Garante per la protezione dei dati personali (Italy) - 10185463

From GDPRhub
Garante per la protezione dei dati personali - 10185463
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(1)(a) GDPR
Article 6(1)(c) GDPR
Article 6(1)(e) GDPR
Article 6(2) GDPR
Article 6(3) GDPR
Article 12(1) GDPR
Article 13 GDPR
Article 21(4) GDPR
Article 26 GDPR
Article 35 GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 25.09.2025
Published: 25.09.2025
Fine: 32,000 EUR
Parties: Autonomous Province of Bolzano/Bozen
National Case Number/Name: 10185463
European Case Law Identifier: n/a
Appeal: Not appealed
Original Language(s): Italian
Original Source: GDPD (in IT)
Initial Contributor: lde

The DPA fined the Province of Bolzano €32,000 for unlawfully operating a network of cameras monitoring traffic flows. The province had no valid legal basis for the involved processing of personal data, in particular license plates.

English Summary

Facts

In 2019, the Province of Bolzano (the controller) installed a network of 124 cameras aimed at analysing traffic flows as a basis for mobility and infrastructure policies in a UNESCO protected area.

These cameras automatically read license plates, and also collected a series of metadata, including an identifier of the camera, date, time, class of the vehicle, its nationality, KEMLER identifier if present (relates to dangerous goods), and speed of transit. The license number immediately went through a double pseudonymisation process, with the license number being deleted within 60 seconds of its acquisition. The metadata on the other hand was stored for 2 years.

The processor, which was the company providing the technology, was the only entity with access to the raw data and to the algorithm used. The controller only had access to the final aggregated data.

The Province stated that the level of pseudonymisation in use means that they were not dealing with data that could be classified as personal data anymore.

The DPA came across the facts through news outlets, and opened an investigation ex-officio.

Holding

The Italian DPA held first of all that license plates are to be classified as personal data, even if pseudonymised. In fact, anyone could connect them to a natural person by consulting the public vehicle registry. It is irrelevant that this is not the intention of the controller.

Referring to the pseudonymisation process put in place by the controller, the DPA pointed out that pseudonymised data is still considered personal data, as they could still be attributable to a natural person when read in conjunction with supplementary information. For example, the stored metadata could be used in this regard. It is also irrelevant that the license number is only stored for 60 seconds, as the duration of processing has no influence on the assessment of its lawfulness.

The province, through its processor, was thus processing personal data and needs to comply with GDPR obligations.

The controller failed to provide a valid legal basis for the processing. In its defence, the Province invoked Article 6 GDPR(1)(c) and (e) GDPR as legal bases, i.e. legal obligations and public interest. In particular, the processing of personal data was necessary to fulfil the objective of ensuring safety in the Dolomites mountain passes, which the Province has been tasked with through a 2019 administrative act. Additionally, other national laws give the Province full autonomy over landscape and environmental matters.

However, the DPA held that the controller has failed to provide a sufficiently specific national legal act that could be a suitable legal basis, as the texts mentioned do not define the categories of data, storage periods, the operations and procedures of the processing, and measures to guarantee lawfulness and correctness. In any case, the controller failed to demonstrate how the measures put in place pass the test of necessity and proportionality.

In light of this, the Italian DPA found the Province in breach of the principle of lawfulness, fairness and transparency under Article 5(1)(a) GDPR, and in breach of Article 6(1)(c)(e), 6(2), and 6(3) GDPR.

Following from the controllers failure to characterise the information at hand as personal data the DPA further found additional violations of Article 12(1) GDPR, Article 13 GDPR, Article 21(4) GDPR, Article 26 GDPR, and Article 35 GDPR.

Finally, the DPA imposed a fine of €32,000 on the controller.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10185463]

Measure of September 25, 2025

Register of Measures
no. 531 of September 25, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Councillor Angelo Fanizza, Secretary General;

CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

CONSIDERING the documentation in the file;

CONSIDERING the observations made by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

RAPPORTEUR: Attorney Guido Scorza;

WHEREAS

1. Introduction.

The Authority has learned from press reports of the signing of a memorandum of understanding between the Autonomous Province of Bolzano - Alto Adige (hereinafter, the "Province"), Municipalities, the Government Commissioner's Office, the Police Headquarters, and the Police Forces. The purpose of the memorandum is to install a network of one hundred and twenty-four cameras across the Province, equipped with automated license plate reading capabilities for vehicles in transit. This network will be used to analyze traffic flows, aimed at guiding mobility and infrastructure policies, and to prevent and detect crimes.

2. The preliminary investigation.

During the investigation initiated on the basis of the aforementioned press reports, the Authority addressed several requests for information to the Province (see notes prot. nos. XX of XX; XX of XX; no. XX of XX; XX of XX). The Province, in responding to these requests (see notes prot. nos. XX of XX; XX of XX; XX of XX), stated, in particular, that:

"[…] the project […] falls within the institutional objectives of the Provincial Administration as set forth in Articles 13, paragraph 7, and 227 of the "New Highway Code," by Presidential Decree no. 381 of March 22, 1974, […] as well as by Provincial Council Resolution no. 683 of 06/08/2019 […]”;

“The project [consists in] detecting traffic flows in South Tyrol through license plate reading […]”;

“[…] the […] cameras placed along the road network read vehicle license plates and do not save photos […]”;

“[…] the statistical and aggregated data are used to plan a series of traffic-related measures, including with a view to environmental and economic protection of the Dolomites-UNESCO area and subsequent sensitive areas that have been gradually added to the project”;

“The cameras were installed and activated [as follows]: from XX (24 cameras); from XX (7 cameras); from XX (8 cameras); from XX (60 cameras); from XX (12 cameras); from XX (13 cameras)”.

“The second-level information was made available to interested parties at the Technical Offices of the Road Service Department of the Autonomous Province of Bolzano starting from XX”;

“[…] a revision of the text was therefore carried out, resulting in a second updated version, dated XX, made available at the same offices”;

“This version was also made available on XX both at the offices and online at the link https://www.provincia.bz.it/turismo-mobilita/strade/manutenzione/monitoraggio-del-traffico.asp, on the institutional website of the Road Service of the Autonomous Province of Bolzano”;

“The current signs containing the first-level information were installed between XX and the first XX, replacing the previous signs […]”;

“[…] the Province's interventions must be justified and must ensure that discriminatory or unreasonable applications are avoided, which necessarily requires the collection of data on traffic flows that are as objective and accurate as possible, and therefore, necessarily, a preliminary phase of monitoring them, since a choice cannot be justified without objective data”;

“the activity in question is expressly contemplated in a primary regulation […, namely] art. 19 of Presidential Decree no. 22 March 1974. 381 […]”;

“license plate numbers and other metadata associated with each license plate […] are never […] disclosed to the Province […]; the cameras are protected by a password known only to the data controller (supplier company) and not to the data controller (Province) […]”;

“the Province […] has access […] only to the final set of progressive numbers associated with traffic flows of origin and destination”;

“the entire process […] takes place entirely within the technological “shell” of the data controller, from which the Province maintains complete segregation”;

“[…] it must be excluded that the license plate constitutes, in the case under examination, personal data […, since it is not] cross-referenced with the database [of the] Automobile Club d’Italia […;] the data controller is not authorized to […] perform any type of matching between the processed data and other information”;

“[…] these license plate numbers constitute [in any case] data anonymous for the Administration and pseudonymized data for the data controller […]”;

the Province “does not have any decryption key”.

“The aggregate processing is […] achieved by associating data sets with a hash string, and no longer with a license plate number”;

- “[…] the system has been configured to create reports for up to 2 years [… to] allow […] to have concrete data for planning road network interventions that allow for the effective management and optimization […] of traffic flows […]”;

- “The video devices are also located within the Autonomous Province of Trento [hereinafter, the “Province of Trento”], by virtue of the [signature of an] agreement”;

- “The civil ownership of the first 24 video cameras, those covered by the aforementioned agreement, belongs to both Provinces”;

- The Province of Trento approved the aforementioned agreement with the minutes of the Provincial Council resolution reg. resolution. No. 1192 of August 12, 2019;

- "the agreement […] is the only agreement" signed between the two Provinces;

- "[…] the placement of the cameras; their selection; the selection of the data to be acquired through them; the choice of supplier […]; The logic to be applied to the data in order to obtain the traffic O/D matrices and determine the traffic type (tourist, through traffic, residential, commuter) was determined by the Autonomous Province of Bolzano.

- "The Province of Trento intervened only on an economic level, does not have any direct contact with [the Authority], but has the right to request aggregate output data directly from the Autonomous Province of Bolzano."

In light of the statements made by the Province, the Authority involved the company providing the technological solution (hereinafter, the "Agency") in the investigation, as data controller, by submitting a request for information (see note prot. no. XX of XX). The Agency, in a note dated XX, stated, in particular, that:

- "[…] the set of data collected by the cameras [is as follows:] the camera identifier (code assigned to the individual camera), date, hour, minute, and second of the vehicle's passage under the camera, the vehicle class, its nationality (if applicable), any KEMLER codes (dangerous goods), and, if applicable, the transit speed”;

- “the […] Company does not query the Public Vehicle Register (P.R.A.) […, since] the activity performed is in no way aimed at identifying natural persons”;

- “the clear license plate is deleted within 60 seconds of receipt. A first salted hash string is created from it (first level of protection), which is in turn deleted within 60 seconds of conversion after the creation of a second salted hash string (second level of protection)”;

- “both hash functions, described above, use the SHA256 function. The salt values used do not vary over time. Based on an algorithm and depending on the license plate's alphanumeric code, one of the over 200 different salts present in the system is used. Only the sub-controller, the only person able to access the databases, is aware of the algorithm and the over 200 different salts used before the two hash encryption functions. The algorithm is unidirectional and depends on the incoming license plate. After applying the first salt and SHA256 function to the license plate, it will be impossible, even for the sub-controller, to trace the license plate from the hash code (first-level protection). Nevertheless, a second salt and SHA256 function are applied, obtaining a further new hash code (second-level protection). Only this last hash code will be saved in the database. The incoming license plate and the hash code (first-level protection) are not stored.

With note dated XX (ref. no. XX), the Office, based on the information acquired, the investigations conducted, and the facts emerging from the preliminary investigation, notified the Province, pursuant to Article 166, paragraph 5, of the Code, of the initiation of proceedings for the adoption of the provisions referred to in Article 58, paragraph 2, of the Regulation, for the Province's processing of personal data in violation of Articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulation, as well as Article 2-ter of the Code. With the same note, the aforementioned owner was invited to submit written defenses or documents to the Guarantor or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

With note dated XX (ref. No. XX), the Province submitted a defense brief, setting out the defense arguments in detail, which are illustrated and considered in paragraph 3 below. The Province did not exercise its right to request a hearing before the Authority pursuant to Article 166, paragraph 6, of the Code.

