Garante per la protezione dei dati personali (Italy) - 10161361

From GDPRhub
Garante per la protezione dei dati personali - 10161361
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(1)(c) GDPR
Article 6(1)(c) GDPR
Article 6(1)(e) GDPR
Article 6(2) GDPR
Article 6(3) GDPR
Article 37(7) GDPR
Art.2-ter c.1 and 2 d. lgs. 196/2003
Art. 7-bis c.3 d. lgs.33/2013
Art. 14 c.1 d. lgs. 33/2013
Type: Complaint
Outcome: Upheld
Started:
Decided: 23.06.2025
Published:
Fine: n/a
Parties: A municipality
National Case Number/Name: 10161361
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Italian
Original Source: GDPRD (in IT)
Initial Contributor: cci

The DPA warned a municipality for unlawfully publishing personal data of a former town councilor and clarified that the publication was not covered by transparency obligations under national administrative law.

English Summary

Facts

A town council published personal data of a town councilor (the data subject) on its website. The data included the data subject’s CV and a declaration that no causes of incompatibility prevented his election as councilor. After resigning from office, the data subject filed a complaint, claiming that the publication of his personal data on the municipality’s website was illegal. The municipality was considered to be the controller for the purpose of the complaint.

In its defense, the controller claimed that the publication of the data was lawful under the legal basis of 6(1)(c) GDPR (legal obligation). Specifically, the controller argued that national law (specifically, Article 20 d. lgs. 39/2013) required it to publish the data subject’s information and to keep it available for three years despite his resignation from office.

During the investigation, the DPA incidentally found that the controller had appointed a DPO but had not communicated their contact details to the DPA.

Holding

The DPO upheld the complaint and issued a warning.

On lawfulness

The DPA clarified that the provisions invoked by the controller, only required the publication of information about administrative officers, not political officers. In this regard, the DPA referred to the guidance from Italy’s anti-corruption authority.

On these grounds, the DPA held that the controller unlawfully published the subject’s data. The DPA considered this a violation of Articles Article 5 GDPR and Article 6 GDPR, Article 2-ter of Italy’s data protection code, and two provisions of Italian administrative law (Articles 7-bis and 14 d. lgs. 33/2013). Additionally, the DPA found that the controller violated the principle of data minimisation (5(1)(c) GDPR) by processing data that were not necessary for the purpose of administrative transparency.

On the DPO’s contact details

The DPA held that the controller violated Article 37(7) GDPR by failing to communicate the contact details of its DPO. The DPA considered this a minor infraction because the DPO’s contact details were available on the controller’s website.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10161361]

Provision of June 23, 2025

Register of Provisions
no. 361 of June 23, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, Attorney, members, and Dr. Claudio Filippi, Acting Secretary General;

SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter "GDPR");

SEEN Legislative Decree no. Legislative Decree No. 196 of June 30, 2003, containing the "Personal Data Protection Code" (hereinafter the "Code");

SEEN General Provision No. 243 of May 15, 2014, containing the "Guidelines on the processing of personal data, including those contained in administrative records and documents, carried out for advertising and transparency purposes on the web by public bodies and other obligated entities," published in the Official Journal No. 134 of June 12, 2014 and on www.gpdp.it, web doc. No. 3134436 (hereinafter the "Transparency Guidelines");

SEEN Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No. 98 of 4/4/2019, published in the Official Journal no. 106 of 8/5/2019 and at www.gpdp.it, web doc. no. 9107633 (hereinafter "Data Protection Authority Regulation no. 1/2019");

SEEN the documentation in the file;

SEEN the observations made by the Secretary General pursuant to Article 15 of Data Protection Authority Regulation no. 1/2000 on the organization and functioning of the Office of the Data Protection Authority, at www.gpdp.it, web doc. no. 1098801;

Rapporteur: Attorney Guido Scorza;

WHEREAS

1. Introduction

This Authority has opened an investigation against the Municipality of XX in reference to the complaint filed by former municipal councilor XX (hereinafter "the complainant").

Specifically, the complainant stated that he had been a city councilor and had resigned from his institutional office, but that, despite this, his personal data, including his CV, were still being published online on the aforementioned Municipality's institutional website.

The preliminary investigation conducted by this Department revealed that the complainant's personal data, including the following documents, can be viewed in the "Transparent Administration" section of the Municipality's institutional website homepage, under "Organization"/"Holders of Political, Administrative, Management, or Government Offices"/"City Council":

1) CV available at the URL:

https://...

