore been introduced in the file described above, i.e., a pseudonymization tool. This means that the file no longer contains the first name, last name, or initials of the first and last names of the students, but rather an alphanumeric code associated with each individual student. The communication methods are therefore unchanged; what has been modified is the student identification tool (no longer using the clear name and surname but an alphanumeric code)";

- "this tool was created by the cooperative staff in collaboration with the Municipality staff";

- "the cooperative's collaborative attitude with the Municipality and the Authority is emphasized. It should be noted that the cooperative has approximately 3,000 worker members and provides services to people, especially the elderly, disabled, and minors. In recent years, the economic situation has been challenging due to several factors, primarily COVID-19, which has resulted in significant expenditures for worker protection, with very expensive personal protective equipment (PPE) and a decline in revenue due to the reduction in beds in residential care facilities and a reduction in school services. There has been an increase in utility costs (electricity, gas) in various residential facilities, and finally, contractual increases have increased costs that many public/private clients are no longer able to afford and pay, resulting in a consequent burden on the cooperative.

- "The cooperative has been working in the field of school inclusion for approximately 40 years. It has always processed a large amount of data, including sensitive data, of vulnerable students/elderly people it supports, and has never incurred, prior to the incident in question, any violation of personal data protection."

3. Applicable legislation.

3.1 The regulatory framework.

The data protection framework established by the Regulation provides that the processing of personal data by entities operating in the public sector is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

With regard to special categories of personal data, processing is generally permitted when "necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection, and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in national legal systems, by laws, regulations, or general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest ground, as well as the suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

Pursuant to Article 28 of the Regulation, the data controller may also entrust processing to third parties who: sufficient guarantees regarding the implementation of appropriate technical and organizational measures to ensure that the processing complies with the applicable data protection legislation (Article 4(8) of the Regulation).

In this case, "processing by a processor shall be governed by a contract or other legal act under Union or Member State law, which is binding on the processor with respect to the controller and which specifies the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller" (Article 28(1) and (3) of the Regulation).

The Regulation also regulates the obligations and other forms of cooperation to which the processor is subject when acting on behalf of the controller and the scope of their respective responsibilities (see Articles 30, 32, 33(2) and 82 of the Regulation).

In this regard, the Regulation also requires the controller and the processor to implement "appropriate technical and organizational measures" (Article 28(1) and (3) of the Regulation). organizational measures to ensure a level of security appropriate to the risk”, taking into account, among other things, “the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons (…) which include, among others, (…) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services (…) When assessing the appropriate level of security, special account shall be taken of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” (Article 32, paragraph 1, letter b) and 2 of the Regulation).

Article 32 of the Regulation, therefore, requires both the data controller and the data processor to adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risk. As previously clarified by the Garante, the data processor, based on their respective responsibilities, must cooperate, including by demonstrating independent decision-making, in adopting appropriate measures and systematically verifying their effectiveness, especially when providing services involving a large number of data subjects, as in the case at hand (see provisions no. 48 of February 11, 2021, web doc. no. 9562831 and no. 293 of July 22, 2021, web doc. no. 9698597, 419 of December 2, 2021, web doc. no. 9733053).

3.2 The processing of personal data carried out by the cooperative.

From what emerges from the complaint in question, as well as from the investigation conducted based on the information acquired, following the investigation and subsequent assessments by this Department, it appears that, in anticipation of the strike called for the XXth by the cooperative's workers, the cooperative's representative sent an email to the Municipality of Bologna and the heads of the local units. The email contained six Excel files, one for each district of the city, containing a list of supplementary services not guaranteed as a result of the strike, broken down by school.

Some of these documents, however, contained not only information regarding the management of possible reductions in supplementary services on the day of the strike, but also personal data relating to the health of children enrolled in certain preschools. Specifically, these documents contained, in addition to the names of the students, their place, date of birth, and citizenship, information regarding the types of disabilities, the specific pathologies suffered by the minors, the disability classification code (ICD10 code), and any certifications held by the students, as well as an indication of the resources for school integration (teachers/educators) assigned to the students and certain annotations.