3. Outcome of the investigation.

3.1. On the alleged failure to comply with procedural deadlines.

In its defence brief, the Province objected that there was "widespread non-compliance with peremptory deadlines", as the Authority had not observed the "120-day deadline from the ascertainment of the violation", as per "Table B, point 2) of the GPDP Regulation no. 2/2019 for notification", taking into account that "the procedure lasted over 16 months. Specifically: on XX the Authority initiated the administrative procedure against the Province by formulating some questions; on the following XX the Province provided a response; on XX a further request from the Guarantor followed; on XX a response from the Province was received; on XX the aforementioned 120-day deadline therefore expired; on the following XX, and even after 123 days from the last response (i.e. hypothetically making a new 120-day deadline start from XX), the Guarantor sent a new request for clarification; on XX, in a perspective Out of courtesy and full cooperation with the Authority, the Province nevertheless provided a timely response; at this point, 282 days had elapsed since that last response and over 400 days (including suspensions) from the initial deadline of XX, when on XX, the Authority sent the Province yet another request for clarification on issues it should have addressed by XX.

In this regard, some clarifications are needed regarding the procedural deadlines applicable to notifying the Province of the contested violations, as set forth in the Guarantor Regulation No. 2/2019.

Given that the administrative procedure in question is not subject to the 90-day deadline referred to in Law No. 689 of November 24, 1981, but rather to the 120-day deadline specifically identified, pursuant to Article 154, paragraph 3, and Article 166, paragraph 9 of the Code, by the aforementioned Guarantor Regulation No. 2/2019, it is noted that this term runs "from the date of ascertainment of the violation" (see Table B, Part 2) of the Guarantor Regulation No. 2/2019) and that the date of ascertainment is to be identified when both the collection of the investigative evidence and its evaluation by the proceeding administration have been completed (see, in this regard, Supreme Court of 8 August 2005, No. 16642; see also, Supreme Court, Civil Section II, No. 21114, No. 28 November 2012, and Supreme Court, Civil Section II, No. 8204, No. 8204, No. 8204).

With specific regard to the activity of independent administrative authorities, it is worth noting that the Supreme Court, in line with consolidated case law, has established that the activity of ascertaining the infringement, in relation to which the dies a quo of the deadline for the notification of the details of the infringement is placed, cannot coincide with the moment in which the fact is acquired in its materiality, but must be understood as including the time necessary for the evaluation of the data acquired and relating to the elements (objective and subjective) of the infringement and, therefore, of the final deliberation phase related to the complexity, in the specific case, of the investigations aimed at finding the existence of the infringement itself and acquiring full knowledge of the illicit conduct, so as to evaluate its consistency for the purposes of the correct formulation of the charge (see Cass. nos. 13050/2014, 1043/2015, 770/2017, 31635/2018 and 21500/2024).

Similarly, with specific reference to administrative offenses under the legislation on personal data protection, the Supreme Court recently reiterated that "the mere 'recognition' of facts does not in itself entail their 'verification', for the purposes of Article 166 [of the Code], where subsequent investigative and evaluative activity is necessary for the efficient implementation of the sanctioning process" (Civil Court, First Section, No. 18583/2025; see already, albeit with reference to the 90-day deadline provided for by Article 14 of Law 689/1981, Civil Court, Second Section, No. 18288/2020).

On this point, it should also be noted that, as noted by Supreme Court case law, in the event of multiple, interconnected violations, "the appropriateness of the overall time spent" by the proceeding administration to ascertain the aforementioned violations is to be understood as strictly connected "to the complexity of the investigation" undertaken by the same (see Supreme Court, First Civil Section, April 4, 2018, no. 8326).

It is also important to note that the aforementioned 120-day deadline "is suspended from August 1 to 31 of each year and resumes running from the end of the suspension period" (see Article 6, paragraph 1 of the Guarantor Regulation no. 2/2019).

In light of the above clarifications regarding the procedural deadlines applicable to this case, as provided for by current legislation, it must be considered that the notification of the disputed violations to the Province, issued by the Office in a note dated 20th December, was not untimely, especially considering the highly complex nature of the case at issue in this administrative proceeding. This required investigations involving not only the Province but also the supplier company and the Province of Trento, thus acquiring essential investigative evidence for the purposes of defining the overall investigative framework.

In any case, with regard to compliance with the aforementioned 120-day deadline, starting "from the ascertainment of the violation", and within which the "communication of the alleged violations (Article 166, paragraph 5, of the Code)" must be carried out (see Table B, no. 2, of the aforementioned Regulation of the Guarantor no. 2/2019), it must be noted that - regardless of any assessment regarding the actual peremptory nature of this deadline in light of the most recent case law of the Court of Justice of the European Union (see judgment C-510/23, Trenitalia, of 30 January 2025) - in this case said deadline was in any case fully respected. The Province's response to the Office's last request for information (see note of XX, file no. XX) was, in fact, included in the Authority's protocol of XX (no. XX), and therefore, the administrative violation charge of XX was notified to the Province within a timeframe of just 25 days. Only in light of this last response, which specifically concerned the reconstruction of the subjective role of the Province and the Province of Trento in the context of the processing in question, could the overall investigation initiated against the Province be considered concluded and finalized, with the consequent "confirmation of the violation."

Regarding the aforementioned case law, according to which the Authority is required to comply with the aforementioned 120-day deadline, including for the purposes of sending multiple requests for information to the parties involved in the proceedings, aimed at clarifying or supplementing the preliminary information already acquired, it should be noted—without commenting on this case law here—that, in this case, contrary to the Province's assertions in its defense brief, all requests for information formulated during the preliminary investigation complied with this deadline, which is allegedly binding on the supervisory authority. Indeed, the first request for information of XX was responded to with a note of XX, entered into the Authority's records on the same date; the second request for information of XX was therefore submitted within 20 days of the Province's response; the third request for information was made on XX, or within 120 days of the date on which the note of XX was received in the Authority's protocol - no. XX of XX - with which the Province responded to the second request for information; the fourth request for information was made to the Company, with the Province in copy for its information, on XX, or within 118 days of the date on which the note of the same date with which the Province responded to the third request for information was received in the Authority's protocol - no. XX of XX; the fifth request for information was made to the Province on XX, or, taking into account the holiday suspension period from XX to XX, within 113 days of the date on which the note of XX was received in the Authority's protocol - no. XX of XX - with which the Company responded to the fourth request for information. This is without prejudice to the fact that the time of ascertainment of the violation cannot formally coincide with the date on which a certain document was acquired by the Authority. The Office must always carry out an in-depth assessment and investigation aimed at effectively "ascertaining the violation," taking into account all the investigative elements acquired from the various requests for information, especially in the context of complex investigations, including technological ones, which involve various parties, such as the one in question.

3.2. The processing of personal data carried out by the Province and the nature of the personal data collected.

It is established that the Province, starting from the month of XX, has installed 124 cameras in the area affected by the project, equipped with automatic license plate recognition capabilities for vehicles in transit. Specifically, the installation of these video devices was carried out according to the following schedule: from XX, 24 cameras; from XX, an additional 7 cameras; from XX, an additional 8 cameras; from XX, an additional 60 cameras; from XX, an additional 12 cameras; from XX, an additional 13 cameras. These devices are capable of extracting information regarding the class of vehicles in transit (motorcycle, car, bus, van, heavy vehicle, other), their nationality, speed rating (if applicable), KEMLER code (if applicable), as well as the origin and destination of the journey. This allows us to understand and analyze traffic flows within the Dolomites-UNESCO area and to make administrative decisions consistent with the actual characteristics of traffic flows in that area.

The license plate data of vehicles in transit is initially collected in plain text and stored for a maximum of 60 seconds, before being further processed.

With regard to this first processing phase, it should be noted that license plate numbers are undoubtedly to be considered "personal data" relating to the owners and users of the vehicles associated with them, as they are information relating to identifiable natural persons (Article 4, paragraph 1, no. 1) of the Regulation), also due to the possibility for anyone to consult the public vehicle register (PRA). This is also confirmed by the case law of the Court of Cassation, which has stated that "there is no doubt that the information in question—the license plate of a motor vehicle, as it refers to an identified or identifiable individual—must be considered 'personal data.'" This was the case under Article 4, letter b), of Legislative Decree No. 196/2003 […] [and] it still is, pursuant to Regulation (EU) 2016/679" (Civil Court, First Section, Order of December 18, 2023, No. 35256; see also Civil Court, First Section, Order of July 7, 2021, No. 19270, which states that "particularly important are data that allow […] indirect identification, such as an identification number (for example, […] the license plate number)".

In this regard, As argued by the Province in its defense brief, that no queries are actually carried out by the PRA or that there is no specific interest on the part of the Province or the Company in carrying out such queries, as the project is not aimed at identifying specific natural persons and initiating administrative proceedings against them. The classification of information relating to a natural person as personal data and the recognition of the data subject's right to the protection guaranteed by European data protection legislation is, in fact, independent of the animus of the data controller and his actual will to acquire or not the additional information necessary for the identification of the data subjects, with the only relevant factor being the abstract existence of "means [...] which the data controller or a third party may reasonably use to identify [a] natural person directly or indirectly" (recital 26 of the Regulation). In fact, a different interpretation would result in data subjects being provided or not provided with protection on a case-by-case basis with regard to the processing of their personal data based on a circumstance, or the mere intention, only declared by the data controller. The data controller may decide whether or not to proceed with the identification of the data subject, which would not be objectively verifiable. Furthermore, regardless of the controller's intentions and as highlighted in the aforementioned Article 26 of the Regulation, the identification of a natural person may also be carried out by interested third parties, whether in the context of completely lawful activities (e.g., requests for data acquisition by law enforcement or judicial authorities in the context of criminal investigations) or unlawful activities (e.g., cybercriminal attacks), using the means reasonably available to them to achieve the identification of the data subjects, which, in this case, consisting of public registers, are readily available.

Having clarified this, it is noted that the investigation also revealed that the license plate number of each vehicle in transit is converted, after applying a salt (selected deterministically, including based on the license plate number itself, from among over 200 different salts present in the system), into an initial hash value, calculated using the hashing function. SHA-256. Upon completion of this conversion, which occurs within 60 seconds of transit, the license plate number is deleted. The first hash value thus obtained is then converted, after applying a salt, into a second hash value, calculated using the SHA-256 hashing function. Upon completion of this second processing, which occurs within a further 60 seconds, the first hash value is deleted. A sequential number is then associated with the second hash value. The association between the second hash value and the sequential number, which both constitute unique vehicle identifiers, is stored in a first database; the data relating to the vehicle's transit (sequential number, speed and any KEMLER code of the vehicle, date and time of transit, video device identifier) are stored in a second database and retained for two years.