2) Declaration of the absence of reasons for the complainant's ineligibility and incompatibility with the office of local administrator, containing personal data, including name, date and place of birth, residence, domicile, and handwritten signature, available at the URL:

3) https://...

The complainant stated that, before filing the complaint with the Guarantor, he exercised his rights regarding the protection of personal data for himself and the other resigning councilors, by submitting a specific request to the Municipality, requesting the deletion of the data.

Furthermore, during the investigation, the "Privacy Policy" section on the home page of the institutional website was checked, with particular reference to the details of the "Data Protection Officer," who appears to be XX, i.e., a different individual from the one communicated by the Municipality to the Guarantor with note prot. no. XX of XX – pursuant to Article 37, paragraph 7, of the GDPR – via the dedicated web procedure on this Authority's website.

2. Personal data protection legislation

Pursuant to the relevant legislation, "personal data" is "any information relating to an identified or identifiable natural person ('data subject')" and "an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person" (Article 4, paragraph 1, no. 1, of the GDPR).

With specific reference to the case brought to the attention of this Authority, it is recalled that public bodies, such as the Municipality, may disclose "personal data" in the cases provided for by Article 4, paragraph 1, of the GDPR. 2-ter, paragraphs 1 and 3, of the Code, in compliance – in any case – with data protection principles, including the principle of "minimization," according to which personal data must be "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letter c, of the GDPR).

Since 2014, the Garante has provided specific guidance to public administrations on the precautions to be taken for the dissemination of personal data online with General Provision No. 243 of May 15, 2014, containing the "Guidelines on the processing of personal data, including those contained in administrative records and documents, carried out for advertising and transparency purposes on the web by public bodies and other obligated entities," published in the Official Journal No. 134 of June 12, 2014 and in www.gpdp.it, web doc. No. 3134436 (currently being updated, but still substantially current).

Furthermore, with regard to the obligations regarding the designation of the Data Protection Officer (DPO), European data protection legislation requires the "controller or processor shall publish the contact details of the DPO and communicate them to the supervisory authority" (Article 37, paragraph 7, GDPR). This communication must be made following the specific procedure indicated on the Garante's institutional website at https://servizi.gpdp.it/comunicazionerpd/s/.

3. Preliminary assessments by the Office of the processing of personal data carried out.

From the documents in the file, it emerged that the complainant was elected as a municipal councilor on XX and that he resigned from his position on XX.

Regarding the online dissemination of personal data contested by the complainant, the Municipality of XX, with note prot. no. XX of XX, responded to the Office's request for information and justified its conduct by citing the need to comply with the online publication obligations regarding transparency set forth in Article 14 of Legislative Decree No. 33/2013.

In this regard, however, with note prot. No. XX of XX, the Office informed the Municipality that, pursuant to the aforementioned state transparency regulations, public administrations are required to publish – with reference to municipal councilors as holders of political offices – the documents indicated in Article 14, paragraph 1, of Legislative Decree No. 33/2013 and to maintain them online for a period of "three years following the termination of the mandate or assignment of the individuals [...]" even if they resign (see ANAC FAQ No. 5.13 regarding transparency regarding the application of Legislative Decree No. 33/2013).

However, the Office pointed out to the Municipality that the documents required to be published pursuant to the aforementioned regulation include the councilor's curriculum vitae, but not the declaration of absence of grounds for ineligibility and incompatibility. This declaration, however, was published online in full and with incomplete information, such as the councilor's residence, domicile, and handwritten signature.

Therefore, from the investigations conducted based on the information acquired and the facts emerging from the preliminary investigation, as well as subsequent assessments, the Office, with the aforementioned memorandum no. XX, determined that the Municipality of XX—by disseminating the personal data and information contained in the declaration of absence of grounds for ineligibility and incompatibility submitted at the time by the complainant in his capacity as a municipal councilor, and by failing to communicate the change in the DPO's details to the Guarantor—had engaged in conduct that was inconsistent with the relevant provisions on the protection of personal data contained in the GDPR. Therefore, the same note notified the Municipality of the violations committed (pursuant to Article 166, paragraph 5, of the Code), communicating the initiation of the procedure for the adoption of the measures referred to in Article 58, paragraph 2, of the GDPR, and inviting the entity to submit written defenses or documents to the Guarantor and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of 24/11/1981).

