Garante per la protezione dei dati personali (Italy) - 10146543

From GDPRhub
Garante per la protezione dei dati personali - 10146543
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(1)(c) GDPR
Article 5(1)(a) GDPR
Article 6(1)(c) GDPR
Article 6(1)(e) GDPR
Article 6(2) GDPR
Article 6(3) GDPR
Article 9(1) GDPR
Article 9(2)(g) GDPR
Article 9(4) GDPR
2-sexies c.1 d. lgs. 196/2003
2-sexies c.2 l. bb) d. lgs. 196/2003
2-ter c. 3 d. lgs. 196/2003
2-ter c.1 d. lgs. 196/2003
Type: Complaint
Outcome: Upheld
Started:
Decided: 29.04.2025
Published:
Fine: 40,000 EUR
Parties: Comune di Bologna
National Case Number/Name: 10146543
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: cci

The municipality of Bologna accidentally forwarded a document with the names of special needs students and information about their health to unauthorized staff as well as 53 families. The DPA fined the municipality €40,000.

English Summary

Facts

The municipality of Bologna (the controller) relied on a social enterprise (Cooperativa Quadrifoglio s.c. Onlus, the processor) as a contractor for providing support and educational services to special need children in schools (the data subjects). In order for the processor to provide its services, the controller shared information about the data subjects with the processor.

The processor emailed the controller about the temporary interruption of certain services due to a workers’ strike. In turn, the controller forwarded the email to numerous members of its staff and to 53 families of children who attended two schools within the municipality.

Due to a human error, the processor attached unnecessary documents to the email, including a list of 61 data subjects who relied on the controller’s services. The list included the data subjects' names (in non-pseudonymized form) and other information, such as detailed information about their health status and the accomodations they needed in school. The controller did not notice the attachment and forwarded it along with the email, resulting in the accidental disclosure of the data.

Following a complaint, the DPA investigated both the controller and the processor. Aside from the procedure with the DPA, the controller paid €2,000[1] in damages in an amicable settlement with the family of one of the data subjects.

Holding

The DPA noted that by forwarding the processor’s email along with the attachment, the controller disclosed the data to two distinct categories of unintended recipients:

  • The families of the data subjects;
  • Numerous members of the controller’s own staff, who did not need the information and were not authorized to handle it.

On these grounds, the DPA held that the controller unlawfully disclosed personal data, in violations of Articles 5, 6, and 9 GDPR as well as several provisions of Italian data protection law. The DPA issued a €40,000 fine.

Comment

The DPA fined the processor €20,000 over the same incident: see Garante per la protezione dei dati personali- provv.10146337.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10146543]

Provision of April 29, 2025

Register of Provisions
No. 273 of April 29, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Claudio Filippi, Acting Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. The complaint.

In a complaint filed with the Authority, Ms. XX complained that "the Quadrifoglio cooperative, which manages certain school services on behalf of the Municipality," had "sent to the Municipality of Bologna, preschool office (ServiziZeroSei), an Excel file with three worksheets: the first indicating that its workers had joined a strike; the other two sheets (Disabilities and Exceptions), with a list of children with disabilities and special needs, with detailed and sensitive information (pathology and various notes)." This email was allegedly sent "also to about thirty municipal employees." Furthermore, the aforementioned Excel file was subsequently "circulated by ServizioZeroSei to all nursery schools in the municipality of Bologna," and the XX nursery school "forwarded it to all parents, 50 families."

2. The preliminary investigation.

With a note dated XX, to which reference is made in full, in response to the request for information made by this Authority on XX (ref. no. XX), the Municipality of Bologna (hereinafter, the Municipality) stated that:

- "The security incident, the subject of the complaint, occurred on XX, with the sending to 53 ordinary email addresses registered to the parents of the 50 children enrolled - for the XX school year - at the XX municipal nursery school of a file in which the following information had been accidentally inserted: The personal and health data of 60 children enrolled in various municipal preschools, including four attending preschool XX;

- "The file in question was attached to an email containing service instructions addressed to municipal preschool staff regarding how to manage possible service reductions resulting from participation in the strike called for XX by USB for educators employed in the educational enhancement service, managed under contract by the RTI Cooperativa Sociale Quadrifoglio."

- "The Municipality of Bologna directly manages 67 preschools located throughout the municipality. The preschools are part of the Zerosei Intermediate Services Unit of the Education, Instruction and New Generations Area and are coordinated by 28 pedagogical coordinators (...) who in turn report to six Territorial Unit Managers, each of whom is responsible for managing all 0-6 Services (nurseries, preschools, and supplementary services) located in the six Districts of the City.

Service communications (...) are mostly handled by the Management of the Zerosei Intermediate Services Unit via email.

- "With respect to the communication sent to schools on 20th, a general mailing was carried out in consideration of the urgent need to provide the necessary information to school staff so they could inform families in time for the strike (...) the files containing the list of services not guaranteed during the strike do not involve the processing of personal data, but contain only the indication of those services that, as a result of the strike, the contractor is unable to provide and are therefore suspended. These files were prepared by the education services contractor for subsequent mailing to schools by the management of UI Servizi Zerosei";

- "The accidental inclusion of the personal data of 61 children in one of the above-mentioned files is attributable to the fact that, under the same contract, the Cooperativa Sociale Quadrifoglio/Coop sociale O.R.S.A. joint venture manages, among other things, educational services for students with disabilities, including those enrolled in municipal preschools. As part of this management, the contractor is provided by the same entity (UI Servizi Zerosei of the Education, Instruction and New Generations Area) with the personal and sensitive data of the children receiving the inclusion service, for the purpose of designing individualized interventions."

- "The Coop Quadrifoglio, as the agent of the joint venture, has been designated as the external data controller, and a specific agreement has been signed between the parties for this purpose (...)";

- "pursuant to Resolution PG 362301/2018, all employees assigned to the U.I. Servizi Zerosei are authorized to process personal data within the organizational units to which they are assigned";

- "formal notification of the incident was promptly given to the interested parties and to this esteemed Data Protection Authority, pursuant to Articles 34 and 33 of EU Regulation 2016/679."