Contrary to what the Province claimed during the investigation, these operations only result in the pseudonymization of information relating to vehicles in transit. trace them back to them, thus maintaining their personal nature. Pseudonymization is, in fact, a measure that can be adopted to ensure data minimization, selective access to information, in accordance with the principles of privacy by design and by default, as well as a level of security appropriate to the risk, which, however, does not affect the personal nature of the information subjected to it (see Article 32, paragraph 1, letter a), of the Regulation). The cons. 26 of the Regulation clarifies, in fact, that “personal data subjected to pseudonymisation, which could be attributed to a natural person through the use of additional information, should be considered as information on an identifiable natural person” (see, among others, the “Guidelines 1/2022 on data subjects' rights - Right of access”, adopted by the European Data Protection Board on XX, where it is highlighted that “personal data subjected to pseudonymisation are still personal data, unlike anonymised data”; see also the “Opinion 1/2017 on the proposal for a Regulation on privacy and electronic communications (2002/58/EC)” of 4 April 2017 - WP 247, with which the Art. 29 Working Party - now the European Data Protection Board -, albeit with reference to the so-called Mac Addresses and in a different context, clarified that “MAC addresses are personal data and remain so even after the adoption of measures security measures such as hashing”).

The Court of Justice of the European Union itself has stated that “it follows from Article 4(5) of the GDPR, in conjunction with Recital 26 of that regulation, that personal data that have only been pseudonymized and that could be attributed to a natural person through the use of additional information must be considered as information on an identifiable natural person, to which the principles relating to data protection apply” (Case C-683/21, National Visual Rights Council, 5 December 2023, paras. 57 and 58).

Nor is it relevant that the entire pseudonymization process, using hash functions, is carried out not directly by the Province but by its own supplier, who acts, in any case, on its behalf as data controller, even though the Province does not directly have the additional information necessary to attribute the data to specific data subjects (vehicle owners/drivers), gaining knowledge exclusively of data on an aggregate basis. Indeed, it should be emphasized that the data controller, as the entity responsible for decisions regarding the purposes and methods of processing the data subjects' personal data, has "general responsibility" for the processing carried out (see Article 74 of the Regulation; see, among others, Decision No. 409 of 1 December 2022, web doc. No. 9833530 and the previous provisions referred to therein; see also the "Guidelines 07/2020 on the concepts of data controller and data processor under the [Regulation]", adopted by the European Data Protection Board on 7 July 2021, especially paragraph 174). Therefore, “such a data controller may be subject to an administrative fine pursuant to Article 83 of the [Regulation] in a situation where personal data are subject to unlawful processing and it is not such a data controller but a processor, used by it, which has carried out such processing on behalf of the controller”, it being irrelevant that “that entity has not itself carried out processing operations on such data”; therefore, it follows from “Article 4, point 7, of the GDPR […], read in the light of recital 74 of the GDPR, […] that an entity, where it satisfies the condition laid down in the said Article 4, point 7, is the controller not only of any processing of personal data which it carries out itself, but also of that carried out on its behalf” (Court of Justice of the European Union, judgment C-683/21, Nacionalinis visuomenės sveikatos centras, of 5 December 2023).

Equally irrelevant is the fact that the processing of unencrypted personal data, prior to the application of the hash function, occurs within a limited time frame of approximately sixty seconds. The duration of the processing is, in fact, irrelevant for the purposes of assessing its lawfulness, and even when the processing is extremely short, the data controller is not exempt from the obligation to ensure that there is an appropriate legal basis to justify it (see, most recently, provisions of January 11, 2024, No. 5, web doc. No. 9977020, and of April 13, 2023, Nos. 122 and 123, web doc. No. 9896412 and web doc. No. 9896808).

In this regard, in its defense brief, the Province argued that:

"The 'hash' [...] has specific mathematical characteristics, including irreversibility. That is, it is a one-way function; no one, not even [the Company], not even if they wanted to, is able to invert it, and this is due to objective mathematical impossibility."

"Since it cannot invert it, even if [the Company] retained the original license plates, rather than immediately deleting them (as it does), it would still be completely unable to identify, starting from a hash string, a specific license plate among those (hypothetically) retained. That is, having taken a hash string, it would have to recalculate all the hashes of the hypothetically retained license plates until it found one identical to the one sought, and keep track of the process along the way (i.e., create an association table)."

"But [the Company], by design, neither stores license plates nor tracks the process of generating each individual hash from a given license plate. Only if it stored license plates and a record of the process […] would the hash in question be a pseudonym within the meaning of Article 4.5) [of the Regulation], a provision that requires the separate storage of "additional information." In the absence of storage of the original data and a table associating them with the hashes, the latter are not, within the meaning of the Regulation, "pseudonyms," thus violating the definition in Article 4.5";

"[…] such additional information stored [by the Company] absolutely does not exist, nor does it result from the investigation, and it is clear that a hash, especially a salted one, cannot be submitted to the PRA for consultation, but only a license plate";

"That is, it happens that [the Company]: does not retain any association table between each license plate and each hash; it does not even retain the original license plates, but deletes them as soon as the hash conversion has taken place; that is, it does not have two databases to cross-reference (license plate database and hash database) nor even an association table; it only retains the hashes. Ultimately, therefore, [the Company] is unable, starting from the hashes alone, to reconstruct the original license plates and therefore consult the Public Vehicle Registry."

"[…] the salting process, in this case a double process, allows us to exclude even the theoretical hypothesis of attacks by third parties who illegally gained possession of the hashes, because the data would be completely unusable for them, a point which also demonstrates the quality of the security measures adopted."

"For the purposes of the definition of 'personal data,' two specific cumulative legal conditions are required: 1. the data subject must be specifically identifiable, pursuant to Recital 26 [of the Regulation]; 2. the data must be classified as information on a natural person. […] In this case, neither of these two conditions is met: that is, we have neither specifically identifiable individuals nor information about them."

"The Public Vehicle Register (PRA) cannot be queried by sending a hash. The license plate must be traced, but since it is a one-way function, this is mathematically impossible. Given a certain hash, it is not possible to identify the license plate, which eliminates the significant risk for the data subjects." It is only possible to create the hash from the license plate, not the other way around."

This means that if the Company wanted to expose the interested parties to risk, it would have to: 1. create a massive database of all Italian and foreign license plates in circulation; 2. store it (rather than delete the plates after 60 seconds); 3. recalculate a new hash database from this license plate database, creating (and saving) a license plate-hash association table during this process […]; 4. compare this second hash database with the first and, using the association table, connect the values of the first with the license plate database; 5. then conduct massive queries to the Public Vehicle Register (PRA), at prohibitive costs (millions of euros); 6. thereby violate the contract with the Autonomous Province; 7. decide to act for its own purposes, becoming the data controller, excluding the Province from liability; 8. all of this without any plausible reason.

"In the event, however, that the hashes are stolen by malicious third parties, the double salting step constitutes a mathematically insurmountable constraint, so there is no doubt that the third party would steal unusable data";

"Salted hashes [...] are therefore not covered by Article 4.1) [of the Regulation]."

This defense cannot be accepted. In order to detect the transit of a vehicle entering and exiting the area affected by the project, the system must generate identical identifiers (second hash value and associated progressive number) from the same license plate number, so that the data relating to the transits of that vehicle can be attributed to the same "traffic unit." Specifically, the first unique vehicle identifier (second hash value) is calculated from a vehicle's license plate number using hashing functions (and a limited, non-variable set of salts), which are considered weak pseudonymization techniques and vulnerable to brute-force attacks (see the document "Pseudonymization techniques and best practices" published in November 2019 by the European Union Agency for Cybersecurity - ENISA, especially section 5.1.3). The second unique vehicle identifier (sequential number), associated with the first unique identifier, is assigned upon the first transit and remains unchanged over time. In this context, it is possible, for example, to calculate the second hash value given a specific license plate number and verify its presence in the first database (indicative of the fact that the vehicle in question has made at least one transit through the territory covered by the project). If this hash value is present, it is then possible to retrieve the associated serial number and search the second database for the transit data associated with that serial number. Since the set of license plate numbers is limited (for example, in the numbering system currently used in Italy, there are approximately 75 million possible combinations of license plate numbers from AA001AA to GZ999ZZ, not all of which are valid or used), the aforementioned operations can be performed, using means reasonably available to anyone, not only on a single license plate number, but also on the entire set of license plate numbers. It is therefore technically and theoretically possible for the data controller or processor, as well as any third parties who for any reason become aware of the characteristics of the hashing functions used (and the set of salts applied) and information on the relationships between the two unique identifiers (second hash value and serial number), to associate the transit data with the license plate numbers of the vehicles that performed them.

In light of all the foregoing considerations, it is established that the Province, using a data controller, processed personal data relating to vehicles transiting the areas where the video devices in question were installed.

On the other hand, although the Province stated in its defense brief that "the provision of information pursuant to Article 13 [of the Regulation], the classification of the contract with [the Company] pursuant to Article 28 [of the Regulation], and the other activities compliant with the Regulation undertaken by the Autonomous Province are attributable solely to a prudential approach," no document in the case file suggests that the Authority implemented these measures solely as a precautionary measure. Instead, it can be deduced from this circumstance that the Province was unsure of its own determination regarding the non-attribution of the information collected to the definition of personal data, so much so that it nevertheless decided to fulfill some of the obligations set forth in the Regulation.

3.3. The lawfulness of the processing.

The processing of personal data through video devices by public bodies is generally permitted if it is necessary to comply with a legal obligation to which the data controller is subject or to perform a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 5, paragraph 1, letter a), Article 6, paragraphs 1, letter c) and e), Articles 2 and 3 of the Regulation, as well as Article 2-ter of the Code; see the "Guidelines 3/2019 on the processing of personal data through video devices," adopted by the European Data Protection Board on January 29, 2020, paragraph 41; see also the FAQs of the Italian Data Protection Authority on video surveillance, dated December 3, 2020, web doc. no. 9496574).

The data controller is required, in any case, to comply with data protection principles, including "lawfulness, fairness, and transparency" and "data minimization," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject," as well as "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c), of the Regulation).

During the investigation, the Province stated that the processing of personal data in question was necessary to "study and understand traffic flows, their dynamics, orientation, type (tourist, commuter, through traffic, residential), and frequency" and then "proceed to substantially reshape traffic flows in the Dolomite area" (note of the 20th). Currently, the video devices in question are not used for the prevention, investigation, detection, or prosecution of crimes.

Preliminary monitoring of traffic flows is necessary to adequately justify the Province's interventions in this area, which are to be adopted to achieve the objective of ensuring the safety of the Dolomite passes, protected by UNESCO, with respect to the massive road traffic flows that pass through them, as established by the Provincial Council resolution of August 6, 2019.

The activity in question is also necessary for the purposes of art. 19 of Presidential Decree No. 381 of March 22, 1974, pursuant to which, in exercising their landscape and other delegated functions, the Provinces, in agreement with each other and after consulting the Ministry responsible for infrastructure and mobility, may regulate measures to limit vehicular traffic along roads connecting their respective territories.

The Province also invoked Article 13, paragraph 7, and Article 227 of the "New Highway Code" as the basis for the processing of personal data in question.