4. Defense briefs.

The Municipality of XX, with note prot. No. XX of XX, sent the Guarantor its defense briefs in relation to the notified violations.

In this regard, it is recalled that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Guarantor, falsely declares or certifies information or circumstances, or produces false documents or records, is liable pursuant to Article 168 of the Code, entitled "False declarations to the Guarantor and interruption of the performance of the duties or exercise of the powers of the Guarantor."

Specifically, regarding the contested publication of the declaration declaring the absence of grounds for ineligibility or incompatibility of the complaining councilor, the administration highlighted, among other things, that:

- "pursuant to Article 20, paragraphs 1 and 2, of Legislative Decree 39/2013, elected municipal councilors, upon being appointed, must submit a declaration declaring the absence of any of the grounds for ineligibility or incompatibility set forth in the same decree.The same provision (Article 20, Legislative Decree 39/2013), in the third paragraph, specifies that the aforementioned declarations must be published on the website of the public administration that awarded the assignment.

- "In this regard, the ANAC reiterated that 'the administrations and entities to which the declaration is made, pursuant to Article 20, paragraph 3, of Legislative Decree no. 39/2013, are required to publish it in the section of the institutional website entitled 'Transparent Administration.' The declaration […] must be available for consultation through a link on the website of the administration or entity that awarded the assignment.'"

- "Therefore, from the above, there is an obligation to publish on the administration's website the declaration of ineligibility and incompatibility with respect to holding positions in public administrations, including, obviously, that of municipal councilor. Therefore, the publication of the [complainant's] declaration of incompatibility is certainly legitimate."

- "Regarding the failure to promptly communicate the change in the contact details of the Data Protection Officer (DPO), it was added that [...] On this point, in reality, one can only admit the failure, caused simply by human error. However, it is important to specify that following the Guarantor's detection of the failure to communicate the change in the contact details of the DPO designated by the Municipality, the latter promptly took action. In fact, as early as XX, the administration had been providing the aforementioned communication through the website of the Italian Data Protection Authority."

- "The failure to communicate the DPO's contact details, in any case, did not negatively impact the Authority's ability to contact the DPO easily and directly."

- "With regard to the alleged online dissemination of personal data [...], it is reiterated that the Municipality of XX has deleted the document entitled "Declaration of Incompatibility XX."

- "The municipal administration will organize a training course on personal data protection for those responsible for managing the "Transparent Administration" section of the website and its employees, also with the aim of raising awareness on the issue and avoiding future errors."

5. Assessments by the Guarantor

The issue at issue in the case brought to the attention of the Guarantor concerns the dissemination of personal data and information contained in the declaration of the absence of grounds for ineligibility and incompatibility, submitted at the time by the complainant in his capacity as a municipal councilor, published online.

The aforementioned declaration clearly stated, in addition to the councilor's name, his date and place of birth, his residential and domicile address, and his handwritten signature.

The Municipality justified its conduct by citing the need to apply Article 20 of Legislative Decree no. 39 of April 8, 2013, which requires the publication on the public administration's website of declarations declaring the absence of grounds for ineligibility or incompatibility as set forth in the aforementioned decree (paragraphs 1-3).

The reconstruction offered by the Authority clarifies some aspects of the issue and is certainly useful for assessing the conduct, but it does not appear adequate to overcome the critical observations raised by the Office.

In this regard, it should be noted that Article 20 of Legislative Decree No. 39/2013, cited by the Municipality to justify the disclosure of the former councilor's personal data, is not applicable to the case at hand.

This is because the publication obligations set forth therein refer only to declarations required by individuals appointed to the administrative, managerial, top-level, and executive positions listed in Legislative Decree No. 39/2013, which do not include municipal councilors.

This interpretation is confirmed by the ANAC, which highlighted that "the purpose of Legislative Decree no. 39/2013 is to protect the independence of administrative offices from undue influence from politics or private interests and that, therefore, the legislation identifies situations of incompatibility/ineligibility for administrative offices only. In no way can the legislative text in question imply consequences for the forfeiture of political offices, which cannot be questioned by virtue of the aforementioned provisions" (Resolution no. 1007 of 23/10/2019, at https://www.anticorruzione.it/-/delibera-numero-1007-del-23-ottobre-2019).