As a preliminary point, it is noted that minors, as "vulnerable natural persons," deserve "specific protection with regard to their personal data, as they may be less aware of the risks, consequences, and safeguards concerned, as well as of their rights in relation to the processing of personal data" (recital no. 38 of the Regulation).

It is also noted that, pursuant to Article 4(1), no. 15 of the Regulation, "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her state of health" are considered data relating to health.

Considering the definition of personal data and health data (Article 4, points 1 and 15, of the Regulation), it is believed that the information regarding the types of disabilities reported in the aforementioned files, the indication of their classification code and the certifications held or not by the children, as well as the assignment of resources for school integration (teachers/educators) to the students, allow us to obtain information on the health status of the minors listed.

Given the above, it is submitted that the cooperative, in sending the documentation containing the above information, which was superfluous to the purposes it intended to achieve (the mere communication of possible reductions in supplementary services on the day of the strike), did not use the necessary expertise to prevent such information from being made available to the aforementioned parties, in violation of the instructions provided by the data controller, pursuant to Article 28 of the Regulation.

Indeed, the contract signed between the Municipality and the cooperative on XX provides, among other things, that the data controller:

- "processes such personal data only for the purposes of performing the contract and, thereafter, only in accordance with any written agreement between the Parties, therefore acting exclusively on the basis of documented instructions provided by the Entity";

- "before initiating any processing and, where necessary, at any other time, will inform the Entity if, in its opinion, any instructions provided by the Entity violate applicable law";

- "is obliged to adopt: appropriate procedures to ensure respect for the rights and requests made to the Entity by data subjects regarding their personal data";

- "must guarantee and provide the Entity with cooperation, assistance, and any information that may reasonably be requested by the latter, to enable it to fulfill its obligations under applicable law, including the provisions and specific decisions of the Italian Data Protection Authority";

- "must adopt and maintain appropriate security measures, both technical and organizational, to protect personal data from any unlawful or accidental destruction or loss, damage, alteration, unauthorized disclosure or access, and in particular, where the processing involves the transmission of data over a network, from any other unlawful form of processing";

- "must enable the Entity, taking into account the state of the art, costs, nature, scope, and purpose of the relevant processing, to adopt, both at the initial stage of determining the means of processing and during the processing itself, any technical and organizational measures deemed appropriate to guarantee and implement the principles established for data protection and to protect the rights of data subjects";

- "guarantees the competence and reliability of its employees and collaborators authorized to process personal data (hereinafter also "data processors") carried out on the Entity's behalf";

- "ensures that the persons in charge have received adequate training in personal data protection and IT security, providing the Authority with evidence of such training."

In light of the instructions provided by the Municipality—without prejudice to the assessments regarding the lawfulness of the processing carried out by the latter, which will be the subject of a separate procedure—in the agreement signed on 20th pursuant to Article 28 of the Regulation and the obligations imposed on the data controller by the legislation on personal data protection, it is believed that the cooperative, in sending to various stakeholders of the Municipality the documentation containing information, including information regarding the health status (such as types of disability, specific pathologies suffered, disability classification code, certifications held, indication of resources for school integration - teachers/educators allocated to students) of the data subjects, minors and, as such, particularly vulnerable; see Council. 38 of the Regulation) did not use the necessary expertise, failed to adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risks presented by the processing, and acted in violation of the instructions provided by the data controller.

For these reasons, the cooperative, even following a simple error resulting from the sending of an email containing the aforementioned documents, processed personal data in violation of Articles 28, paragraph 3, and 32, paragraph 1 of the Regulation.