In this regard, it should be noted that, as stated by the Court of Justice of the European Union, pursuant to Article 52, paragraph 1, first sentence, of the Charter of Fundamental Rights of the European Union ("CFREU"), any limitations on the exercise of the rights and freedoms recognized by the Charter—which include, in particular, the right to respect for private life, guaranteed by Article 13, paragraph 1, of the "CFREU"—cannot be considered unlawful. 7 of the Charter, and the right to the protection of personal data, enshrined in Article 8 of the Charter - must, in fact, be provided for by law, which implies, in particular, that the legal basis permitting the interference with these rights must itself define the scope of the limitation on the exercise of the right in question. In particular, "to satisfy the requirement of proportionality, which is expressed in Article 5(1)(c) of the Regulation […] the law on which the processing is based must provide clear and precise rules governing the scope and application of the [envisaged] measure and impose minimum requirements so that the individuals whose personal data are affected have sufficient guarantees to effectively protect their data against the risk of abuse. Such law must be legally binding within the national legal system and, in particular, indicate the circumstances and conditions under which a measure providing for the processing of such data may be adopted, thus ensuring that the interference is limited to what is strictly necessary" (judgment C-175/20, Valsts ieņēmumu dienests, 24 February 2022, para. 83).

In this regard, the Court has also held that legislation introducing a measure permitting such interference must provide clear and precise rules governing the scope and application of the measure in question and establishing minimum requirements, so that individuals whose personal data have been processed have sufficient guarantees to effectively protect that data against the risk of abuse (see C-175/20, cited above, para. 55; see Article 6(3) of the Regulation, as well as recital 45 thereof).

Furthermore, any limitations on the fundamental rights to respect for private life and the protection of personal data (and Articles 7 and 8 of the CFREU) "may be made, provided that, in accordance with Article 52(1) of the Charter, they are provided for by law" and "respect the essence of the fundamental rights as well as the principle of proportionality. Pursuant to this principle, limitations may be made only where they are necessary and genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others. They must apply only to the extent strictly necessary, and the legislation causing the interference must lay down clear and precise rules governing the scope and application of the measure in question" (C-184/20, Vyriausioji tarnybinės etikos komisija, 1 August 2022, para. 64).

Similar principles have also been affirmed by the European Court of Human Rights in relation to the admissibility of limitations to the right to respect for private and family life enshrined in Article 7 of the ECHR. 8 of the European Convention on Human Rights, even in cases where the interference concerns activities or conduct taking place in a public place (see Glukhin v. Russia, Application No. 11519/20, 4 July 2023, paras. 64, 75, and 77; Satakunnan Markkinapörssi Oy and Satamedia Oy v. Finland, Application No. 931/13, 27 June 2017, paras. 129-131; Peck v. United Kingdom, Application No. 44647/9, 28 January 2003, para. 59; Copland v. United Kingdom, Application No. 62617/00, 3 April 2007, para. 46).

In accordance with this legal framework and the case law of the two Courts, Article 6(2) and (3) of the Regulation specifies that the basis for the processing of data referred to in paragraph 1(c) and (e) must be established by Union law or the law of the Member State to which the controller is subject. Such law must determine the purpose of the processing and contain specific provisions to adapt the application of the provisions of the Regulation. It is understood that Union or Member State law must, in any case, pursue an objective of public interest and be proportionate to the legitimate aim pursued.

In implementing the provisions of Article 6(2) and (3) of the Regulation, the national legislator has specified that the legal basis provided for in Article 6(3)(e) is: 6(1)(b) of the Regulation, i.e., "the law of the Member State to which the data controller is subject" and on which "the processing of the data referred to in paragraph 1(c) and (e) [of Article 6 of the Regulation] is based," consists of "a law or regulation or general administrative act" (see Article 2-ter, paragraph 1, of the Code).

That said, with regard to the specific case, it is noted that the Province has not demonstrated the existence of a qualitatively adequate legal framework to justify the processing of the license plate numbers of vehicles in transit for the processing purposes envisaged.

In particular, it is noted that the Province referred, first and foremost, to Articles 13, paragraph 7, and 227 of Legislative Decree No. 285 of 30 April 1992 (New Highway Code), which, however, do not provide for the possibility of acquiring the license plate numbers of vehicles in transit and tracking the frequency of their passage and the routes taken by specific vehicles. Nor did the Province refer to specific "directives issued by the Ministry of the Environment and Land Protection, after consulting the Ministry of Infrastructure and Transport" which, for the purposes of these provisions, would cover the processing of personal data in question.

The Province also noted that the initiative in question is the subject of Provincial Council Resolution No. 683 of August 6, 2019, concerning "Approval of the draft agreement between the Province [...] of Trento and the Province [...] of Bolzano for the management of a structural monitoring system for vehicular traffic on the Dolomite passes," adopted pursuant to Article 19 of Presidential Decree No. 381 of March 22, 1974. This resolution concerns the "Approval of the draft agreement between the Province [...] of Trento and the Province [...] of Bolzano for the management of a structural monitoring system for vehicular traffic on the Dolomite passes." Through this agreement, the two Provinces, in order to “to adopt more suitable measures [than the scheduled access], [they intended to start] a process of systematic data collection for traffic monitoring through four Dolomite passes”. The aim “of this monitoring is to be able to build, for the entire season, an O/D matrix [, i.e. origin/destination,] on the vehicular traffic that currently travels through the Dolomite passes, through a system of cameras and the creation of specific software, associated with a related database, which will remain the property of the two Administrations, which will allow the classification into at least 4 categories of vehicles (motorcycles, cars, buses, other) and in different speed classes as well as the possibility of a possible homologation for sanctioning purposes”. The “structural monitoring project starting from the summer of 2019, consists of the installation and management of a system of 24 fixed cameras for a period of 8 years […]”. It is also stated that “the management of the monitoring system will be the responsibility of the Province of Bolzano, while the data flow will be accessible from both Provinces. The system will remain the property of the two administrations.

The law to which this resolution refers, namely Article 19 of Presidential Decree No. 381 of March 22, 1974, limits itself, however, to contemplating the possibility of "regulating measures to limit vehicular traffic along the roads connecting the respective territories." It provides a general requirement to justify such measures, but makes no specific reference to the need to track the routes taken by specific vehicles using license plate detection technologies.

In this context, neither Resolution No. 683 of the Provincial Council of Bolzano of August 6, 2019, nor the related Resolution No. 1192 of the Provincial Council of Trento of August 12, 2019, can be considered adequate in terms of the quality of the legal basis (see Article 6, paragraph 3, of the Regulation), given that they do not specifically regulate the types of data processed, the data retention periods, and the processing operations and procedures, including measures to ensure lawful and fair processing. In particular, the resolutions make no explicit reference to the collection and processing of license plate data and their retention for a period of two years in order to reconstruct vehicle routes. They merely make a generic reference to the creation of an "O/D [origin/destination] matrix for vehicle traffic currently traveling through the Dolomite passes." These aspects were, in fact, defined by the Province solely through internal organizational documents and within the contractual relationship with the data controller. Nor can the argument, put forward by the Province in its defense brief, be accepted, according to which the "[...] resolution of the Provincial Council [...] prescribes both the need to construct the O/D matrix (which requires the recognition of the same vehicle when passing through at least two different locations, therefore requiring the use of video cameras) and the need to classify vehicles (which, combined with the O/D matrix, requires the use of video cameras), as well as the different speed classes (which also requires video cameras)", given that, as highlighted above, legislation that interferes with the right to data protection must contain clear and precise provisions governing its scope and application, satisfying the quality requirements set out in the Regulation, thus making the processing predictable for data subjects. These requirements cannot be considered satisfied where, as the Province maintains, the processing can only be deduced from the overall wording of the provision on which it is based.

The Province, in its defense briefs, also stated that, in the unlikely event that personal data processing is deemed to exist, it must be considered that "the legal basis for the processing is that of Article 6.1.e) [of the Regulation], therefore, pursuant to Article 6.3, it is not necessary for the relevant provision to indicate the purpose, it being sufficient that it be 'necessary' for the task of public interest, nor, above all, that it indicate the categories of personal data and the other elements of the processing, as is clearly deduced from the use, in Article 6.3, of the verb "may" (or "could contain"), although in the conditional tense "may contain," etc. Similarly, Article 2-ter, paragraph 1-bis [of the Code] confirms the lawfulness of the processing."

In this regard, it should be noted that, as stated by the Court of Justice of the European Union, "the lawful processing of personal data […] on the basis of Article 6(1)(e) of the GDPR presupposes not only that [the controllers] can be regarded as carrying out a task carried out in the public interest, but also that the processing of personal data for the performance of such a task relies on a legal basis provided for in Article 6(3) of that regulation" (judgment of 20 October 2022, Koalitsia «Demokratichna Bulgaria – Obedinenie» - C‑306/21, paras. 48-52). In particular, the legal basis for the processing under Article 6(1)(e) of the GDPR is the processing of personal data pursuant to Article 6(1)(e). (e) of the Regulation, “in accordance with Article 6(3) of the GDPR, in conjunction with recital 45 thereof […] must be established by Union law or by the law of the Member State to which the controller is subject. Furthermore, Union law or Member State law must pursue an objective of public interest and be proportionate to the legitimate aim pursued. The combined provisions of Article 6(1)(e) of the GDPR and Article 6(3) of that Regulation therefore require a legal basis, in particular a national legal basis, for the processing of personal data by controllers acting in the performance of a task carried out in the public interest or in the exercise of official authority” (judgment of 2 March 2023, C-268/21 - Norra Stockholm Bygg, paras. 30-32; see also judgment of 30 March 2023, C-34/21 - Hauptpersonalrat der Lecturers and Teachers, paragraph 87). Therefore, in the absence of specific legal provisions (see Article 2-ter, paragraph 1, of the Code) that contemplate and regulate, with the necessary quality requirements, the processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the data controller cannot generically invoke the legal basis set out in Article 6, paragraph 1, letter e), of the Regulation (see Article 2-ter, paragraph 1, of the Code, which, while permitting processing "necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in them," nevertheless requires "compliance with Article 6 of the Regulation").

Having clarified this regarding the quality requirements of the legal basis, it should be noted that the processing of personal data may find its legal basis in Article 6, paragraph 1, letter e), of the Regulation. 1.1(e) of the Regulation if and to the extent that it is "necessary" for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. This condition must be examined in conjunction with the principle of data minimization enshrined in Article 6(1)(c) of the Regulation, according to which personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This is because, as highlighted above, in accordance with the aforementioned Article 52(1) of the Charter of Fundamental Rights of the European Union, the fundamental rights to respect for private life and to the protection of personal data, set out in Articles 7 and 8 of the Charter, may be subject to limitations only if they are provided for by law and respect the essence of the fundamental rights as well as the principle of proportionality, expressly referred to in Article 6(3) of the Regulation. By virtue of this principle, such limitations must be necessary and genuinely meet objectives of general interest recognized by the Union or the need to protect the rights and freedoms of others, operating only to the extent strictly necessary.

Therefore, in order to determine whether processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, it is necessary to verify in particular whether, in light of the seriousness of the interference with the fundamental rights to respect for private life and the protection of personal data caused by the processing, the latter is justified and, in particular, proportionate to the achievement of the objectives pursued. As highlighted by Council 39 of the Regulation, this requirement of necessity is not satisfied when the general interest objective in question can reasonably be achieved equally effectively by other means that are less prejudicial to the fundamental rights of the data subjects, in particular the rights to respect for private life and to the protection of personal rights guaranteed by Articles 7 and 8 of the Charter, given that derogations and restrictions to the principle of protection of such data must be limited to what is strictly necessary (see Court of Justice of the European Union, judgments C-184/20, Vyriausioji tarnybinės etikos komisija, of 1 August 2022, paras. 73, 82, 85, 93, 94, 98, 99; C-439/19, Latvijas Republikas Saeima, of 22 June 2021, paras. 99, 105, 106, and 113).