In a subsequent note dated XX, to which reference is made in full, the Municipality, in response to the request for information made by this Authority on XX (ref. no. XX), stated that:

- "School assistants are responsible for viewing incoming emails and sorting them into paper format for all or part of the work group, depending on the communications they contain. This function is assigned to this individual because in municipal preschools, school assistants have a broader role than simple cleaning and supervision duties. Specifically, the following tasks are expressly specified in the declaration of activities specific to the professional profile approved by Municipal Council Resolution P.G. No. 228627/2005 (...): maintaining relationships, information, and communications, with particular attention to the relationship with parents and collaboration with teachers; using the technological and IT tools provided by the service for basic processing and communication functions."

- "Within the organization of school and educational services directly managed by the Municipality of Bologna, procedures involving the processing of personal data relating to children, families, and staff are assigned to administrative staff offices (central or regional) or other levels of responsibility, as there are no administrative staff in the schools. Access to the personal data of enrolled children by school staff often occurs through paper documents (sometimes provided directly by families) or through sharing restricted-access folders with the relevant managers."

- "In summary, the aforementioned staff are authorized to use the shared email account based on their duties and are authorized to carry out related processing, as well as being adequately instructed and trained."

The Quadrifoglio social cooperative, in a note dated XX, to which reference is made in full, in response to the request for information made by this Authority on XX (ref. no. XX), stated the following:

- "On XX, the Municipality of Bologna awarded the contract for the management of educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the qualification of the curriculum in the city's preschools to the newly formed temporary consortium between the Quadrifoglio social cooperative (lead agent) and O.R.S.A., a social cooperative company (principal) for the period XX with the option of renewal for an additional two school years."

- "According to the Tender Specifications, the Quadrifoglio Social Cooperative (hereinafter the "Agent") is required to inform the Municipality of Bologna (hereinafter the "Client") of any service disruptions (e.g., strikes). The Agent undertakes to notify the Client of any union strikes resulting in staff absences and the consequent need to reorganize services. Subsequently, the Client informs the respective school services; finally, the school services forward the notification to the families."

- "For service management, the Client shall send the Agent's pedagogical coordination service, before the start of the school year, a document containing the sensitive data relating to the minors in its care (name, surname, date and place of birth, citizenship, type of disability, ICD-IO code), necessary for the activation and management of the school inclusion service for minors with disabilities."

- "On the occasion of a general strike called for the XXth, the Agent sent an email to the Client (dated XX), according to the procedure described above, to report the services not provided for the strike day. It should be noted that the email, signed (... by) the coordinator of the supplementary and school inclusion services of the municipal preschools present in the territories of Borgo-Reno, Navile, and Porto-Saragozza, contained 6 attached files relating to the services present in the six districts of Bologna. The files relating to the territories of Borgo-Reno, Navile, and Porto-Saragozza contained 2 sheets: the first (...) contained only the information relating to the closure/opening of supplementary services on the strike day indicated above; the second sheet, however, erroneously kept, contained the information relating only to the school inclusion service, therefore the sensitive data relating to the minors in charge remained."

Based on the information acquired, the Office notified the Municipality, as data controller, with a letter dated XX (ref. no. XX), pursuant to Article 166, paragraph 5, of the Code, of the initiation of the procedure for the adoption of the provisions referred to in Article 58, paragraph 2, of the Regulation. This was because a municipal office (UI Servizio Zerosei) sent an email with attached files containing specific categories of student data to the email addresses of the sixty-seven preschools in the area, the twenty-six pedagogical coordinators, and the six heads of the territorial units located in the city's six districts. A municipal preschool also sent one of the aforementioned files to fifty-three email addresses of the parents of children enrolled in that school, in the absence of an appropriate legal basis and in violation of Articles 5, 6, and 9 of the Regulation, and Articles 2-ter and 2-sexies of the Code.

With the same notice, the data controller was invited to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The Municipality submitted its defense briefs, with note dated XX (ref. no. XX), to which reference is made in full, stating, in particular, that:

- "The accidentally disclosed data consists of sensitive personal data relating to 61 children attending, at the time, the municipal preschools in the Porto Saragozza and Santo Stefano della Città districts, consisting of: name, surname, date and place of birth, citizenship, certifications held - CIS (Certificate of Educational Integration), functional diagnosis, certifications pursuant to Law 104/92, type of disability, ICD10 code, CIS revision date. Information relating to the year of enrollment, school attendance schedule, assigned hours of intervention, and various notes are also included."

- "With regard to the number of individuals who potentially had access to such data, only one individual in each school is authorized to use the Institute's email. It is therefore confirmed that, by job description, school staff are responsible for viewing incoming emails and sorting them into paper copies for all or part of the workgroup, depending on the communications they contain. This function is performed by a single staff member who receives and reads the email. In the case in question, the planned operation was to print the email text (so it could be shared with teachers) and note the information in the table, which was supposed to list only the guaranteed and non-guaranteed services. No indication was included regarding the potential circulation of the email."

- "The sending of the data in question to the 50 families of the XX preschool was also caused by human error by the school employee. Had the employee carefully read the instructions contained in the aforementioned email, she would have easily concluded that there was no information to provide to families for the school in question, as there were no before- and after-hours services available at that school. In fact, at the school (...), the educational enhancement service was offered for both classes from 1:30 PM to 3:30 PM (in conjunction with the teaching staff), and therefore the strike did not impact the daily functioning of the school service."

- "The personal data breach is the result of manifestly negligent conduct by an employee of the Quadrifoglio Cooperative in the actual performance of simple office duties. This employee inserted, without any reason, into a communication (or rather, into files attached to an email) personal data relating to minors with disabilities that were not relevant to the purpose for which the communication was created. This communication (...) should have contained only the list of services unavailable during the aforementioned strike. Therefore, the employee, on behalf of the Data Controller, contaminated the communication process with the schools involved with elements that were completely unrelated to it, transmitting unnecessary data that was then forwarded by the school staff."