For this reason, it is believed that Article 20 of Legislative Decree no. 39/2013 – contrary to what the Municipality claims – cannot constitute an adequate legal basis to justify the online dissemination of the complainant's personal data contained in the declaration of the absence of causes of ineligibility and incompatibility, as it does not satisfy any of the lawfulness requirements set forth in Article 2-ter of the Code. Furthermore, the provision of additional information regarding the date and place of birth, the address of residence and domicile, as well as the handwritten signature of the then municipal councilor, is contrary to the principle of data minimization, as the data is excessive and not "limited to what is necessary in relation to the purposes for which it is processed" (Article 5, paragraph 1, letter c, GDPR).

Regarding the further issue, which arose during the investigation, regarding the indication in the privacy notice on the home page of the institutional website of the Municipality of XX of a Data Protection Officer (DPO) other than the one communicated to the Italian Data Protection Authority – pursuant to Article 37, paragraph 7, of the GDPR – with note no. XX of XX, the municipality admitted "the failure to timely communicate the change in the contact details of the DPO" to this Authority. However, in this regard, it was stated that this conduct was "trivially caused by human error" and that the situation was remedied by properly notifying the Guarantor, which was indeed done and recorded under file no. XX of XX.

6. Outcome of the investigation into the complaint

The circumstances highlighted in the defense briefs of the Municipality of XX, examined as a whole, although certainly worthy of consideration for the purposes of assessing the conduct, are not sufficient to allow the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Guarantor Regulation no. 1/2019, as none of the cases envisaged in Article 11 referred to therein apply.

In this context, the Office's preliminary assessments are confirmed in note file no. XX of XX, and it is found that the conduct of the Municipality of XX did not comply with the relevant regulations regarding the protection of personal data, as the aforementioned Municipality

1. disclosed the complainant's personal data (name, date and place of birth, residence, domicile, and handwritten signature) contained in the document entitled "Declaration of Incompatibility," published online:

a) in the absence of an appropriate legal basis, in violation of the provisions of Article 2-ter, paragraphs 1 and 3, of the Code; Articles 7-bis, paragraph 3, and 14, paragraph 1, of Legislative Decree No. 33/2013; and Article 6, paragraph 1, letters c) and e), paragraph 2, and paragraph 3, letter b), of the GDPR;

b) in violation of the principle of data minimization, which does not "limit data to what is necessary in relation to the purposes for which they are processed" (i.e., administrative transparency), as set forth in Article 5, paragraph 1, letter c), of the GDPR;

2. failed to promptly notify the Data Protection Authority (but only following a complaint from this Authority) of the change in the contact details of the Data Protection Officer (DPO) designated by the Municipality, in violation of Article 37, paragraph 7, of the GDPR.

It is believed, however, that the particularity of this case must be considered in any case, which presents a series of circumstances that merit careful evaluation. In particular, the fact that:

- the Municipality of XX is a small entity with just over 400 inhabitants and an extremely small number of employees;

- The data controller, following the Office's request, promptly intervened, collaborating with the Authority during the investigation of this proceeding in order to remedy the violation and mitigate its potential negative effects;

- The conduct noted, in violation of personal data protection regulations – given the Municipality's declarations – stems from the belief that the disputed documents must be published pursuant to Article 20 of Legislative Decree No. 39/2013 (according to a broad interpretation of the transparency principle) and is therefore clearly negligent;

- In this case, the aforementioned conduct involved a small number of data subjects (the complainant and two other municipal councilors), whose shared data did not belong to special categories or to criminal convictions or offenses (Articles 9 and 10 of the GDPR);

- the data controller has declared that the conduct has ceased, removing the personal data contained in the online statement from the website and notifying the Data Protection Authority of the change in the DPO's contact details;

- the response to the Data Protection Authority also described certain technical and organizational measures implemented pursuant to Articles 25-32 of the GDPR;

- there are no previous relevant GDPR violations committed by the entity;

- in relation to the failure to notify the Data Protection Authority of the update of the DPO's contact details—as indeed represented by the Municipality—it was nevertheless possible to contact the DPO easily and directly, as the data was correctly published on the institutional website.

The circumstances of this specific case therefore lead to the classification of this case as a "minor violation" pursuant to Article 148, Article 83(2) of the GDPR, and the "Guidelines on the application and provision of administrative pecuniary sanctions for the purposes of Regulation (EU) No. 2016/679," adopted by the Article 29 Working Party on October 3, 2017, WP 253, and endorsed by the European Data Protection Board with "Endorsement 1/2018" of May 25, 2018.