4. Conclusions.

In light of the above considerations, taking into account the statements made during the investigation – the veracity of which may be held accountable pursuant to Article 38 of the Regulation. 168 of the Code – it is stated that the information provided by the data controller in the defense briefs does not overcome the concerns notified by the Office with the document initiating the proceedings and is insufficient to allow the dismissal of the present proceedings, since none of the cases provided for by Article 11 of the Guarantor Regulation no. 1/2019 apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data carried out by the cooperative is found to be unlawful, in violation of Articles 28, paragraph 3, and 32, paragraph 1 of the Regulation.

Violation of the aforementioned provisions gives rise to the administrative sanction provided for by Article 83, paragraph 4, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation itself, as also referred to in Article 166, paragraph 2, of the Code.
Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante Regulation No. 1/2019).

Given that the cooperative's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Considering that, in this case, all the violations ascertained - Articles 28, paragraph 3 and 32, paragraph 1 of the Regulation - are subject to the sanction provided for by Article 83, paragraph 4, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €10,000,000 (ten million/00).

The aforementioned administrative fine imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set out in Article 83(2) of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the breach, it must be considered that the communication concerned a large number of vulnerable data subjects (see Article 83(2)(a) of the Regulation);

- with specific regard to the subjective nature of the breach, it was caused by a material error (Article 83(2)(b) of the Regulation);

- with regard to the categories of personal data communicated, this includes special categories of data relating to minors (Article 83(2)(g) of the Regulation).

In light of this specific circumstance, it is considered that, in this case, the severity of the breach committed by the data controller is high (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of 24 May 2023, point 60).

The following mitigating circumstances must also be considered:

- the data processor has taken measures, including by cooperating with the data controller, to mitigate the damage and prevent the recurrence of similar incidents (Article 83(2)(c) of the Regulation);

- there have been no previous relevant breaches (Article 83(2)(e) of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83(2)(f) of the Regulation);

- the data controller has compensated the parents of one of the data subjects involved in the unlawful communication (Article 83, paragraph 2, letter k) of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to set the fine at €20,000.00 (twenty thousand/00) for the violation of Articles 28, paragraph 3, and 32, paragraph 1 of the Regulation, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority no. 1/2019, this chapter containing the injunction order should be published on the Garante's website.

This is in consideration of the specific circumstances of this specific case, regarding the communication of personal data, including special categories of data of numerous students, without having adopted appropriate technical and organizational measures and in failure to comply with the instructions provided by the data controller.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW, THEREFORE, THE GUARANTOR

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Quadrifoglio social cooperative in the terms set out in the grounds is unlawful due to the violation of Articles 28 and 32 of the Regulation;

ORDERS

pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 17 of the Regulation. 166 of the Code, the Quadrifoglio Social Cooperative, with registered office at Viale Savorgnan d’Osoppo 4/10, 10064 Pinerolo (TO) – Tax Code and VAT No. 03890320017, is ordered to pay the total sum of €20,000.00 (twenty thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half of the imposed fine;

ORDERS

The Quadrifoglio Social Cooperative:

- to pay the total sum of €20,000.00 (twenty thousand/00) in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this provision, under penalty of the adoption of the consequent enforcement actions pursuant to Article 27 of Law No. 689/1981;

ORDERS

pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, provided for by Article 57, paragraph 1, letter u), of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, April 29, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE ACTING SECRETARY GENERAL
Filippi

[web doc. no. 10146337]

Provision of April 29, 2025

Register of Provisions
no. 274 of April 29, 2025

THE AUTHORITY FOR THE PROTECTION OF PERSONAL DATA

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, and Attorney Guido Scorza, members, and Dr. Claudio Filippi, Acting Secretary General;

SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree no. 196 of 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. The Complaint.

In a complaint filed with the Authority, Ms. XX complained that the Quadrifoglio social cooperative (hereinafter "the cooperative"), "which manages certain school services on behalf of the Municipality," had "sent to the Municipality of Bologna, preschool office (ServiziZeroSei), an Excel file with three worksheets: the first indicating that its workers had joined a strike; the other two sheets (Disability and Exceptions), with a list of children with disabilities and special needs, with detailed and sensitive information (pathology and various notes).