In this case, the documentation does not show that the Province carried out specific and preliminary assessments regarding the actual necessity of processing the personal data in question and its proportionality to the objective pursued (see Article 6, paragraph 3, of the Regulation). It is not theoretically possible to exclude that there were sufficiently effective tools and solutions, but less impactful on the rights and freedoms of the data subjects, to justify any traffic limitation measures adopted pursuant to the aforementioned Article 19 of Presidential Decree no. 22 March 1974. 381. On the other hand, as highlighted by the European Data Protection Board, albeit in a different context, "location data are particularly suited to providing insights into the lifestyle habits of data subjects. The journeys made have the particular characteristic of allowing the driver's place of work and residence, as well as his/her interests (leisure), to be traced" ("Guidelines 01/2020 on the processing of personal data in the context of connected vehicles and mobility-related applications", 9 March 2021, p. 17). Only in its defense brief did the Province, in fact, argue that "the reality is that there is no reliable alternative technical solution, one applied in response to the state of the art [...] Any other alternative solution (e.g. interviews with drivers; home investigations; telephone interviews; postal questionnaires; collaboration with telephone operators) is certainly inferior, since it would not only require an extraordinary search for personal data, subsequent massive processing, sometimes not even possible or even relevant, and in any case unjustified interference in the personal sphere, but it would also be prohibitively expensive", further stating that it would be "the burden of this Office [of the Guarantor] to prove otherwise". It should be remembered, however, that in accordance with the accountability principle (see Articles 5, paragraph 2, and 24 of the Regulation), which informs all European data protection legislation, the data controller must ensure, before starting the processing, compliance with data protection principles, including those of "data minimization" (Article 5, paragraph 1, letter c), of the Regulation, which, as mentioned, is reflected in the requirement of "necessity" for processing in the legal bases referred to in Article 6, paragraph 1, letters b) to e), of the same Regulation, and "be able to demonstrate this."

Finally, regarding the fact that, as stated, data relating to vehicles in transit may be processed broadly for "statistical analysis," it should be noted that, although this processing purpose has not been specifically invoked by the Province, there is no proven legal basis justifying such processing for statistical purposes. The Province has not cited any law, or, where required by law, any regulation, appropriate in terms of rank and quality, that expressly provides for such processing, regulating its essential characteristics, nor has it established the applicability of industry-specific ethical rules (see Articles 6, paragraph 1, letter a), and paragraphs 2 and 3, and 89 of the Regulation, as well as Articles 2-ter, 2-quater, paragraph 4, and Chapter III of the Code).

In light of all the foregoing considerations, it is established that the Province processed the personal data in question, relating to vehicles in transit, using video devices installed on public roads, in a manner inconsistent with the principles of lawfulness, fairness, and transparency, and in the absence of an appropriate legal basis, in violation of Articles 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, of the Regulation, as well as Article 2-ter of the Code.

3.4. The principle of storage limitation

Under the principle of "storage limitation," personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which they are processed (Article 5, paragraph 1, letter e), of the Regulation).
The Province has stated that it will retain pseudonymized personal data for a period of two years from the date of collection, as "it is possible to query the software to create reports based on historical data for up to two years."

This extremely long retention period cannot be considered proportionate to the purposes of the processing, given that, once the relevant characteristics of each vehicle in transit (class; speed class; origin and destination) have been identified and the relevant information acquired for the purposes of processing aggregated data, there is no reason to retain license plate data, even pseudonymized, for such a long period of time, exposing data subjects to a significant risk to their fundamental rights and freedoms, resulting from the fact that their movements across the territory can be systematically tracked and reconstructed.

Furthermore, there is no evidence in the documents that the data relating to the unique identifiers (second hash value and sequential number) of vehicles transiting the reference territory are also subject to deletion after this period. Their retention, even after deletion of information relating to individual transits, is sufficient to disclose the fact that at least one transit has occurred.

For these reasons, the Province acted inconsistently with the principle of "retention limitation," in violation of Article 5, paragraph 1, letter e), of the Regulation.

3.5. Transparency towards data subjects.

In accordance with the principles of "lawfulness, fairness, and transparency," the data controller must take appropriate measures to provide the data subject, prior to processing, with all the information required by the Regulation in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (Articles 5(1)(a), 12, and 13 of the Regulation).

When video devices are used, the data controller, in addition to providing first-level information by placing warning signs near the area subject to video surveillance, must also provide data subjects with "second-level information", which must "contain all the mandatory elements pursuant to Article 13 of the [Regulation]" and "be easily accessible to the data subject, for example through a complete information page made available in a central hub […] or posted in an easily accessible place" ("Guidelines 3/2019 on the processing of personal data through video devices" of the European Data Protection Board, adopted on 29 January 2020, in particular par. 7; but see already the "Provision on video surveillance" of the Garante of 8 April 2010, web doc. n. 1712680, in particular par. 3.1; lastly, see the Garante's FAQs on video surveillance". video surveillance, web doc. no. 9496574, no. 4; see also provisions of April 29, 2025, no. 244, web doc. no. 10144974; April 10, 2025, no. 201, web doc. no. 10139433; March 27, 2025, no. 168, web doc. no. 10138999; December 19, 2024, no. 805, web doc. no. 10107263; February 22, 2024, no. 100, web doc. no. 9990659; January 11, 2024, no. 5, web doc. no. 9977020 and the related press release of January 25, 2024, Web Doc. No. 9977299; October 20, 2022, No. 341, Web Doc. No. 9831369; April 28, 2022, No. 162, Web Doc. No. 9777974; April 7, 2022, No. 119, Web Doc. No. 9773950; September 16, 2021, No. 327, Web Doc. No. 9705650; and March 11, 2021, No. 90, Web Doc. No. 9582791).

First-level information (warning sign) "should communicate the most important information, such as the purposes of the processing, the identity of the controller, and the existence of the data subject's rights, together with information on the most significant impacts of the processing" (ECB Guidelines, cited above, para. 114). Furthermore, the signage must also contain information that may be unexpected for the data subject. This could include, for example, the transmission of data to third parties, particularly if located outside the EU, and the retention period. If this information is not provided, the data subject should be able to trust that only real-time monitoring is taking place (without any data recording or transmission to third parties) (ECB Guidelines, cited above, para. 115). First-level warning signage must contain a clear reference to the second-level information, for example, by indicating a website where the text of the extended privacy notice can be found.

Regarding the transparency of the processing, it should first be noted that the data subjects are not only the owners of the vehicles detected but also any other drivers of those vehicles, in the case of rented vehicles or vehicles otherwise granted for use to third parties, including within a family context. Furthermore, the data subjects are also all other persons who, regardless of whether the license plate number was acquired, appear in the videos, which, albeit for a short period of time, are captured by video devices placed on public roads for license plate reading purposes.

The Province has filed a copy of the first-level information (warning sign) that was allegedly provided to data subjects (see Annex XX to note XX, cited). However, this information does not comply with the requirements of Articles 5, paragraph 1, letter a), and 13 of the Regulation, as:

it does not mention the Province of Trento as a joint controller of the processing (see Article 13, paragraph 1, letter a), of the Regulation; see (see also paragraph 3.6 of this provision);

indicates a purpose for the processing ("road safety") that is completely irrelevant to the purpose allegedly pursued (see Article 13, paragraph 1, letter c), of the Regulation);

does not mention the rights of data subjects under Articles 15-22 of the Regulation (see Article 13, paragraph 2, letter b), of the Regulation);

does not provide information on the most significant impacts of the processing, particularly with regard to the automated reading of license plates of vehicles in transit (see Article 5, paragraph 1, letter a), of the Regulation);

does not refer to the data retention period of two years from collection, as this information could be unexpected for data subjects (see Article 5, paragraph 1, letter a), of the Regulation);

does not contain a clear reference to the second level of information, for example by indicating a website on which it is possible to consult the text of the extended information (see art. 5, par. 1, letter a), of the Regulation). In this regard, it is irrelevant when the Province argued in its defence that "the information sign initially used [...] was the one pro tempore suggested [by] the Guarantor [, or the one referred to in the general provision on video surveillance of 8 April 2010], which did not contain a link [to the second level information]"; this is because the indications regarding the elements that must make up the first level information were provided by the European Data Protection Board as early as XX with the aforementioned Guidelines 3/2019 on the processing of personal data through video devices, prior to the period in which the Province installed the video devices for the execution of the project (XX); as regards the circumstance that, as always stated in the defence brief, "and that "art. 13 [of the Regulation] does not include the inclusion of the aforementioned link among the essential requirements of the information, therefore it can reasonably be considered an appropriate, but not necessary, element”, it must be noted that, as a rule, the data controller must provide the data subjects with all the information referred to in art. 13 of the Regulation and that the same can benefit from the possibility of providing them with a layered information, composed of a simplified first-level information and an extended second-level information, only on condition that the first-level information contains a reference to the second-level information, thus allowing the data subjects, if they so wish, to acquire all the information relating to the processing (see the aforementioned Guidelines 3/2019, paragraphs 111 and 117, where it is highlighted that “data controllers may follow a tiered approach, opting for a combination of methods in order to ensure transparency […]. As regards video surveillance, the most important information must be indicated on the warning sign itself (first level), while the further mandatory details may be provided with other means (second level)”, it being understood that “the first level warning signs must contain a clear reference to this second level of information”).

The Province also stated that it replaced the initial warning signs with "the current signs containing the first-level information [which] were installed between 20th and 20th, replacing the previous signs," i.e., after the Authority initiated its investigation (see Appendix 20th to the note dated 20th).

This new version of the first-level information on data processing also does not fully comply with the requirements of Article 5, paragraph 1, letter a), and Article 13 of the Regulation, as:

it does not mention the Province of Trento as a joint data controller (see Article 13, paragraph 1, letter a), of the Regulation; see also paragraph 3.6 of this provision);

It incorrectly names the Provincial Roads Service as the data controller and the Province itself as the Data Protection Officer (see Article 13, paragraph 1, letters a) and b), of the Regulation.

It fails to mention the rights of data subjects under Articles 15-22 of the Regulation (see Article 13, paragraph 2, letter b), of the Regulation).

It fails to mention the data retention period of two years from collection, as this information could be unexpected for data subjects (see Article 5, paragraph 1, letter a), of the Regulation).

Regarding the second-level information on the processing of personal data, the Province stated that "the second-level information was made available to interested parties at the Technical Offices of the Road Services Department of the Autonomous Province of Bolzano starting October 25, 2019 [...]" and that "as part of the accountability process, a revision of the text was therefore carried out, resulting in a second updated version, dated XX, made available at the same offices [...]." This version "was also made available on XX both at the offices and online at the link https://www.provincia.bz.it/turismo-mobilita/strade/manutenzione/monitoraggio-del-traffico.asp, on the institutional website of the Road Services Department of the Autonomous Province of Bolzano."