In light of all of the above, and the overall circumstances of the case at hand, rather than imposing a pecuniary sanction, it is deemed sufficient to warn the data controller for the violation of the above provisions, pursuant to Article 58(2)(a) of the GDPR. b) of the GDPR (see also recital 148 of the GDPR).

Finally, it is believed that the conditions set forth in Article 17 of the Regulation of the Italian Data Protection Authority no. 1/2019 are met.

NOW THAT THE ABOVE STATEMENT IS BASED, THE GUARANTOR

having noted the unlawfulness of the conduct and processing carried out by the Municipality of XX, represented by its legal representative pro tempore, with registered office in XX – within the time limits indicated in the grounds pursuant to Articles 58, paragraph 2, letter b) of the GDPR

WARNS

the Municipality of XX for violating Articles 5, paragraph 1, letter c); 6, paragraph 1, letters c) and e); paragraph 2 and paragraph 3, letter b); 37, paragraph 7, of the GDPR, as well as Article 2-ter, paragraphs 1 and 3, of the Code

ORDERS

that violations and measures adopted pursuant to Article 58, paragraph 2, of the GDPR be recorded in the Authority's internal register with this provision, as required by Article 17 of the Guarantor Regulation No. 1/2019.

Pursuant to Article 78 of the GDPR, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, June 23, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Scorza

THE ACTING SECRETARY GENERAL
Filippi

[web doc. no. 10161361]

Measure of June 23, 2025

Register of Measures
no. 361 of June 23, 2025

THE DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Claudio Filippi, Acting Secretary General;

HAVING SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, the "General Data Protection Regulation" (hereinafter "GDPR");

HAVING SEEN Legislative Decree No. 196 of 30 June 2003, containing the "Personal Data Protection Code" (hereinafter "Code");

HAVING SEEN General Provision No. 243 of 15 May 2014, containing the "Guidelines on the processing of personal data, including those contained in administrative records and documents, carried out for advertising and transparency purposes on the web by public bodies and other obliged entities," published in the Official Journal No. 134 of 12 June 2014 and in www.gpdp.it, doc. Web doc. No. 3134436 (hereinafter "Transparency Guidelines");

SEEN Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Journal No. 106 of May 8, 2019 and at www.gpdp.it, Web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

SEEN the documentation in the file;

SEEN the observations made by the Secretary General pursuant to Article 15 of Regulation No. 1/2000 on the organization and functioning of the Office of the Italian Data Protection Authority, at www.gpdp.it, Web doc. No. 1098801;

Rapporteur: Attorney Guido Scorza;

WHEREAS

1. Introduction

This Authority has opened an investigation against the Municipality of XX in reference to the complaint filed by former municipal councilor XX (hereinafter the "complainant").

Specifically, the complainant stated that he had been a municipal councilor and had resigned from his institutional office, but that, despite this, his personal data, including his CV, were still being published online on the aforementioned Municipality's institutional website.

The preliminary investigation conducted by this Department revealed that the complainant's personal data, including the following documents, can be viewed in the "Transparent Administration" section of the Municipality's institutional website homepage, under "Organization"/"Holders of Political, Administrative, Management, or Government Offices"/"City Council":

1) CV available at the URL:

https://...

2) Declaration of the absence of reasons for the complainant's ineligibility and incompatibility with the office of local administrator, containing personal data, including name, date and place of birth, residence, domicile, and handwritten signature, available at the URL:

3) https://...

The complainant stated that, before filing the complaint with the Guarantor, he exercised his rights regarding the protection of personal data for himself and the other resigning councilors, by submitting a specific request to the Municipality, requesting the deletion of the data.

Furthermore, during the investigation, the "Privacy Policy" section on the home page of the institutional website was checked, with particular reference to the details of the "Data Protection Officer," who appears to be XX, i.e., a different individual from the one communicated by the Municipality to the Guarantor with note prot. no. XX of XX – pursuant to Article 37, paragraph 7, of the GDPR – via the dedicated web procedure on this Authority's website.

2. Personal data protection legislation

Pursuant to the relevant legislation, "personal data" is "any information relating to an identified or identifiable natural person ('data subject')" and "an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person" (Article 4, paragraph 1, no. 1, of the GDPR).

With specific reference to the case brought to the attention of this Authority, it is recalled that public bodies, such as the Municipality, may disclose "personal data" in the cases provided for by Article 4, paragraph 1, of the GDPR. 2-ter, paragraphs 1 and 3, of the Code, in compliance – in any case – with data protection principles, including the principle of "minimization," according to which personal data must be "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letter c, of the GDPR).