- "This aspect consequently impacts the subjective element of the alleged violation, i.e., it excludes the Municipality's liability, or, alternatively, only marginal liability."

- "In order to mitigate the effects of the breach, the Municipality promptly contacted the recipients after becoming aware of the error, informing them that they were not permitted to further process the data received and that they should have it immediately deleted (...). Furthermore, following a mediation process initiated by the parents of one of the data subjects whose data was subject to the breach, the Municipality awarded them financial compensation for the damage that occurred. The compensation awarded, precisely by virtue of the acknowledged liability, was fully reimbursed to the Administration by Coop Quadrifoglio";

- "this Administration has defined new and more stringent instructions for the Cooperative responsible for data processing";

- "a specific audit was also conducted at the Cooperative";

- "New instructions have been given to all employees assigned to the Zerosei Intermediate Services Unit (...) and new procedural methods and additional organizational measures have been adopted, immediately implemented, aimed at ensuring greater security of the personal data processed. A special section has been created on the intranet dedicated to nursery and preschool staff to act as a repository for employees and school staff with the instructions and measures implemented. Furthermore, it has been established that all service communications sent to schools are strictly controlled. Attached files are now always converted to PDF, and the communications specify that these are internal communications and cannot be disclosed to third parties. Numerous working meetings have been held with the staff with coordination roles (Territorial Unit Managers and pedagogical coordinators) to further explore the issue, and specific operational guidelines have been shared for the processing of so-called "sensitive" personal data within the scope of the activities of the municipal Zerosei services (...). All staff have received periodic basic training on personal data protection. (…) To prevent accidental loss, all personal data is shared via hard drive folders with restricted access to authorized individuals only.

- “From a security perspective, both physical and IT security measures are in place.”

- “In the notification (… pursuant to Article 33 of the Regulation), all the information required by law was provided to the Authority. Therefore, the subsequent complaint filed by the data subject (…) concerned a situation that was widely known to the Authority following the aforementioned notification.”

- “The personal data breach under investigation was not the result of intentional or malicious actions, and the number of third parties receiving the communication is objectively small. Furthermore, it is considered appropriate to highlight the fact that these third parties are part of the same school community, with an obvious concern for the confidentiality of minors' data, which they unwittingly received. These circumstances are of primary importance in assessing the actual impact of the breach.”

3. Applicable legislation.

3.1 The regulatory framework.

The data protection framework established by the Regulation provides that the processing of personal data by public bodies is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

The legal basis for the aforementioned processing must be established by Union or Member State law, which must pursue "an objective of public interest [and be] proportionate to the objective" (Article 6, paragraph 3, of the Regulation).

In this context, it is established that "Member States may maintain or introduce more specific provisions to adapt the application of the provisions of the […] Regulation with regard to processing in accordance with paragraph 1(c) and (e), by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing […]" (Article 6, paragraph 2, of the Regulation).

The Code has established that "the legal basis referred to in Article 6, paragraph 3, point (b) of the Regulation shall be a law or regulation or general administrative act" (Article 2-ter, paragraph 1).

In particular, processing operations consisting of the "dissemination" and "communication" of personal data are permitted only when provided for by a law, regulation, or general administrative act (Article 2-ter, paragraph 3 of the Code).

With regard to special categories of personal data, processing is generally permitted where "necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in domestic legal systems, by laws or regulations or by general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest ground, as well as the suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

The data controller is, in any case, required to comply with data protection principles, including "lawfulness, fairness, and transparency," as well as "data minimization." These principles require that personal data be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" and be "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c) of the Regulation). The data must be processed by authorized personnel who have been trained on how to access the data (Articles 4, point 10), 29, and 32, paragraph 4, of the Regulation).

3.2 The processing of personal data carried out by the Institute.

The investigation conducted, based on the information acquired and the facts emerging from the preliminary investigation, as well as subsequent assessments by this Department, has established that the Intermediate Unit (UI) for Zero-Six Services of the Municipality's Education, Instruction, and New Generations Department communicated personal data, including data relating to the health of students, by forwarding an email, originally received from the Quadrifoglio Social Cooperative, to the sixty-seven municipal preschools in the area, to the six heads of territorial units managing all 0-6 Services (nurseries, preschools, and supplementary services), and to the twenty-six pedagogical coordinators.

Specifically, this communication contained, in addition to information regarding the management of possible reductions in supplementary services during a strike day, personal data relating to the health of children enrolled in certain preschools (including the names of the students, place and date of birth, citizenship, types of disability, specific pathologies suffered, disability classification code (ICD10 code), certifications held, and an indication of the resources for school integration (teachers/educators) allocated to the students).

Subsequently, a school assistant at the XX municipal preschool sent one of the files attached to the aforementioned email, containing the aforementioned personal data, to fifty-three email addresses registered to the parents of children enrolled in that school for the XX school year.

As a preliminary point, it is noted that minors, as "vulnerable natural persons," deserve "specific protection with regard to their personal data, as they may be less aware of the risks, consequences, and safeguards involved, as well as of their rights in relation to the processing of personal data" (recital 38 of the Regulation).

It is also noted that, pursuant to Article 4(1), no. 15 of the Regulation, "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about the state of health of that natural person" are considered data concerning health.

Given the definition of personal data and health data (Article 4, points 1 and 15, of the Regulation), it is believed that the information regarding the types of disabilities reported in the aforementioned documents, the classification code for these disabilities, the certifications held or not held by the children, and the assignment of resources for school integration (teachers/educators) to students allow us to obtain information on the health status of the minors listed.

That said, with regard to the first aspect highlighted, regarding the provision by the aforementioned municipal office of the documents containing the aforementioned information regarding the health status of minors to preschools, to the heads of all territorial units managing all 0/6 Services, and to pedagogical coordinators, the following is highlighted.