With regard to the first version of the extended information notice, provided starting from October 25, 2019, it is noted that data subjects are informed that "furthermore, there is no possibility of tracing the personal data after its conversion," a statement that does not reflect the actual characteristics of the processing, given that, as illustrated above, the data controller, acting on behalf of the Province, is in possession of the information necessary to associate the data with license plate numbers, as these are merely pseudonymized data. Likewise, for the same reasons, it is incorrect that "the processing of personal data is therefore of minimal duration," as "the alphanumeric license plate code is immediately anonymized," making it "impossible to trace the original license plate," and that "the retention period of the personal data is minimal," also considering that, as highlighted above, pseudonymized data are retained for a period of two years. These statements constitute a violation of Articles 5, paragraph 1, letter a), and 13, paragraph 1, letter c), of the GDPR. 2(a) of the Regulation.

Furthermore, paragraph 6 of the privacy policy states that "the specific functioning of the encryption system, which immediately transforms personal data into anonymous data through encryption, means that processing is not carried out other than at a purely theoretical level using software" and that, therefore, "the processing does not constitute processing that allows the data subject to exercise his or her rights." In light of the above considerations regarding the full existence of personal data processing for an extended period of two years, this incorrect statement constitutes a violation of Articles 5(1)(a) and 13(2)(b) of the Regulation.

It should also be noted that the right to object under Article 21 of the Regulation was not explicitly brought to the attention of the data subjects and was not presented clearly and separately from any other information, thus also violating Article 21(4) of the Regulation.

Furthermore, the privacy notice in question does not clearly indicate the potential recipients or categories of recipients of the personal data, as there is no reference to the provider that, as data processor, processes the personal data on behalf of the Province. This therefore violates Article 13(1)(e) of the Regulation.

More generally, it should be noted that the fact that this version of the complete second-level privacy notice was made available to data subjects only in paper form at the "Technical Offices of the Roads Department of the Autonomous Province of Bolzano," without also publishing the text on the Province's official website, cannot be considered compliant with Articles 12(1) and 13 of the Regulation. Article 12(1) of the Regulation requires that the privacy notice referred to in Article 13 of the Regulation be "easily accessible" to data subjects. In this regard, the European Data Protection Board has stated that "second-level information must be easily accessible to the data subject, for example through a comprehensive information page made available at a central point (information desk, reception, cashier's desk, etc.) or posted in an easily accessible location" ("Guidelines 3/2019 on the processing of personal data through video devices", adopted on XX, para. XX), but on the assumption that this central point is located near the area subject to video surveillance. Otherwise, when, as in the present case, the video surveillance devices are distributed over large areas and distant from the data controller's premises, the first-level information notice must necessarily link to a second-level information notice available online, so that data subjects can easily access it without having to physically visit the data controller's premises. Therefore, Articles 12, paragraph 1, and 13 of the Regulation were comprehensively violated in the period between the start date of processing and XX, the date on which the information was published online.

Regarding the information on data processing, made available to data subjects starting from XX and published on the Province's institutional website starting from XX, following the initiation of the investigation by the Authority, it should be noted that this version of the document also incorrectly states that "furthermore, there is no possibility of tracing the personal data," that "the processing of personal data is therefore of minimal duration: through a specific cryptographic function, the license plate's alphanumeric code is immediately anonymized and used for statistical purposes," that "the cryptographic function [...] ensures that it is impossible to trace the original license plate after its conversion," and that "the retention period of the personal data is minimal, according to the time technically necessary to convert the license plate of the vehicle in transit into an encrypted code (60 seconds)." These statements constitute a violation of Articles 5(1)(a) and 13(2)(a) of the Regulation.

Furthermore, paragraph 6 of the privacy policy states that "the personal data collected is immediately transformed into anonymous data for statistical purposes, which could result in derogations from the exercise of your rights as a data subject." In light of the above considerations regarding the full existence of personal data processing for an extended period of two years, this incorrect statement constitutes a violation of Articles 5(1)(a) and 13(2)(b) of the Regulation.

It should also be noted that the right to object under Article 21 of the Regulation was not explicitly brought to the attention of the data subjects and was not presented clearly and separately from any other information, thus also violating Article 21(4) of the Regulation.

Furthermore, the privacy policy in question does not clearly indicate the recipients or categories of recipients of the personal data, as there is no reference to the provider who, as data processor, processes the personal data on behalf of the Province. This constitutes a violation of Article 13, paragraph 1, letter e), of the Regulation.

The lack of transparency towards data subjects is further aggravated by the fact that, as highlighted in paragraph 3.2 above, the legal basis on which the processing was based cannot be considered qualitatively adequate to meet the requirements of the European and national data protection legal framework, as it does not contain a detailed description of the data being processed, the data subjects, and the permitted processing operations.

In light of all the above considerations, it must be concluded that:

- from the date of activation of the video devices until XX, the date on which the new signs containing the first-level information were installed, including instructions on how to access the second-level information, the Province failed to fulfill its information obligations towards the interested parties (owners/drivers of the vehicles/other filmed individuals), having therefore acted in violation of Articles 5, paragraph 1, letter a), 12, paragraph 1, and 13 of the Regulation;

- starting from XX, the date on which the new signs containing the first-level information were installed, the Province provided the interested parties (owners/drivers of the vehicles/other filmed individuals) with a first-level information that was not entirely adequate, in violation of Articles 5, paragraph 1, letter a), 13, paragraph 1, letters a) and b), and paragraph 2, letter c). b) of the Regulation, as well as an inappropriate second-level disclosure that is not entirely appropriate, in violation of Articles 5, paragraph 1, letter a), and 13, paragraphs 1, letter e), and 2, letters a) and b), and 21, paragraph 4, of the Regulation.

3.6. Joint controllership with the Autonomous Province of Trento.

Pursuant to Article 4, paragraph 1, point 7, of the Regulation, the data controller is "the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law."

When two or more controllers jointly determine the purposes and means of processing, "they shall be joint controllers" and must "determine in a transparent manner, by means of an internal agreement, their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercise of the rights of the data subject, and their respective duties to provide the information referred to in Articles 13 and 14, unless and insofar as their respective responsibilities are determined by Union or Member State law to which the controllers are subject. Such an agreement may designate a contact point for the data subjects" (Article 26(1) of the Regulation). The agreement between the joint controllers "shall adequately reflect the respective roles and the relationship of the joint controllers with the data subjects" and "the essential content of the agreement [must be] made available to the data subject" (Article 26(2) of the Regulation).

As clarified by the Court of Justice of the European Union, "a natural or legal person who influences, for purposes proper to him, the processing of personal data and is therefore involved in determining the purposes and means of such processing may be considered a controller within the meaning of Article 4, point 7, of the GDPR" (judgments C-604/22, IAB Europe, of 7 March 2024, para. 57, and C 25/17, Jehovan todistajat, of 10 July 2018, para. 68). Therefore, "pursuant to Article 26, paragraph 1, of the GDPR, 'joint controllers' exist when two or more controllers jointly determine the purposes and means of processing" (judgments C-604/22, cited above, para. 57, and C-683/21, National Visual Control Commission, dated 5 December 2023, para. 40).

The investigation revealed that the video devices in question were also located within the Autonomous Province of Trento, pursuant to an agreement signed between the two provinces.

The agreement states that the database created as part of the project "will remain the property of the two administrations," that "the monitoring system will be managed by the Province of Bolzano," that "the data flow will be accessible by both provinces," and that "the system will remain the property of the two administrations" (see Resolution of the Provincial Council of Bolzano No. 683 of August 6, 2019, and Resolution of the Provincial Council of Trento No. 1192 of August 12, 2019). The Province of Trento, which co-financed the project, therefore has the right to request the Province to receive the aggregated output data.

Based on these elements, it must be considered that, by entering into the aforementioned agreement, co-financing the project (50%) and implementing it in their respective territories in order to obtain aggregated information on traffic flows within those territories, the two provinces acted as joint data controllers.

As clarified by the European Data Protection Board, "the general criterion for the existence of joint controllership is the joint participation of two or more entities in defining the purposes and means of a processing operation. Joint participation may take the form of a joint decision taken by two or more entities [...]" ("Guidelines 07/2020 on the concepts of controller and processor under the GDPR," adopted on July 7, 2021, para. 53). To this end, "an important criterion is that the processing would not be possible without the participation of both entities, in the sense that the processing operations performed by each entity are inseparable, or inextricably linked." In this case, by co-financing the project, authorizing the Province of Bolzano to contract out the work on its own behalf, and to install the video devices in its territory, the Province of Trento enabled the overall processing of personal data within the project, which, without its collaboration with the Province of Bolzano, would not have been possible.

Although during the preliminary investigation, both Provinces maintained that all decisions regarding the purpose and means of data processing were made solely by the Province of Bolzano and that the fact that the Autonomous Province of Trento financed the project is not decisive for the existence of a joint ownership situation, it should be noted that the agreement was stipulated "for the management of the monitoring program, for the year 2019 and following, of vehicle traffic on the Dolomite passes" and that the Province of Bolzano awarded the contract for the supply, installation, and management of the monitoring system, being "authorized to sign the contract also on behalf of the Province of Trento," so much so that the Province of Bolzano "through the successful tenderer was authorized to carry out installation work of the monitoring system also on the road network managed by the Province of Trento."

Furthermore, the project's results, in terms of aggregated traffic flow data, benefit both Provinces, as they can access and use this data for their own mobility policies (see "Guidelines 07/2020 on the concepts of data controller and data processor under the GDPR," cited above, paragraph 60, which states that "[...] joint data controllership may also exist when the entities pursue closely related or complementary purposes. This may occur, for example, when there is a mutual benefit resulting from the same processing operation [...]").

In this regard, it is worth noting that, as stated by the Court of Justice of the European Union, the existence of joint responsibility does not necessarily imply equivalent responsibility for the same processing of personal data among the different entities involved. Conversely, such entities may be involved in different phases of such processing and at different levels, so that the degree of responsibility of each of them must be assessed taking into account all the relevant circumstances in the specific context (judgments C-604/22, cited above, para. 58, and C-25/17, cited above, paras. 66 and 69; see the "Guidelines 07/2020 on the concepts of controller and processor under the GDPR", cited above, para. 58). Furthermore, it is not necessary for the purposes and means of processing to be determined by written instructions or mandates from the controller. Therefore, a data controller may be considered a natural or legal person who, for purposes specific to it, influences the processing of personal data and therefore participates in determining the purposes and means of such processing (see judgments C-604/22, cited above, para. 61, and C-25/17, cited above, para. 68; cf. the "Guidelines 07/2020 on the concepts of data controller and data processor under the GDPR," cited above, paras. 57 and 58).