Since 2014, the Garante has provided specific guidance to public administrations on the precautions to be taken for the dissemination of personal data online with General Provision No. 243 of May 15, 2014, containing the "Guidelines on the processing of personal data, including those contained in administrative records and documents, carried out for advertising and transparency purposes on the web by public bodies and other obligated entities," published in the Official Journal No. 134 of June 12, 2014 and in www.gpdp.it, web doc. No. 3134436 (currently being updated, but still substantially current).

Furthermore, with regard to the obligations regarding the designation of the Data Protection Officer (DPO), European data protection legislation requires the "controller or processor shall publish the contact details of the DPO and communicate them to the supervisory authority" (Article 37, paragraph 7, GDPR). This communication must be made following the specific procedure indicated on the Garante's institutional website at https://servizi.gpdp.it/comunicazionerpd/s/.

3. Preliminary assessments by the Office of the processing of personal data carried out.

From the documents in the file, it emerged that the complainant was elected as a municipal councilor on XX and that he resigned from his position on XX.

Regarding the online dissemination of personal data contested by the complainant, the Municipality of XX, with note prot. no. XX of XX, responded to the Office's request for information and justified its conduct by citing the need to comply with the online publication obligations regarding transparency set forth in Article 14 of Legislative Decree No. 33/2013.

In this regard, however, with note prot. No. XX of XX, the Office informed the Municipality that, pursuant to the aforementioned state transparency regulations, public administrations are required to publish – with reference to municipal councilors as holders of political offices – the documents indicated in Article 14, paragraph 1, of Legislative Decree No. 33/2013 and to maintain them online for a period of "three years following the termination of the mandate or assignment of the individuals [...]" even if they resign (see ANAC FAQ No. 5.13 regarding transparency regarding the application of Legislative Decree No. 33/2013).

However, the Office pointed out to the Municipality that the documents required to be published pursuant to the aforementioned legislation include the councilor's curriculum vitae, but not the declaration of the absence of causes for ineligibility and incompatibility. This declaration was published online in full, with in any case excessive information, such as the councilor's residence, domicile, and handwritten signature.

Therefore, from the investigations conducted based on the information acquired and the facts emerging from the preliminary investigation, as well as subsequent assessments, the Office, with the aforementioned memorandum no. XX, determined that the Municipality of XX—by disseminating the personal data and information contained in the declaration of the absence of grounds for ineligibility and incompatibility submitted at the time by the complainant in his capacity as a municipal councilor, and by failing to communicate the change in the DPO's data to the Guarantor—had engaged in conduct that did not comply with the relevant provisions on the protection of personal data contained in the GDPR. Therefore, with the same memorandum, the violations committed were notified to the Municipality (pursuant to Article 166, paragraph 5, of the Code), communicating the initiation of the procedure for the adoption of the measures referred to in Article 58, paragraph 1, of the GDPR. 2 of the GDPR and inviting the entity to submit written defenses or documents to the Guarantor and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of 24/11/1981).

4. Defense briefs.

The Municipality of XX, with note prot. No. XX of XX, sent the Guarantor its defense briefs in relation to the reported violations.

In this regard, it is recalled that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Guarantor, falsely declares or certifies information or circumstances or produces false documents or records is liable pursuant to Article 168 of the Code, entitled "False statements to the Guarantor and interruption of the performance of the duties or exercise of the powers of the Guarantor."

Specifically, regarding the contested publication of the declaration declaring the absence of grounds for ineligibility and incompatibility of the complaining councilor, the administration highlighted, among other things, that:

- "pursuant to Article 20, paragraphs 1 and 2, of Legislative Decree 39/2013, elected municipal councilors, upon being appointed, must submit a declaration declaring the absence of any of the grounds for ineligibility or incompatibility set forth in the same decree. The same provision (Article 20, Legislative Decree 39/2013), in the third paragraph, specifies that the aforementioned declarations must be published on the website of the public administration that appointed them."

- "In this regard, the ANAC reiterated that 'the administrations and entities to which the declaration is made, pursuant to Article 20, paragraph 3, of Legislative Decree No. 39/2013, are required to publish it in the "Transparent Administration" section of the institutional website. The declaration [...] must be available for consultation through a link on the website of the administration or entity that assigned the assignment.'"