As the Italian Data Protection Authority has repeatedly stated, personnel authorized to process personal data by the data controller (Article 29 of the Regulation and Article 2-quaterdecies of the Code) are entitled to process only the information relevant and necessary to carry out the activities assigned to them, based on organizational choices and the specific tasks performed (see, albeit in different contexts, provision no. 322 of September 16, 2021, web doc. no. 9711517, no. 214 of May 27, 2021, web doc. 9689234, no. 105 of June 18, 2020, web doc. no. 9444865).

In this specific case, however, the aforementioned municipal office transmitted to certain schools and employees (local unit managers, pedagogical coordinators, etc.) numerous personal data, including health data, of minors enrolled in schools in areas other than those under the jurisdiction of the aforementioned entities and schools. This information, therefore, is superfluous and unnecessary for the performance of the duties assigned to the personnel receiving the communication.

Although the documents in question were made available only to individuals within the data controller's organization, and the information contained therein was not made accessible to "external" parties within that context, the data was nevertheless made available to a very broad, specific or identifiable group of individuals, such as preschools other than those to which the children belong, the heads of territorial units, and the pedagogical coordinators responsible for schools not attended by the minors in question. This access was not, however, exclusively to the personnel responsible for the territory and area of assignment.

Although these individuals, by virtue of their roles and the functions performed under the applicable regulations, may certainly process the personal data of students within the scope of their educational and instructional activities, they cannot, however, be considered legitimately entitled to process, as in this case, the personal data, including data relating to the health of minors enrolled in schools other than those under their jurisdiction.

Furthermore, with reference to the different profile under examination, relating to the sending by the XX nursery school of the email containing the attached document called “PortoSaragozza", containing the aforementioned personal data, including health data, of approximately sixty children, to the email addresses of approximately fifty parents of pupils of the school, it is stated that such data were made known, albeit due to a material error, in any case in favour of a specific or determinable number of third parties (art. 4, par. 1 no. 10 of the Regulation), giving rise to a communication of numerous personal data, including health data (including types of disability, specific pathologies suffered, disability classification code, certifications held, indication of resources for school integration - teachers/educators - attributed to the pupils) of the interested parties, minors and, as such, particularly vulnerable (see cons. 38 of the Regulation, as well as provision of 27 November 2024, no. 728, doc. Web no. 10097324, provision of December 12, 2024, no. 767, web doc. no. 10099052, provision of February 27, 2025, no. 117, web doc. no. 10118264).

In light of the foregoing considerations, the sending of the aforementioned email with attached documentation containing personal data, including data relating to the health of the minors listed therein, effectively made the preschools different from those of the children listed therein, the Heads of Territorial Units, the pedagogical coordinators responsible for different areas and schools, as well as the parents of students enrolled in school XX, informed of the personal situations and information relating to the health of particularly vulnerable minors (see the definition of "communication" of personal data contained in Article 2-ter, paragraph 4, letter a), of the Code).

While acknowledging that this communication occurred following a simple error, due to the forwarding of an email containing the aforementioned documentation by the Quadrifoglio cooperative—without prejudice to the assessments regarding the lawfulness of the processing carried out by the cooperative, which will be the subject of a separate proceeding—it is noted that the Municipality, in any case, did not monitor and verify the content of the document received for forwarding, obligations it was also required to fulfill based on the "general responsibility" placed on the data controller (Articles 5, paragraph 2, and 24 of the Regulation, see Order No. 81 of March 7, 2019, web doc. 9121890; Order No. 160 of September 17, 2020, web doc. 9461168; Order No. 294 of July 22, 2021, web doc. 9698724).

For these reasons, this Municipality has processed personal data in violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

4. Conclusions.

In light of the above considerations, taking into account the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 13 of the GDPR. 168 of the Code – it is stated that the information provided by the data controller in the defense briefs does not address the concerns notified by the Office with the initiation of the proceedings and is insufficient to allow the dismissal of this proceeding, since none of the cases provided for by Article 11 of the Guarantor Regulation No. 1/2019 apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data by the Municipality is found to be unlawful, having occurred in the absence of lawful processing conditions, in violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

Violation of the aforementioned provisions gives rise to the administrative sanction provided for in Article 83, paragraph 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code.

Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i), i) and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Garante's Regulation No. 1/2019).

Given that the Institute's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 1, applies. 3 of the Regulation, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Considering that, in this case, all the violations identified—Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, c) and e), 2 and 3, and 9, paragraphs 1, 2, g), and 4 of the Regulation, and 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code—are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000 (twenty million).

The aforementioned administrative fine imposed, depending on the circumstances of each individual case, must be determined in amount, taking due account of the factors set out in Article 83(2) of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the breach, it must be considered that the communication concerned a large number of vulnerable data subjects (see Article 83(2)(a) of the Regulation);

- with specific regard to the subjective nature of the breach, it was caused by material errors resulting from an incorrect communication received from the data controller (Article 83(2)(b) of the Regulation);

- with regard to the categories of personal data communicated, this includes special categories of data relating to minors (Article 83(2)(g) of the Regulation).
In light of this specific circumstance, it is considered that, in this case, the level of severity of the violation committed by the data controller is high (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of 24 May 2023, point 60).

The following mitigating circumstances must also be considered:

- the data controller has taken measures to mitigate the damage and prevent the recurrence of similar incidents (Article 83(2)(c) of the Regulation);

- there are no previous relevant violations committed by the data controller, taking into account the circumstances in which the violations occurred (Article 83(2)(e) of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83(2)(f) of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the pecuniary sanction at €40,000.00 (forty thousand/00) for the violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order must be published on the Italian Data Protection Authority's website.

This is in consideration of the specific circumstances of this specific case, regarding the disclosure of personal data, including special categories of data of numerous students, in the absence of a lawful basis.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW CONSIDERING ALL THE ABOVE, THE ITALIAN DATA PROTECTION AUTHORITY

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Municipality of Bologna in the terms set out in the grounds is unlawful due to the violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1 and 2 of the Regulation. 1, 2, letter g), and 4 of the Regulations and 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code;

ORDERS

pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulations, as well as Article 166 of the Code, the Municipality of Bologna, with registered office at Piazza Maggiore 6, 40124 Bologna - VAT No. 01232710374, to pay the total sum of €40,000.00 (forty thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

the Municipality of Bologna:

- to pay the total sum of €40,000.00 (forty thousand/00) in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the annotation of this order in the Authority's internal register, as required by Article 57, paragraph 1, letter u), of the Regulations.