The fact that the Province of Trento does not have access to the personal data being processed and does not store it in its own databases is irrelevant in this regard. This is because, again recalling the case law of the Court of Justice of the European Union, "the joint responsibility of several entities for the same processing, pursuant to that provision, does not presuppose that each of them has access to the personal data in question" (judgment C-40/17, Fashion ID, of 29 July 2019, para. 69; see also judgments C 25/17, cited above, para. 69, and C 210/16, Wirtschaftsakademie Schleswig-Holstein, of 5 June 2018, para. 38; see also the "Guidelines 07/2020 on the concepts of controller and processor under the GDPR", cited above, para. 56).

In light of the foregoing considerations and in line with previous public sector measures adopted by the Authority (see measures dated January 24, 2024, Nos. 31 and 32, web doc. Nos. 9992914 and 9992986; April 13, 2023, No. 122, web doc. No. 9896412), it must be considered that, within the scope of the project in question, the two Provinces processed personal data as joint data controllers, although they did not previously enter into a joint data controllership agreement, in violation of Article 26 of the Regulation.

3.7. Data protection impact assessment.

In the event of high risks to data subjects—for example, resulting from the use of new technologies—the data controller must conduct a data protection impact assessment, in order to adopt, in particular, appropriate measures to address such risks, after consulting the Garante in advance, where applicable (see Articles 35 and 36, paragraph 1, of the Regulation).

In this case, the Province failed to demonstrate that it had prepared a data protection impact assessment before starting the processing in question.

This impact assessment was, however, required, given that a data protection impact assessment is always required when the processing involves "systematic monitoring on a large scale of a publicly accessible area" (see Article 35, paragraph 3, letter c), of the Regulation; see "Guidelines 3/2019 on the processing of personal data through video devices," cited above, paragraph 1. 10)

The obligation to conduct an impact assessment was, moreover, also considered to be integrated pursuant to Article 35, paragraph 1, of the Regulation, given that at least three of the criteria indicated by the Article 29 Working Party in the "Guidelines on data protection impact assessment and determining whether processing is likely to result in a high risk" for the purposes of Regulation (EU) 2016/679" of 4 April 2017 were met, namely systematic monitoring, processing of highly personal data (location data), and large-scale data processing (see section III).

Given that the Authority has therefore charged the Province with violating Article 35 of the Regulation, it should be noted that only in its defense brief did the Authority argue that "the impact assessment was actually conducted" and that "it was not produced earlier due to a mere oversight [...]".

While noting that, in this regard only, the Province's conduct in its relations with the Authority cannot be considered compliant with the principle of "accountability" (Article 5, paragraph 2, of the Regulation), it should nevertheless be noted that the documentation submitted in the case file (see attachments to note XX) consists of two documents, both titled "Data Protection Impact Assessment relating to the Vehicle Traffic Flow Detection System on the Dolomite Passes," which merely contain temporal references ("XX" and "XX") but lack a specific date (for example, through acquisition into the Authority's IT system). In any case, these documents do not meet the substantive requirements set out in art. 35 of the Regulation, since an assessment has not been carried out of the probability and severity of the risks arising in theory from the processing, of the effectiveness of the technical and organizational measures envisaged for the purpose of mitigating such risks (see art. 35, paragraph 7, letters c) and d) of the Regulation) and of the overall level of risk remaining following the aforementioned measures (see art. 36, paragraph 1, of the Regulation; see the “Guidelines on data protection impact assessment and determining whether processing is likely to result in a high risk” for the purposes of Regulation (EU) 2016/679” of the Article 29 Working Party, adopted on 4 October 2017 - WP 248 rev.01, endorsed by the European Data Protection Board with “Endorsement 1/2018” of 25 May 2018, which highlights that “whenever the data controller is unable to find adequate measures sufficient to reduce the risks to an acceptable level (i.e. residual risks remain high) it is necessary to consult the supervisory authority”); see also the “Annex 2 - Criteria for an acceptable data protection impact assessment” of the same Guidelines, which requires that in the impact assessment “the risks to the rights and freedoms of data subjects are managed (Article 35, paragraph 7, letter c))”, determining “the origin, nature, particularity and severity of the risks (see recital 84) or, more specifically, for each risk (illegitimate access, unwanted modification and disappearance of data) […] from the perspective of data subjects; the sources of risk are considered (recital 90)”, identifying “the potential impacts on the rights and freedoms of data subjects in case of events including illegitimate access, unwanted modification and disappearance of data”, as well as “threats that could lead to illegitimate access, unwanted modification and disappearance of data”, estimating “the likelihood and severity (recital 90)”, and then determining “the measures envisaged to manage such risks (Article 35, paragraph 7, letter c)”. 7, letter d) and recital 90).

It is therefore confirmed that the Province acted in violation of Article 35 of the Regulation.

4. Conclusions.

In light of the above assessments, it is noted that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 168 of the Code – although worthy of consideration, do not overcome the concerns notified by the Office with the document initiating the proceedings and are insufficient to allow the dismissal of the present proceedings. Furthermore, none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data carried out by the Province is found to be unlawful, having carried out processing of personal data via video devices in violation of Articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulation, as well as Article 2-ter of the Code.

Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing or related processing), Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Considering that, in the case at hand, the most serious violations, relating to Articles 5, 6, 12, 13, and 21 of the Regulation, as well as Article 2-ter of the Code, are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article 83, paragraph 3, of the Regulation. 166, paragraph 2, of the Code, the total amount of the fine is up to €20,000,000.

5. Corrective measures (Article 58, paragraph 2, letters d) and f), of the Regulation).

Given that the documentation in the file only shows evidence of the deactivation of video devices located within the Province of Trento, at the express request of the latter (see the Province's note of 20th June, file no. XX, which confirmed this circumstance) and given the unlawful processing, it is necessary to order the Province, pursuant to Article 58, paragraph 2, letter d), of the Regulation, to promptly delete the personal data collected as part of the project, as well as to require the Province, pursuant to Article 58, paragraph 2, letter f), to: f) of the Regulation, the prohibition of any further processing using video devices installed on its own territory or, pursuant to agreements or other contractual arrangements, on the territory of other public entities and used in the context of the same project.

Pursuant to Articles 58, paragraph 1, letter a) of the Regulation and 157 of the Code, the Province shall notify this Authority, providing adequately documented feedback, within thirty days of notification of this order, of the steps taken to implement the above order pursuant to the aforementioned Article 58, paragraph 2, letters d) and f) of the Regulation.

6. Adoption of the injunction order for the application of the administrative fine and additional penalties (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code, as an additional administrative sanction" (Article 16, paragraph 1, of the Garante's Regulation No. 1/2019).

In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the pecuniary administrative sanction provided for in Article 83, paragraph 1, of the Code. 5 of the Regulation.

The aforementioned administrative fine imposed, based on the circumstances of each individual case, must be determined in amount, taking into account the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

Although the Province retained data relating to vehicles in transit for an extended period of time, thus theoretically being able to obtain sensitive information regarding the movements of a large number of data subjects within the observed territory, it did not process such data within the administrative proceedings under its jurisdiction; the Authority therefore acted with the intent to serve the public interest, albeit negligently, in the mistaken belief that there was an appropriate legal framework for the sector to support the initiative undertaken or that the information collected did not constitute personal data (Article 83, paragraph 2, letters a) and b), of the Regulation);

The Province has adopted measures to pseudonymize the data processed, thus mitigating the risk of data subjects being identified by third parties (Article 83, paragraph 2, letter a), of the Regulation);

The processing operations carried out, while potentially affecting the use of public spaces by data subjects, especially in the absence of adequate information on data processing, have not had detrimental consequences for their legal rights, as the video devices were not used to make decisions concerning them (Article 83, paragraph 2, letter a), of the Regulation);

Although inadequately, the Province had nevertheless posted information signs regarding the use of video devices in the affected areas (Article 83, paragraph 2, letter a), of the Regulation);

The processing did not involve special categories of data as defined in Article 83, paragraph 2, letter a), of the Regulation. 9 of the Regulation (see Article 83, paragraph 2, letter g), of the Regulation),

In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR," dated May 24, 2023, point 60).

That said, considering that the data controller is a public entity of provincial importance, it is believed that, for the purposes of quantifying the sanction, the following circumstances should be taken into account:

There are no previous relevant violations committed by the Province in the same context (Article 83, paragraph 2, letter e), of the Regulation);

The Province cooperated effectively with the Authority during the investigation (Article 83, paragraph 2, letter f), of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the pecuniary sanction at €32,000 (thirty-two thousand) for the violation of Articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulation, as well as Article 2-ter of the Code, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor no. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the processing involved data relating to vehicles transiting the area affected by the project, information of particularly sensitive nature. Although the investigation revealed that the Province had not initiated any proceedings against individuals identified by license plate numbers, their analysis may theoretically yield information regarding the data subjects' movements within the said area. Furthermore, the processing occurred over an extended period of time.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW WITH ALL THE FOREGOING, THE GUARANTOR

declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Autonomous Province of Bolzano for violation of Articles 5, paragraph 1, letter e), and a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulations, as well as 2-ter of the Code, within the time limits set forth in the reasons;

ORDERS

the Autonomous Province of Bolzano, represented by its legal representative pro tempore, with registered office at Piazza Silvius Magnago 1 - 39100 Bolzano (BZ), Tax Code 00390090215, to pay the sum of €32,000 (thirty-two thousand) as an administrative fine for the violations indicated in the reasons. It is hereby stated that the offender, pursuant to art. 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

- the aforementioned Province, in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €32,000 (thirty-two thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

- the aforementioned Province, pursuant to Article 58, paragraph 2, letters d) and f), of the Regulation, to immediately delete the personal data collected in the context of the project in question, and imposes a ban on any further processing by means of video devices installed on its territory or, pursuant to agreements or other contractual arrangements, on the territory of other public entities and employed in the context of the same project. It also provides the Guarantor, within the same deadline, pursuant to Articles 58, paragraph 2, letters d) and f), of the Regulation. 1, letter a), of the Regulation and Article 157 of the Code, an adequately documented report on the initiatives undertaken to implement the order;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, the publication of the injunction order on the Italian Data Protection Authority's website;

- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Italian Data Protection Authority Regulation No. 1/2019, the publication of this provision on the Authority's website;

- pursuant to Article 17 of the Italian Data Protection Authority Regulation No. 1/2019, the recording of the violations and measures adopted in accordance with Article 58, paragraph 2, of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, of the Italian Data Protection Authority's internal register. 1, letter u) of the Regulations.

Pursuant to Articles 78 of the Regulations, 152 of the Code, and 10 of Legislative Decree no. 150/2011, an appeal against this decision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the decision itself, or within sixty days if the appellant resides abroad.