- "Therefore, from the above, there is an obligation to publish on the administration's website the declaration of ineligibility and incompatibility with respect to holding public administration positions, including, obviously, that of municipal councilor. Therefore, the publication of the [complainant's] declaration of incompatibility is certainly legitimate."

- "Regarding the failure to timely communicate the change in the contact details of the Data Protection Officer (DPO), it was added that [...] On this point, in reality, one can only admit the omission, caused simply by human error. It is important to note, however, that following the Guarantor's discovery of the failure to communicate the change in contact details of the DPO designated by the Municipality, the latter promptly took action. Indeed, as early as XX, the administration had been providing the aforementioned communication through the website of the Italian Data Protection Authority.

- "The failure to communicate the contact details of the Data Protection Officer, in any case, did not negatively impact the Authority's ability to contact the DPO easily and directly."

- "With regard to the alleged dissemination of personal data online [...], it is reiterated that the Municipality of XX has deleted the document entitled "XX Incompatibility Declaration."

- "The municipal administration will organize a training course on personal data protection to be submitted to those responsible for managing the "Transparent Administration" section of the website and to its employees, also with the aim of raising awareness on the issue and avoiding future errors."

5. Assessments by the Guarantor

The issue at issue in the case submitted to the Guarantor concerns the dissemination of personal data and information contained in the declaration of the absence of grounds for ineligibility and incompatibility, submitted at the time by the complainant in his capacity as a municipal councilor, which was published online.

The aforementioned declaration clearly stated, in addition to the councilor's name, his date and place of birth, his residential and domicile address, and his handwritten signature.

The Municipality justified its conduct by citing the need to apply Article 20 of Legislative Decree No. 39 of April 8, 2013, which requires the publication on the public administration's website of declarations of the absence of grounds for ineligibility or incompatibility set forth in the aforementioned decree (paragraphs 1-3).

The reconstruction offered by the Authority clarifies some aspects of the issue and is certainly useful for assessing the conduct, but it does not appear adequate to overcome the critical observations raised by the Office. In this regard, it should be noted that Article 20 of Legislative Decree No. 39/2013, cited by the Municipality to justify the disclosure of the former councilor's personal data, is not applicable to the case at hand.

This is because the publication obligations therein apply only to the declarations required by individuals appointed to hold administrative, managerial, top-level, and executive positions listed in Legislative Decree No. 39/2013, which do not include municipal councilors.

This interpretation is confirmed by the ANAC, which noted that "the purpose of Legislative Decree No. 39/2013 is to protect the independence of administrative offices from undue influence from politics or private interests, and therefore the legislation identifies situations of incompatibility/ineligibility for administrative positions only." In no way can the legislative text in question imply consequences for the forfeiture of political office, which cannot be challenged by virtue of the aforementioned provisions" (Resolution No. 1007 of 23/10/2019, at https://www.anticorruzione.it/-/delibera-numero-1007-del-23-ottobre-2019).

For this reason, we believe that Article 20 of Legislative Decree No. 39/2013 – contrary to what the Municipality claims – cannot constitute an adequate legal basis to justify the online dissemination of the complainant's personal data contained in the declaration of the absence of grounds for ineligibility and incompatibility, as it does not satisfy any of the lawfulness requirements set forth in Article 2-ter of the Code. Furthermore, the provision of additional information regarding the date and place of birth, the address of residence and domicile, as well as the handwritten signature of the then municipal councilor, is contrary to the principle of data minimization, as the data is excessive and not "limited to what is necessary in relation to the purposes for which it is processed" (Article 5, paragraph 1, letter c, GDPR).

Regarding the further issue, which arose during the investigation, regarding the indication in the privacy notice on the home page of the institutional website of the Municipality of XX of a Data Protection Officer (DPO) other than the one communicated to the Italian Data Protection Authority – pursuant to Article 37, paragraph 7, of the GDPR – with note no. XX of XX, the municipality admitted "the failure to timely communicate the change in the contact details of the DPO" to this Authority. However, in this regard, it was stated that this conduct was "trivially caused by human error" and that the situation was remedied by properly notifying the Guarantor, which was indeed done and recorded under file no. XX of XX.

6. Outcome of the investigation into the complaint

The circumstances highlighted in the defense briefs of the Municipality of XX, examined as a whole, although certainly worthy of consideration for the purposes of assessing the conduct, are not sufficient to allow the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Guarantor Regulation no. 1/2019, as none of the cases envisaged in Article 11 referred to therein apply.