2. The preliminary investigation.

With a note dated XX (ref. no. XX), to which reference is made in full, the cooperative responded to the request for information made by the Guarantor on XX (ref. no. XX), stating, in particular, that:

- "On XX, the Municipality of Bologna awarded the service of managing educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the qualification of the curriculum in the city's preschools to the TEMPORARY CONSOLIDATION OF JOINT VENTURES between COOPERATIVA SOCIALE QUADRIFOGLIO (Agent) and O.R.S.A. SOCIAL COOPERATIVE COMPANY (Client) for period XX with the option of renewal for an additional two school years”;

- “pursuant to the Tender Specifications, the Quadrifoglio Social Cooperative (hereinafter the "Agent") is required to inform the Municipality of Bologna (hereinafter the "Client") of any disruptions to service (e.g., strikes). The Agent undertakes to notify the Client of any union strikes resulting in staff absences and the consequent need to reorganize services. Subsequently, the Client shall inform the respective school services; Finally, the communication was sent by school services to families.

- "For service management, the Client shall send the Agent's pedagogical coordination service, before the start of the school year, a document containing the sensitive data relating to the minors in their care (name, surname, date and place of birth, citizenship, type of disability, ICD-IO code), necessary for the activation and management of the school inclusion service for minors with disabilities."

- "On the occasion of a general strike called for the XXth day, the Agent sent an email to the Client (dated XX), according to the procedure described above, to report the services not provided for the strike day. It is noted that the email, signed by (...) coordinator of the integrative and school inclusion services of the municipal preschools in the Borgo-Reno, Navile, and Porto-Saragozza areas, contained six attached files relating to the services available in the six Bologna neighborhoods.The files relating to the Borgo-Reno, Navile, and Porto-Saragozza areas contained two sheets: the first, updated in content, starting from the document received from the Municipality at the beginning of the year (...) containing only information regarding the closure/opening of supplementary services on the strike day indicated above; the second sheet, however, incorrectly maintained, contained information relating only to the school inclusion service, thus retaining sensitive data relating to minors in its care.

- "The aforementioned email contained the following notice at the bottom: 'ATTENTION: The content of this message is intended solely for the persons to whom it is addressed and may contain information whose confidentiality is legally protected under the terms of the current European Regulation 679/2076 on privacy - GDPR.'"

- "On XX, the Mandatory Cooperative became aware of a personal data breach, through an official notification from the Bologna Services Coordinator."

- "After verifying the incident, the Agent promptly proceeded (...), sending a service complaint against the worker (...), due to gross negligence in her duties, inviting her to submit her counterarguments within 5 days (...). The response received from the worker (...) identified that the communication regarding the June 11 strike had been sent only to individuals already in possession of the sensitive data erroneously transmitted by the coordinator";

- "Following a coordination meeting between the Client Entity (...) and the Mandatory Cooperative (...) to review the facts and provide an overview of the measures to be implemented, it was agreed to establish implementing measures for the processing of personal data (...). In response, the Mandatory Cooperative's Privacy Management Office developed a "Privacy Measures Implementation Plan";

- "On XX, the Client conducted a privacy and IT security audit at the Mandatory Cooperative's headquarters, in order to verify the management system at issue":

- "On XX, the Client sent a report (...) requesting the imposition of a penalty of €2,000 against the Mandatory Cooperative (...). Following a request for compensation made by one of the families affected by the accident, of which the Client had communicated to the Agent as the party involved and required to respond (…), the penalty previously applied was revoked by the Client; In fact, compensation was awarded to the family who had requested it for the incident.

Based on the information acquired, the Office notified, pursuant to Article 166, paragraph 5 of the Code, with note dated XX (prot. no. XX), the cooperative, as the data controller designated by the Municipality of Bologna pursuant to Article 28 of the Regulation, of the initiation of the procedure for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, concerning the alleged violations of Articles 28 and 32 of the Regulation, inviting the aforementioned entity to submit written defenses or documents to the Guarantor or to request a hearing by the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of 24 November 1981).