Pursuant to Articles 78 of the Regulations, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this decision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the decision itself, or within sixty days if the appellant resides abroad.

Rome, April 29, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE ACTING SECRETARY GENERAL
Filippi

[web doc. No. 10146543]

Decision of April 29, 2025

Register of Decisions
No. 273 of April 29, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Claudio Filippi, Acting Secretary General;

SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree no. 196 of June 30, 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Guarantor No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Ginevra Cerrina Feroni;

WHEREAS

1. The complaint.

In a complaint filed with the Authority, Ms. XX complained that "the Quadrifoglio cooperative, which manages certain school services on behalf of the Municipality," had "sent to the Municipality of Bologna, preschool office (ServiziZeroSei), an Excel file with three worksheets: the first indicating that its workers had joined a strike; the other two sheets (Disabilities and Exemptions), with a list of children with disabilities and special needs, with detailed and sensitive information (pathology and various notes)”. This email would have been sent “also to about thirty municipal employees”. Furthermore, the aforementioned Excel file would later have been “sent by ServizioZeroSei to all the nursery schools in the municipality of Bologna” and the XX nursery school would have “forwarded it to all parents, 50 families”.

2. The preliminary investigation.

With a note dated XX, to which reference is made in full, in response to the request for information made by this Authority on XX (ref. no. XX), the Municipality of Bologna (hereinafter, the Municipality) stated that:

- "The security incident, the subject of the complaint, occurred on XX, with the sending to 53 regular email addresses registered to the parents of 50 children enrolled - for the XX school year - at the XX municipal preschool. A file containing the personal data and health information of 60 children enrolled in various municipal preschools, 4 of whom attended the XX preschool, had been accidentally inserted.

- "The file in question was attached to an email containing service instructions addressed to municipal preschool staff, regarding how to manage possible service reductions resulting from participation in the strike called for the XX by USB for educators employed in the educational enhancement service, managed under contract by the RTI Cooperativa Sociale Quadrifoglio";

- "The Municipality of Bologna directly manages 67 preschools located throughout the municipality. The preschools are part of the Intermediate Unit Services Zerosix of the Education, Instruction and New Generations Area and are coordinated by 28 pedagogical coordinators (...) who in turn report to six Territorial Unit Managers, each of whom is responsible for managing all 0-6 Services (nurseries, preschools, and supplementary services) located in the city's six districts";

- Service communications (...) are mostly handled by the Management of the Zerosei Intermediate Services Unit via email";

- "With respect to the communication sent to schools on XX, a general mailing was carried out in consideration of the urgent need to provide the necessary information to school staff so they could then inform families in time for the strike day (...) the files containing the list of services not guaranteed during the strike do not involve the processing of personal data, but contain only the indication of those services that, as a result of the strike, the contractor is unable to provide and therefore are suspended. These files were prepared by the educational services contractor for subsequent forwarding to schools by the management of UI Servizi Zerosei.

- "The accidental inclusion of the personal data of 61 children in one of the above-mentioned files is attributable to the fact that, under the same contract, the RTI Cooperativa Sociale Quadrifoglio/Coop sociale O.R.S.A. manages, among other things, educational services for students with disabilities, including those enrolled in municipal preschools. As part of this management, the contractor is provided by the same department within the organization (UI Servizi Zerosei of the Education, Instruction, and New Generations Area) with the personal and sensitive data of children receiving inclusion services, for the purpose of designing individual interventions.

- "The Quadrifoglio cooperative, as the agent of the temporary consortium, has been designated as the external data controller, and a specific agreement has been signed between the parties for this purpose (...)";

- "With resolution PG 362301/2018, all employees assigned to the U.I. Zerosei Services are authorized to process personal data within the organizational units to which they are assigned;

- "Formal notification of the incident was promptly given to the interested parties and to this esteemed Guarantor, pursuant to Articles 34 and 33 of EU Regulation 2016/679."

With a subsequent note dated XX, to which reference is made in full, the Municipality, in response to the request for information made by this Authority dated XX (ref. no. XX), stated that:

- "School assistants are responsible for viewing incoming emails and sorting them in hard copy to all or part of the work group, depending on the communications they contain. This role is assigned to this individual because in municipal preschools, school assistants have a broader role than simple cleaning and surveillance duties, and in particular, in the declaration of activities specific to the professional profile approved by resolution of the Municipal Council of Preschools (P.G.), No. 228627/2005 (…), the following duties are expressly provided: maintaining relationships, information, and communications, with particular attention to relationships with parents and collaboration with teachers; using the technological and IT tools provided for basic processing and communication functions;

- "Within the organization of school and educational services directly managed by the Municipality of Bologna, procedures involving the processing of personal data relating to children, families, and staff are assigned to administrative staff offices (central or regional) or other levels of responsibility, as there are no administrative staff in the schools. In many cases, school staff access to the personal data of enrolled children through paper documents (sometimes provided directly by families) or through sharing restricted-access folders with the relevant managers.

- "In summary, the aforementioned staff has access to the shared email account due to their duties and is authorized to process related data, as well as being adequately instructed and trained."

The Quadrifoglio social cooperative, in a note dated XX, to which reference is made in full, responded to the request for information made by this Authority on XX (ref. no. XX), as follows:

- "On XX, the Municipality of Bologna awarded the contract for the management of educational services for the school inclusion of students with disabilities, supplementary school educational services, and specialized services for the improvement of the curriculum in the city's preschools to the newly established temporary consortium between the Quadrifoglio social cooperative (lead agent) and O.R.S.A., a social cooperative (principal), for the period XX with the option to renew for an additional two school years”;

- “pursuant to the Tender Specifications, the Quadrifoglio Social Cooperative (hereinafter the "Agent") is required to inform the Municipality of Bologna (hereinafter the "Client") of any disruptions to service (e.g., strikes). The Agent undertakes to notify the Client of any union strikes resulting in staff absences and the consequent need to reorganize services. Subsequently, the Client shall inform the respective school services; Finally, the communication was sent by school services to families.