In this context, the Office's preliminary assessments are confirmed in note file no. XX of XX, and it is found that the conduct of the Municipality of XX did not comply with the relevant regulations regarding the protection of personal data, as the aforementioned Municipality

1. disclosed the complainant's personal data (name, date and place of birth, residence, domicile, and handwritten signature) contained in the document entitled "Declaration of Incompatibility," published online:

a) in the absence of an appropriate legal basis, in violation of the provisions of Article 2-ter, paragraphs 1 and 3, of the Code; Articles 7-bis, paragraph 3, and 14, paragraph 1, of Legislative Decree No. 33/2013; and Article 6, paragraph 1, letters c) and e), paragraph 2, and paragraph 3, letter b), of the GDPR;

b) in violation of the principle of data minimization, which is not "limited to what is necessary in relation to the purposes for which it is processed" (i.e., administrative transparency), as set forth in Article 5, paragraph 1, letter c), of the GDPR;

2. failed to promptly notify the Data Protection Authority (but only following a complaint from this Authority) of the change in the contact details of the Data Protection Officer (DPO) designated by the Municipality, in violation of Article 37, paragraph 7, of the GDPR.

However, it is believed that the particularity of this case must be considered, as it presents a series of circumstances that merit careful consideration. Specifically, the following:

- the Municipality of XX is a small entity with just over 400 inhabitants and an extremely small number of employees;

- the data controller, following the Office's request, intervened promptly, collaborating with the Authority during the investigation of this proceeding to remedy the violation and mitigate its potential negative effects;

- the conduct observed, in violation of personal data protection regulations – given the Municipality's statements – stems from the belief that the disputed documents must be published pursuant to Article 20 of Legislative Decree No. 39/2013 (according to a broad interpretation of the principle of transparency) and is therefore clearly negligent;

- In this case, the aforementioned conduct involved a small number of data subjects (the complainant and two other municipal councilors), whose shared data did not belong to special categories or to criminal convictions or offenses (Articles 9 and 10 of the GDPR);

- The data controller declared that the conduct had ceased, removing the personal data contained in the declaration published online from the website and notifying the Authority of the change in the DPO's contact details;

- The response to the Authority also described certain technical and organizational measures implemented pursuant to Articles 25-32 of the GDPR;

- There are no previous relevant GDPR violations committed by the entity;

- In relation to the failure to notify the Authority of the update of the DPO's contact details—as indeed represented by the Municipality—it was nevertheless possible to contact the DPO easily and directly, as the data was correctly published on the institutional website.

The circumstances of this specific case therefore lead to the classification of this case as a "minor violation" pursuant to Article 148, Article 83(2) of the GDPR, and the "Guidelines on the application and provision of administrative pecuniary sanctions for the purposes of Regulation (EU) No. 2016/679," adopted by the Article 29 Working Party on October 3, 2017, WP 253, and endorsed by the European Data Protection Board with "Endorsement 1/2018" of May 25, 2018.

In light of all of the above, and the overall circumstances of the case at hand, rather than imposing a pecuniary sanction, it is deemed sufficient to warn the data controller for the violation of the above provisions, pursuant to Article 58(2)(a) of the GDPR. b) of the GDPR (see also recital 148 of the GDPR).

Finally, it is believed that the conditions set forth in Article 17 of the Regulation of the Italian Data Protection Authority no. 1/2019 are met.

NOW THAT THE ABOVE STATEMENT IS BASED, THE GUARANTOR

having noted the unlawfulness of the conduct and processing carried out by the Municipality of XX, represented by its legal representative pro tempore, with registered office in XX – within the time limits indicated in the grounds pursuant to Articles 58, paragraph 2, letter b) of the GDPR

WARNS

the Municipality of XX for violating Articles 5, paragraph 1, letter c); 6, paragraph 1, letters c) and e); paragraph 2 and paragraph 3, letter b); 37, paragraph 7, of the GDPR, as well as Article 2-ter, paragraphs 1 and 3, of the Code

ORDERS

that violations and measures adopted pursuant to Article 58, paragraph 2, of the GDPR be recorded in the Authority's internal register with this provision, as required by Article 17 of the Garante's Regulation No. 1/2019.

Pursuant to Article 78 of the GDPR, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, June 23, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Scorza

THE ACTING SECRETARY GENERAL
Filippi