The cooperative submitted its defense briefs, with Note of XX, to which reference is made in full, stating, in particular, that:

- "is entrusted with the management of educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the qualification of the curriculum in preschools in the Municipality of Bologna (...) since the month of XX";

- "In order to perform this service, it was necessary to process sensitive and health data, among other things, of minors receiving educational support. In relation to this purpose, the Municipality of Bologna assumes the role of Data Controller and the undersigned Cooperative assumes the role of Data Processor. Within the scope of this relationship, the Municipality of Bologna, in fulfillment of its obligations related to the role, has issued instructions for data processing to the Data Processor (...). No specific requirements regarding the need to use data encryption tools have been issued by the Data Controller. The agreement is limited to a general reference to the provisions of art. 28 GDPR”;

- “In order to enable the planning of the services requested from the Cooperative, the Municipality of Bologna, through its authorized data processors (both sensitive and health-related), sends the Managers of the individual Territorial Units, before the start of the school year, files containing the names of the minors receiving support, along with an indication of the conditions justifying the support. This documentation is essential for the provision of the service. The files containing the names of the minors and their respective conditions are sent by the Municipality of Bologna to the undersigned Cooperative, through the Territorial Managers, without any coding”;

- “During the general strike called for the 20th, the Cooperative sent an email to the Municipality of Bologna (dated 20th), (…) to indicate the services not guaranteed for the strike day”;

- “The Cooperativa Quadrifoglio s.c. Onlus has been providing services to minors, the disabled, and the elderly for over 40 years. This involved the processing of a huge amount of sensitive and health-related data. They have always been processed in accordance with the provisions of the applicable regulations, and prior to the current dispute, the undersigned had never received a complaint regarding the alleged undue disclosure and/or loss and/or destruction of data protected by the aforementioned regulations.

- "The Guarantor's attention is drawn to the fact that the Cooperative, as Data Processor, has managed the data provided to it by the Data Controller in compliance with the instructions received from the latter. The files subject to communication (deemed unlawful) were processed by the Processor and returned to the Data Controller in the manner in which they were received by the latter;

- "to assume that the Processor should have used organizational measures superior to those defined and used by the Data Controller would appear unfounded, especially considering that the Data Processor has always and exclusively dealt with the Data Controller."

- "it is worth noting that the obligations that Article 28 generically attributes to the Processor are deemed fulfilled by the precautions adopted, as they appear proportionate to the risk inherent in sharing data solely with the Data Controller."

- "it is noted that a data breach cannot automatically be identified from the mere sending of a single email to multiple recipients (the heads of territorial units), as each recipient was authorized to process the data. The respective file was clearly identified by name;

- "the data was processed in accordance with the purposes indicated by the Data Controller, namely, to communicate the strike that would have affected child support services."

- "in light of the above, it is clear that the conduct described does not constitute a subjective element of negligence (much less intent), given that the communication was made to individuals already authorized to process the data and in compliance with the instructions issued by the Data Controller."

- "the Cooperative promptly took action to mitigate the effects of the breach and to adopt the necessary technical and organizational measures to improve the security of personal data processing in compliance with applicable legislation. The Cooperative, also as a result of its collaboration with the Client, awarded compensation to the family who had requested it in light of the incident;

- "The Cooperative subsequently developed a 'Privacy Measures Implementation Plan' (...), including an information/training session on the management system for all affected personnel."

- "The Cooperative also initiated disciplinary proceedings against the operator responsible for data processing."

- "Any violation, which was not substantiated, would have had no detrimental effects on the minors, as communication was limited to individuals within the Data Controller's organization."

During the hearing held on XX, the cooperative stated, among other things, that:

- "At the beginning of each school year, the Municipality, the data controller, sends the cooperative a single file, divided into various tables corresponding to the different neighborhoods, containing the data of students with disabilities; The file contains the names of the schools, student data, the number of hours covered by the educational service, and the types of conditions the students with disabilities have.