- "For service management, the Client shall send the Agent's pedagogical coordination service, before the start of the school year, a document containing the sensitive data relating to the minors in their care (name, surname, date and place of birth, citizenship, type of disability, ICD-IO code), necessary for the activation and management of the school inclusion service for minors with disabilities."

- "On the occasion of a general strike called for the XXth day, the Agent sent an email to the Client (dated XX), according to the procedure described above, to report the services not provided for the strike day. It is noted that the email, signed (... by) the coordinator of the integrative and school inclusion services of the municipal preschools in the Borgo-Reno, Navile, and Porto-Saragozza areas, contained six attached files relating to the services provided in the six Bologna neighborhoods. The files relating to the territories of Borgo-Reno, Navile, Porto-Saragozza contained 2 sheets: the first (…) containing only the information relating to the closure/opening of supplementary services on the strike day indicated above; The second sheet, however, was incorrectly retained and contained information relating only to the school inclusion service, thus retaining sensitive data relating to minors in its care.

Based on the information acquired, the Office notified, with a note dated XX (ref. no. XX), the Municipality, as data controller, pursuant to art. 166, paragraph 5, of the Code, of the initiation of the procedure for the adoption of the provisions referred to in art. 58, paragraph 2, of the Regulation, as a municipal office (UI Servizio Zerosei) sent an email with several files attached, containing particular categories of student data, to the email addresses of the sixty-seven preschools in the area, to the twenty-six pedagogical coordinators, to the six heads of the territorial units located in the six districts of the city, and a municipal preschool sent one of the aforementioned files to fifty-three email addresses of the parents of children enrolled in that school, in the absence of an appropriate legal basis in violation of the Articles 5, 6, and 9 of the Regulation, and Articles 2-ter and 2-sexies of the Code.

With the same note, the data controller was invited to submit written statements or documents to the Data Protection Authority or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The Municipality submitted its defense briefs, with a note dated XX (ref. No. XX), to which reference is made in full, stating, in particular, that:

- "The accidentally communicated data consist of sensitive personal data relating to 61 children attending, at the time, the municipal preschools in the Porto Saragozza and Santo Stefano districts of the City, consisting of: name, surname, date and place of birth, citizenship, certifications held - CIS (certificate of school integration), functional diagnosis, certifications pursuant to law 104/92, type of disability, ICD10 code, CIS revision date.It also includes information relating to the year of enrollment, school attendance schedule, assigned intervention hours, and various notes.

- "With regard to the number of individuals who potentially had access to this data, only one individual in each school is authorized to use the school's email. It is therefore confirmed that, by job description, school staff are responsible for viewing incoming emails and sorting them into paper copies for all or part of the workgroup, depending on the communications they contain. This function is performed by a single staff member who receives and reads the email. In this case, the planned operation was to print the email text (so it could be shared with teachers) and note the information in the table, which was supposed to only list guaranteed and non-guaranteed services. No indication was included regarding the potential circulation of the email."

- "The sending of the data in question to the 50 families of preschool XX was also caused by human error by the school staff member. Indeed, if the employee had carefully read the provisions contained in the aforementioned email, she would have easily concluded that there was no information to provide to families for the school in question, as there were no before- and after-hours services available at that school. In the school (...), in fact, the educational enhancement service was offered for both classes from 1:30 PM to 3:30 PM (in conjunction with the teaching staff), and therefore the strike did not impact the daily functioning of the school service.

- "The breach of personal data is the result of manifestly negligent conduct by an employee of the Quadrifoglio Cooperative in the material performance of simple office tasks, carried out by inserting, without any reason, in a communication (or rather, in files attached to an email) personal data relating to minors with disabilities that were not relevant to the purpose for which the communication itself was drafted. This communication (...) should have contained only the list of services unavailable during the aforementioned strike. Therefore, the operator, on behalf of the Data Controller, contaminated the communication process with the schools involved with elements that were completely unrelated to it, transmitting unnecessary data that was then forwarded by school staff.

- "This aspect consequently impacts the subjective element of the alleged violation, resulting in the exclusion of the Municipality's liability, or, alternatively, only marginal liability."

- "The Municipality, in order to mitigate the effects of the violation, promptly contacted the recipients after becoming aware of the error, informing them that they were not permitted to further process the data received and that they should have it deleted immediately (...). Furthermore, following a mediation process initiated by the parents of one of the data subjects whose data was subject to the violation, the Municipality awarded them financial compensation to remedy the damage that occurred. The compensation paid, precisely by virtue of the acknowledged liability, has been fully reimbursed to the Administration by Coop Quadrifoglio”;

- “this Administration has defined new and more stringent instructions for the Cooperative responsible for data processing”;

- “a specific audit was also conducted at the Cooperative”;

- “new instructions have been given to all employees assigned to the Zerosei Intermediate Services Unit (…) and new procedural methods and additional organizational measures have been adopted, implemented immediately, aimed at ensuring greater security of the personal data processed. A dedicated section has been created on the intranet dedicated to nursery and preschool staff, serving as a repository for employees and school staff, containing the instructions and measures implemented. Furthermore, it has been established that all service communications sent to schools will be rigorously monitored. Attached files are now always converted to PDF, and communications specify that these are internal communications and should not be disclosed to third parties. Numerous working meetings were held with coordinating staff (Territorial Unit Managers and educational coordinators) to further explore the topic, and specific operational guidelines were shared for the processing of so-called "sensitive" personal data within the scope of the municipal Zerosei services (...). All staff received periodic basic training on personal data protection (...) To prevent accidental leakage, all personal data is shared via hard drive folders with restricted access to authorized personnel only.

- "From a security perspective, both physical and IT security measures are in place."

- "In the notification (... pursuant to Article 33 of the Regulation), all the information required by law was provided to the Authority. Therefore, the subsequent complaint filed by the interested party (...) concerned a situation that was widely known to the Authority following the aforementioned notification";

- "the personal data breach being investigated was not the result of intentional or malicious actions, and the number of third parties receiving the communication is objectively small. Furthermore, it is considered appropriate to highlight the fact that these third parties are part of the same school community, with an obvious concern for the confidentiality of minors' data, which they unwittingly received. These circumstances are of primary importance in assessing the actual impact of the breach.

3. Applicable law.

3.1 The regulatory framework.

The data protection framework established by the Regulation provides that the processing of personal data by public bodies is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

The legal basis for the aforementioned processing must be established by Union or Member State law, which must pursue "an objective of public interest [and be] proportionate to the objective pursued" (Article 6, paragraph 3, of the Regulation).

In this context, it is established that "Member States may maintain or introduce more specific provisions to adapt the application of the rules of the […] Regulation with regard to processing in accordance with paragraph 1, letters (c) and (e), determining more precisely specific requirements for processing and other measures to ensure lawful and fair processing […]” (Article 6, paragraph 2, of the Regulation).

The Code has established that “the legal basis referred to in Article 6, paragraph 3, letter b), of the Regulation shall be a law or regulation or general administrative acts” (Article 2-ter, paragraph 1).

In particular, processing operations consisting of the “dissemination” and “communication” of personal data are permitted only when provided for by a law, regulation, or general administrative act (Article 2-ter, paragraph 3 of the Code).

With regard to special categories of personal data, processing is, as a rule, permitted when “necessary for reasons of substantial public interest on the basis of Union or Member State law, which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject” (Article 2-ter, paragraph 3 of the Code). 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in domestic law, by laws, regulations, or general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest grounds, as well as the appropriate and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

The data controller is, in any case, required to comply with data protection principles, including "lawfulness, fairness, transparency," and "minimization," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" and must be "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c) of the Regulation), and must process the data using "authorized" personnel. and "instructed" regarding access to data (Articles 4, point 10), 29, and 32, paragraph 4, of the Regulation).

3.2 The processing of personal data carried out by the Institute.

From the investigation carried out, based on the information acquired and the facts that emerged from the preliminary investigation, as well as subsequent assessments by this Department, it is established that the Intermediate Unit (UI) Zero-six Services of the Education, Instruction, and New Generations Area of the Municipality communicated personal data, including data relating to the health of students, by forwarding an email, originally received from the Quadrifoglio Social Cooperative, to the sixty-seven municipal preschools in the area, to the six heads of territorial units that manage all 0-6 Services (nurseries, preschools, and supplementary services), and to the twenty-six pedagogical coordinators.

This communication, in particular, contained, in addition to information regarding the management of possible reductions in supplementary services during a strike day, personal data relating to the health of children enrolled in certain preschools (including the names of the students, place and date of birth, citizenship, types of disability, specific pathologies suffered, disability classification code (ICD10 code), certifications held, and an indication of the resources for school integration (teachers/educators) allocated to the students).

Subsequently, a school assistant at the XX municipal preschool sent one of the files attached to the aforementioned email, containing the aforementioned personal data, to fifty-three email addresses registered to the parents of children enrolled in that school for the XX school year.

As a preliminary point, it is noted that minors, as "vulnerable natural persons," deserve "specific protection with regard to their personal data, as they may be less aware of the risks, consequences, and safeguards involved, as well as of their rights in relation to the processing of personal data" (recital 38 of the Regulation).

It is also noted that, pursuant to Article 4(1), no. 15 of the Regulation, "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about the state of health of that natural person" are considered data concerning health.

Given the definition of personal data and health data (Article 4, points 1 and 15, of the Regulation), it is believed that the information regarding the types of disabilities reported in the aforementioned documents, the classification code for these disabilities, the certifications held or not held by the children, and the assignment of resources for school integration (teachers/educators) to students allow us to obtain information on the health status of the minors listed.

That said, with regard to the first aspect highlighted, regarding the provision by the aforementioned municipal office of the documents containing the aforementioned information regarding the health status of minors to preschools, to the heads of all territorial units managing all 0/6 Services, and to pedagogical coordinators, the following is highlighted.

As the Italian Data Protection Authority has repeatedly stated, personnel authorized to process personal data by the data controller (Article 29 of the Regulation and Article 2-quaterdecies of the Code) are entitled to process only the information relevant and necessary to carry out the activities assigned to them, based on organizational choices and the specific tasks performed (see, albeit in different contexts, provision no. 322 of September 16, 2021, web doc. no. 9711517, no. 214 of May 27, 2021, web doc. 9689234, no. 105 of June 18, 2020, web doc. no. 9444865).

In this specific case, however, the aforementioned municipal office transmitted to certain schools and employees (local unit managers, pedagogical coordinators, etc.) numerous personal data, including health data, of minors enrolled in schools in areas other than those under the jurisdiction of the aforementioned entities and schools. This information, therefore, is superfluous and unnecessary for the performance of the duties assigned to the personnel receiving the communication.

Although the documents in question were made available only to individuals within the data controller's organization, and the information contained therein was not made accessible to "external" parties within that context, the data was nevertheless made available to a very broad, specific or identifiable group of individuals, such as preschools other than those to which the children belong, the heads of territorial units, and the pedagogical coordinators responsible for schools not attended by the minors in question. This access was not, however, exclusively to the personnel responsible for the territory and area of assignment.

Although these individuals, by virtue of their roles and the functions performed under the applicable regulations, may certainly process the personal data of students within the scope of their educational and instructional activities, they cannot, however, be considered legitimately entitled to process, as in this case, the personal data, including data relating to the health of minors enrolled in schools other than those under their jurisdiction.