- "Whenever the cooperative needs to notify the Municipality of a service interruption/change, it must use this file, indicating the staff members who are absent from the service, for example, on strike. The Municipality will send this file to the various schools in the various districts to let them know that, on a certain date, the staff member assigned to that particular student will not be available."

- "Following the report in question, the data controller has engaged the cooperative to identify measures to prevent further data leakage and better protect privacy. A data encryption mechanism has therefore been introduced in the file described above, i.e., a pseudonymization tool. This means that the file no longer contains the first name, last name, or initials of the first and last names of the students, but rather an alphanumeric code associated with each individual student. The communication methods are therefore unchanged; what has been modified is the student identification tool (no longer using the clear name and surname but an alphanumeric code)";

- "this tool was created by the cooperative staff in collaboration with the Municipality staff";

- "the cooperative's collaborative attitude with the Municipality and the Authority is emphasized. It should be noted that the cooperative has approximately 3,000 worker members and provides services to people, especially the elderly, disabled, and minors. In recent years, the economic situation has been challenging due to several factors, primarily COVID-19, which has resulted in significant expenditures for worker protection, with very expensive personal protective equipment (PPE) and a decline in revenue due to the reduction in beds in residential care facilities and a reduction in school services. There has been an increase in utility costs (electricity, gas) in various residential facilities, and finally, contractual increases have increased costs that many public and private clients are no longer able to afford and pay, resulting in a consequent burden on the cooperative.

- "The cooperative has been working in the field of school inclusion for approximately 40 years. It has always processed a large amount of data, including sensitive data, on vulnerable students and elderly people it supports, and has never incurred any personal data protection violations prior to the incident in question."

3. Applicable law.

3.1 The regulatory framework.

The data protection framework established by the Regulation provides that the processing of personal data by entities operating in the public sector is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

With regard to special categories of personal data, processing is generally permitted when "necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection, and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in national legal systems, by laws, regulations, or general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest ground, as well as the suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

Pursuant to Article 9, paragraph 2, of the Code, the processing is necessary for the purposes of the processing. Pursuant to Article 28 of the Regulation, the controller may also entrust processing to third parties who provide sufficient guarantees that appropriate technical and organizational measures have been implemented to ensure that the processing complies with the applicable data protection legislation (Article 4(8) of the Regulation).

In this case, "processing by a processor shall be governed by a contract or other legal act under Union or Member State law, which is binding on the processor and which specifies the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller" (Article 28(1) and (3) of the Regulation).

The Regulation also regulates the obligations and other forms of cooperation to which the processor is subject when acting on behalf of the controller and the scope of their respective responsibilities (see Articles 30, 32, 33(2) and 82 of the Regulation).

In this regard, the Regulation also requires the controller and processor to implement "appropriate technical and organizational measures to ensure a level of security appropriate to the risk," taking into account, among other things, "the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons (...) which includes, inter alia, (...) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services (...). When assessing the appropriate level of security, special account shall be taken of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed" (Article 32, paragraph 1, letter b) and 2, of the Regulation).

Article 32 Article 32 of the Regulation, therefore, requires both the data controller and the data processor to adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risk. As previously clarified by the Garante, the data processor, based on their respective responsibilities, must cooperate, including by demonstrating independent decision-making, in adopting appropriate measures and systematically verifying their effectiveness, especially when providing services involving a large number of data subjects, as in the case at hand (see provisions no. 48 of February 11, 2021, web doc. no. 9562831 and no. 293 of July 22, 2021, web doc. no. 9698597, 419 of December 2, 2021, web doc. no. 9733053).

3.2 The processing of personal data carried out by the cooperative.

From what emerges from the complaint in question, as well as from the investigation conducted based on the information acquired, following the investigation and subsequent assessments by this Department, it appears that, in anticipation of the strike called for the XXth by the cooperative's workers, the cooperative's representative sent an email to the Municipality of Bologna and the heads of the local units. The email contained six Excel files, one for each district of the city, containing a list of supplementary services not guaranteed as a result of the strike, broken down by school.