Furthermore, with reference to the different profile under examination, relating to the sending by the XX nursery school of the email containing the attached document called “PortoSaragozza", containing the aforementioned personal data, including health data, of approximately sixty children, to the email addresses of approximately fifty parents of pupils of the school, it is stated that such data were made known, albeit due to a material error, in any case in favour of a specific or determinable number of third parties (art. 4, par. 1 no. 10 of the Regulation), giving rise to a communication of numerous personal data, including health data (including types of disability, specific pathologies suffered, disability classification code, certifications held, indication of resources for school integration - teachers/educators - attributed to the pupils) of the interested parties, minors and, as such, particularly vulnerable (see cons. 38 of the Regulation, as well as provision of 27 November 2024, no. 728, doc. Web no. 10097324, provision of December 12, 2024, no. 767, web doc. no. 10099052, provision of February 27, 2025, no. 117, web doc. no. 10118264).

In light of the foregoing considerations, the sending of the aforementioned email with attached documentation containing personal data, including data relating to the health of the minors listed therein, effectively made the preschools different from those of the children listed therein, the Heads of Territorial Units, the pedagogical coordinators responsible for different areas and schools, as well as the parents of students enrolled in school XX, informed of the personal situations and information relating to the health of particularly vulnerable minors (see the definition of "communication" of personal data contained in Article 2-ter, paragraph 4, letter a), of the Code).

While acknowledging that this communication occurred following a simple error, due to the forwarding of an email containing the aforementioned documentation by the Quadrifoglio cooperative—without prejudice to the assessments regarding the lawfulness of the processing carried out by the cooperative, which will be the subject of a separate proceeding—it is noted that the Municipality, in any case, did not monitor and verify the content of the document received for forwarding, obligations it was also required to fulfill based on the "general responsibility" placed on the data controller (Articles 5, paragraph 2, and 24 of the Regulation, see Order No. 81 of March 7, 2019, web doc. 9121890; Order No. 160 of September 17, 2020, web doc. 9461168; Order No. 294 of July 22, 2021, web doc. 9698724).

For these reasons, this Municipality has processed personal data in violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

4. Conclusions.

In light of the above considerations, taking into account the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 13 of the GDPR. 168 of the Code – it is stated that the information provided by the data controller in the defense briefs does not address the concerns notified by the Office with the initiation of the proceedings and is insufficient to allow the dismissal of this proceeding, since none of the cases provided for by Article 11 of the Guarantor Regulation No. 1/2019 apply.

Therefore, the Office's preliminary assessments are confirmed and the unlawful processing of personal data by the Municipality is found, having occurred in the absence of lawful processing conditions, in violation of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

Violation of the aforementioned provisions gives rise to the administrative sanction provided for in Article 83, paragraph 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation itself, as also referred to in Article 166, paragraph 2, of the Code.

Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation as well as Article 166, paragraph 2, of the Code, 166 of the Code, has the power to “impose an administrative pecuniary sanction pursuant to Article 83, in addition to the [other] [corrective] measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case” and, in this context, “the [Garante] Board adopts the injunction order, with which it also orders, with regard to the application of the accessory administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code” (Article 16, paragraph 1, of the Guarantor Regulation no. 1/2019).

Considering that the Institute's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative fine does not exceed the amount specified for the most serious violation. Considering that, in the present case, all the violations ascertained—Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Articles 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code—are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article Pursuant to Article 166, paragraph 2, of the Code, the total amount of the fine is up to €20,000,000 (twenty million).

The aforementioned administrative fine imposed, depending on the circumstances of each individual case, must be determined with due consideration of the factors set out in Article 83, paragraph 2, of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the breach, it must be considered that the communication concerned a large number of vulnerable data subjects (see Article 83, paragraph 2, letter a), of the Regulation);

- with specific regard to the subjective nature of the breach, it was caused by material errors resulting from an incorrect communication received from the data controller (Article 83, paragraph 2, letter b), of the Regulation);

- Regarding the categories of personal data communicated, this includes special categories of data relating to minors (Article 83, paragraph 2, letter g) of the Regulation).

In light of this specific circumstance, the severity of this breach committed by the data controller is considered high in this case (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of 24 May 2023, point 60).

The following mitigating circumstances must also be considered:

- the data controller has taken measures to mitigate the damage and prevent the recurrence of similar incidents (Article 83, paragraph 2, letter c) of the Regulation);

- there are no previous relevant breaches committed by the data controller, taking into account the circumstances in which the breaches occurred (Article 83, paragraph 2, letter e) of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83, paragraph 2, letter f) of the Regulation).

Based on the above factors, assessed as a whole, the fine is deemed to be €40,000.00 (forty thousand/00) for violations of Articles 5, paragraph 1, letters a) and c), 6, paragraphs 1, letters c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, this chapter containing the injunction order should be published on the Italian Data Protection Authority's website.

This is in consideration of the specific circumstances of this specific case, regarding the communication of personal data, including special categories of data of numerous students, in the absence of a lawful basis.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW CONSIDERING ALL THE ABOVE, THE ITALIAN DATA PROTECTION AUTHORITY

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Municipality of Bologna in the terms set out in the justification is unlawful due to the violation of Articles 5, paragraph 1, letter e), and 83 of the Regulation. a) and c), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulations, and 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code;

ORDERS

pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulations, as well as Article 166 of the Code, the Municipality of Bologna, with registered office at Piazza Maggiore 6, 40124 Bologna - VAT No. 01232710374, to pay the total sum of €40,000.00 (forty thousand/00) as an administrative fine for the violations indicated in the justification. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

the Municipality of Bologna:

- to pay the total sum of €40,000.00 (forty thousand/00) in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, the publication of the injunction order on the Guarantor's website;

pursuant to Article 17 of the Guarantor Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, as provided for by Art. 57, paragraph 1, letter u), of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, April 29, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Cerrina Feroni

THE ACTING SECRETARY GENERAL
Filippi
  1. The processor, who was not part of the settlement, spontaneously decided to cover the amount.