Some of these documents, however, contained not only information regarding the management of possible reductions in supplementary services on the day of the strike, but also personal data relating to the health of children enrolled in certain preschools. Specifically, these documents contained, in addition to the names of the students, their place, date of birth, and citizenship, information regarding the types of disabilities, the specific pathologies suffered by the minors, the disability classification code (ICD10 code), and any certifications held by the students, as well as an indication of the resources for school integration (teachers/educators) assigned to the students and certain annotations.

As a preliminary point, it is noted that minors, as "vulnerable natural persons," deserve "specific protection with regard to their personal data, as they may be less aware of the risks, consequences, and safeguards concerned, as well as of their rights in relation to the processing of personal data" (recital no. 38 of the Regulation).

It is also noted that, pursuant to Article 4(1), no. 15 of the Regulation, "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her state of health" are considered data relating to health.

Considering the definition of personal data and health data (Article 4, points 1 and 15, of the Regulation), it is believed that the information regarding the types of disabilities reported in the aforementioned files, the indication of their classification code and the certifications held or not by the children, as well as the assignment of resources for school integration (teachers/educators) to the students, allow us to obtain information on the health status of the minors listed.

Given the above, it is submitted that the cooperative, in sending the documentation containing the above information, which was superfluous to the purposes it intended to achieve (the mere communication of possible reductions in supplementary services on the day of the strike), did not use the necessary expertise to prevent such information from being made available to the aforementioned parties, in violation of the instructions provided by the data controller, pursuant to Article 28 of the Regulation.

Indeed, the contract signed between the Municipality and the cooperative on XX provides, among other things, that the data controller:

- "processes such personal data only for the purposes of performing the contract and, thereafter, only in accordance with any written agreement between the Parties, therefore acting exclusively on the basis of documented instructions provided by the Entity";

- "before initiating any processing and, where necessary, at any other time, will inform the Entity if, in its opinion, any instructions provided by the Entity violate applicable law";

- "is obliged to adopt: appropriate procedures to ensure respect for the rights and requests made to the Entity by data subjects regarding their personal data";

- "must guarantee and provide the Entity with cooperation, assistance, and any information that may reasonably be requested by the latter, to enable it to fulfill its obligations under applicable law, including the provisions and specific decisions of the Italian Data Protection Authority";

- "must adopt and maintain appropriate security measures, both technical and organizational, to protect personal data from any unlawful or accidental destruction or loss, damage, alteration, unauthorized disclosure or access, and in particular, where the processing involves the transmission of data over a network, from any other unlawful form of processing";

- "must enable the Entity, taking into account the state of the art, costs, nature, scope, and purpose of the relevant processing, to adopt, both at the initial stage of determining the means of processing and during the processing itself, any technical and organizational measures deemed appropriate to guarantee and implement the principles established for data protection and to protect the rights of data subjects";

- "guarantees the competence and reliability of its employees and collaborators authorized to process personal data (hereinafter also "data processors") carried out on the Entity's behalf";

- "ensures that the persons in charge have received adequate training in personal data protection and IT security, providing the Authority with evidence of such training."

In light of the instructions provided by the Municipality—without prejudice to the assessments regarding the lawfulness of the processing carried out by the latter, which will be the subject of a separate procedure—in the agreement signed on 20th pursuant to Article 28 of the Regulation and the obligations imposed on the data controller by the legislation on personal data protection, it is believed that the cooperative, in sending to various stakeholders of the Municipality the documentation containing information, including information regarding the health status (such as types of disability, specific pathologies suffered, disability classification code, certifications held, indication of resources for school integration - teachers/educators allocated to students) of the data subjects, minors and, as such, particularly vulnerable; see Council. 38 of the Regulation) did not use the necessary expertise, did not adopt suitable technical and organizational measures to guarantee a level of security appropriate to the risks presented by the processing and acted in a manner that deviated from the instructions provided by the data controller.

For these reasons, the cooperative, albeit as a result of a simple error resulting from the sending of an email containing the aforementioned documents, has processed personal data in violation of Articles 28, paragraph 3, and 32, paragraph 1, of the Regulation.

4. Conclusions.

In light of the above considerations, and taking into account the statements made during the investigation – the veracity of which may be held accountable pursuant to Article 168 of the Code – it is stated that the information provided by the data controller in the defense briefs does not address the concerns notified by the Office with the initiation of the proceeding and is insufficient to allow the dismissal of this proceeding. Furthermore, none of the cases provided for in Article 11 of the Guarantor Regulation No. 1/2019 apply.
Therefore, the Office's preliminary assessments are confirmed and the cooperative's processing of personal data is found to be unlawful, in violation of Articles 28, paragraph 3, and 32, paragraph 1, of the Regulation.

Violation of the aforementioned provisions gives rise to the administrative sanction provided for in Article 83, paragraph 4, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation itself, as also referred to in Article 166, paragraph 2, of the Code.
Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i) and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letters i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante Regulation No. 1/2019).

Given that the cooperative's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Given that, in this case, all the violations identified—Articles 28, paragraph 3, and 32, paragraph 1, of the Regulation—are subject to the sanction provided for in Article 83, paragraph 4, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €10,000,000 (ten million).

The aforementioned administrative pecuniary sanction imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the violation, it must be considered that the communication concerned a large number of vulnerable data subjects (see Article 83, paragraph 2, letter a), of the Regulation);

- with specific regard to the subjective nature of the breach, it was caused by a material error (Article 83, paragraph 2, letter b), of the Regulation);

- with regard to the categories of personal data communicated, this includes special categories of data relating to minors (Article 83, paragraph 2, letter g), of the Regulation).

In light of this specific circumstance, the seriousness of the breach committed by the data controller is considered high in this case (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of May 24, 2023, point 60).

The following mitigating circumstances must also be considered:

- the data processor has taken steps, including by cooperating with the data controller, to adopt measures to mitigate the damage and prevent the recurrence of similar incidents (Article 83(2)(c) of the Regulation);

- there are no previous relevant violations (Article 83(2)(e) of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83(2)(f) of the Regulation);

- the data processor has compensated the parents of one of the data subjects affected by the unlawful communication (Article 83(2)(k) of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to set the fine at €20,000.00 (twenty thousand/00) for violation of Articles 28, paragraph 3, and 32, paragraph 1, of the Regulation, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also deemed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority No. 1/2019, this chapter containing the injunction order should be published on the Italian Data Protection Authority's website.

This is in consideration of the specific circumstances of this specific case, regarding the communication of personal data, including special categories of data of numerous students, without having adopted appropriate technical and organizational measures and in failure to comply with the instructions provided by the data controller.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW, CONSIDERING ALL THE ABOVE, THE AUTHORITY

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Quadrifoglio social cooperative in the terms set out in the grounds is unlawful due to the violation of Articles 28 and 32 of the Regulation;

ORDERS

pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 17 of the Regulation. 166 of the Code, the Quadrifoglio Social Cooperative, with registered office at Viale Savorgnan d’Osoppo 4/10, 10064 Pinerolo (TO) – Tax Code and VAT No. 03890320017, is ordered to pay the total sum of €20,000.00 (twenty thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half of the imposed fine;

ORDERS

The Quadrifoglio Social Cooperative:

- to pay the total sum of €20,000.00 (twenty thousand/00) in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this provision, under penalty of the adoption of the consequent enforcement actions pursuant to Article 27 of Law No. 689/1981;

ORDERS

pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, provided for by Article 57, paragraph 1, letter u), of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be filed before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, April 29, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE ACTING SECRETARY GENERAL
Filippi
  1. Some of the information about the breach is not mentioned in the decision but can be found in the DPA's decision against the controller over the same breach, which includes a more exhaustive explanation of the facts. See Garante per la protezione dei dati personali, provv. 10146543.