Rome, September 25, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Scorza

THE SECRETARY GENERAL
Fanizza

[web doc. no. 10185463]

Decision of September 25, 2025

Register of Decisions
no. 531 of September 25, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Councillor Angelo Fanizza, Secretary General;

SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree no. 196 of June 30, 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Data Protection Authority, approved with Resolution No. 98 of 4 April 2019, published in the Official Journal No. 106 of 8 May 2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Data Protection Authority Regulation No. 1/2019");

CONSIDERING the documentation in the file;

CONSIDERING the observations made by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

RAPPORTEUR: Attorney Guido Scorza;

WHEREAS

1. Introduction.

The Authority has learned from press reports of the signing of a memorandum of understanding between the Autonomous Province of Bolzano - Alto Adige (hereinafter, the "Province"), Municipalities, the Government Commissioner's Office, the Police Headquarters, and the Police Forces. The purpose of the memorandum is to install a network of one hundred and twenty-four cameras across the Province, equipped with automated license plate reading capabilities for vehicles in transit. This network will be used to analyze traffic flows, aimed at guiding mobility and infrastructure policies, and to prevent and detect crimes.

2. The preliminary investigation.

During the investigation initiated on the basis of the aforementioned press reports, the Authority addressed several requests for information to the Province (see notes prot. nos. XX of XX; XX of XX; no. XX of XX; XX of XX). The Province, in responding to these requests (see notes prot. nos. XX of XX; XX of XX; XX of XX), stated, in particular, that:

"[…] the project […] falls within the institutional objectives of the Provincial Administration as set forth in Articles 13, paragraph 7, and 227 of the "New Highway Code," by Presidential Decree no. 381 of March 22, 1974, […] as well as by Provincial Council Resolution no. 683 of 06/08/2019 […]”;

“The project [consists in] detecting traffic flows in South Tyrol through license plate reading […]”;

“[…] the […] cameras placed along the road network read vehicle license plates and do not save photos […]”;

“[…] the statistical and aggregated data are used to plan a series of traffic-related measures, including with a view to environmental and economic protection of the Dolomites-UNESCO area and subsequent sensitive areas that have been gradually added to the project”;

“The cameras were installed and activated [as follows]: from XX (24 cameras); from XX (7 cameras); from XX (8 cameras); from XX (60 cameras); from XX (12 cameras); from XX (13 cameras)”.

“The second-level information was made available to interested parties at the Technical Offices of the Road Service Department of the Autonomous Province of Bolzano starting from XX”;

“[…] a revision of the text was therefore carried out, resulting in a second updated version, dated XX, made available at the same offices”;

“This version was also made available on XX both at the offices and online at the link https://www.provincia.bz.it/turismo-mobilita/strade/manutenzione/monitoraggio-del-traffico.asp, on the institutional website of the Road Service of the Autonomous Province of Bolzano”;

“The current signs containing the first-level information were installed between XX and the first XX, replacing the previous signs […]”;

“[…] the Province's interventions must be justified and must ensure that discriminatory or unreasonable applications are avoided, which necessarily requires the collection of data on traffic flows that are as objective and accurate as possible, and therefore, necessarily, a preliminary phase of monitoring them, since a choice cannot be justified without objective data”;

“the activity in question is expressly contemplated in a primary regulation […, namely] art. 19 of Presidential Decree no. 22 March 1974. 381 […]”;

“license plate numbers and other metadata associated with each license plate […] are never […] disclosed to the Province […]; the cameras are protected by a password known only to the data controller (supplier company) and not to the data controller (Province) […]”;

“the Province […] has access […] only to the final set of progressive numbers associated with traffic flows of origin and destination”;

“the entire process […] takes place entirely within the technological “shell” of the data controller, from which the Province maintains complete segregation”;

“[…] it must be excluded that the license plate constitutes, in the case under examination, personal data […, since it is not] cross-referenced with the database [of the] Automobile Club d’Italia […;] the data controller is not authorized to […] perform any type of matching between the processed data and other information”;

“[…] these license plate numbers constitute [in any case] data anonymous for the Administration and pseudonymized data for the data controller […]”;

the Province “does not [in fact] have any decryption key.”

"The aggregate processing is […] achieved by associating data sets with a hash string, and no longer with a license plate number";

- "[…] the system has been configured to create reports for up to 2 years [… to] allow […] concrete data to be available for planning road network interventions that allow for the effective management and optimization […] of traffic flows […]";

- "The video devices are also located within the Autonomous Province of Trento [hereinafter, the "Province of Trento"], by virtue of the [signature of an] agreement";

- "The civil ownership of the first 24 video cameras, those covered by the aforementioned agreement, belongs to both Provinces";

- The Province of Trento approved the aforementioned agreement with the minutes of the Provincial Council resolution, reg. resolution no. 1192 of August 12, 2019;

- "the agreement […] is the only agreement" between the two Provinces;

- "[…] the placement of the cameras; their selection; the selection of the data to be acquired through them; the choice of supplier […]; the logic to be applied to the data in order to obtain the traffic O/D matrices and the determination of traffic type (tourist, through traffic, residential, commuter) were determined by the Autonomous Province of Bolzano";

- "the Province […] of Trento intervened only on a financial level, does not […] have any direct contact with [the Authority], but has the right to request aggregate output data directly from the Autonomous Province of Bolzano."

In light of the statements made by the Province, the Authority involved the company providing the technological solution (hereinafter, the "Company") in the investigation, as data controller, by submitting a request for information (see note prot. no. XX of XX). In a note dated XX, the Company stated, in particular, that:

- "[…] the data set collected by the cameras [is as follows:] the camera identifier (code assigned to the individual camera), the date, hour, minute, and second of the vehicle's passage under the camera, the vehicle class, its nationality (if applicable), any KEMLER codes (dangerous goods), and, if applicable, the speed of transit";

- "the […] Company does not query the Public Vehicle Registry (P.R.A.) […, since] the activity performed is in no way aimed at identifying natural persons";

- "the clear license plate is deleted within a maximum of 60 seconds of receipt. A first salted hash string (first level of protection) is created from it, which is in turn deleted within 60 seconds of conversion after the creation of a second salted hash string (second level of protection)";

- "Both hash functions described above use the SHA256 function. The salt values used do not vary over time. Based on an algorithm and depending on the license plate's alphanumeric code, one of the over 200 different salts in the system is used. Only the sub-data controller, the only person able to access the databases, is aware of the algorithm and the over 200 different salts used before the two hash encryption functions. The algorithm is unidirectional and depends on the incoming license plate. After applying the first salt and SHA256 function to the license plate, it will be impossible, even for the sub-data controller, to trace the license plate from the hash code (first-level protection). Nonetheless, a second salt and SHA256 function are applied, obtaining a further new hash code (second-level protection). Only this last hash code will be saved in the database. The incoming license plate and the hash code (first-level protection) are not stored."

With note dated XX (prot. no. XX), the Office, on the basis of the elements acquired, the checks carried out and the facts that emerged following the investigative activity, notified the Province, pursuant to art. 166, paragraph 5, of the Code, of the initiation of the procedure for the adoption of the provisions referred to in art. 58, paragraph 2, of the Regulation, for having implemented the processing of personal data in violation of articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26 and 35 of the Regulation, as well as 2-ter of the Code. With the same note, the aforementioned owner was invited to submit written defenses or documents to the Guarantor or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

With note dated XX (ref. No. XX), the Province submitted a defense brief, setting out the defense arguments in detail, which are illustrated and considered in paragraph 3 below. The Province did not exercise its right to request a hearing before the Authority pursuant to Article 166, paragraph 6, of the Code.

3. Outcome of the investigation.

3.1. On the alleged failure to comply with procedural deadlines.

In its defence brief, the Province objected that there was "widespread non-compliance with peremptory deadlines", as the Authority had not observed the "120-day deadline from the ascertainment of the violation", as per "Table B, point 2) of the GPDP Regulation no. 2/2019 for notification", taking into account that "the procedure lasted over 16 months. Specifically: on XX the Authority initiated the administrative procedure against the Province by formulating some questions; on the following XX the Province provided a response; on XX a further request from the Guarantor followed; on XX a response from the Province was received; on XX the aforementioned 120-day deadline therefore expired; on the following XX, and even after 123 days from the last response (i.e. hypothetically making a new 120-day deadline start from XX), the Guarantor sent a new request for clarification; on XX, in a perspective Out of courtesy and full cooperation with the Authority, the Province nevertheless provided a timely response; at this point, 282 days had elapsed since that last response and over 400 days (including suspensions) from the initial deadline of XX, when on XX, the Authority sent the Province yet another request for clarification on issues it should have addressed by XX.

In this regard, some clarifications are needed regarding the procedural deadlines applicable to notifying the Province of the contested violations, as set forth in the Guarantor Regulation No. 2/2019.

Given that the administrative procedure in question is not subject to the 90-day deadline referred to in Law No. 689 of November 24, 1981, but rather to the 120-day deadline specifically identified, pursuant to Article 154, paragraph 3, and Article 166, paragraph 9 of the Code, by the aforementioned Guarantor Regulation No. 2/2019, it is noted that this term runs "from the date of ascertainment of the violation" (see Table B, Part 2) of the Guarantor Regulation No. 2/2019) and that the date of ascertainment is to be identified when both the collection of the investigative evidence and its evaluation by the proceeding administration have been completed (see, in this regard, Supreme Court of 8 August 2005, No. 16642; see also, Supreme Court, Civil Section II, No. 21114, No. 28 November 2012, and Supreme Court, Civil Section II, No. 8204, No. 8204, No. 8204).

With specific regard to the activity of independent administrative authorities, it is worth noting that the Supreme Court, in line with consolidated case law, has established that the activity of ascertaining the infringement, in relation to which the dies a quo of the deadline for the notification of the details of the infringement is placed, cannot coincide with the moment in which the fact is acquired in its materiality, but must be understood as including the time necessary for the evaluation of the data acquired and relating to the elements (objective and subjective) of the infringement and, therefore, of the final deliberation phase related to the complexity, in the specific case, of the investigations aimed at finding the existence of the infringement itself and acquiring full knowledge of the illicit conduct, so as to evaluate its consistency for the purposes of the correct formulation of the charge (see Cass. nos. 13050/2014, 1043/2015, 770/2017, 31635/2018 and 21500/2024).

Similarly, with specific reference to administrative offenses under the legislation on personal data protection, the Supreme Court recently reiterated that "the mere 'recognition' of facts does not in itself entail their 'verification', for the purposes of Article 166 [of the Code], where subsequent investigative and evaluative activity is necessary for the efficient implementation of the sanctioning process" (Civil Court, First Section, No. 18583/2025; see already, albeit with reference to the 90-day deadline provided for by Article 14 of Law 689/1981, Civil Court, Second Section, No. 18288/2020).

On this point, it should also be noted that, as noted by Supreme Court case law, in the event of multiple, interconnected violations, "the appropriateness of the overall time spent" by the proceeding administration to ascertain the aforementioned violations is to be understood as strictly connected "to the complexity of the investigation" undertaken by the same (see Supreme Court, First Civil Section, April 4, 2018, no. 8326).

It is also important to note that the aforementioned 120-day deadline "is suspended from August 1 to 31 of each year and resumes running from the end of the suspension period" (see Article 6, paragraph 1 of the Guarantor Regulation no. 2/2019).

In light of the above clarifications regarding the procedural deadlines applicable to the case at hand, as provided for by current legislation, it must be considered that the notification to the Province of the contested violations, carried out by the Office with note dated XX, was not untimely, especially considering the high degree of complexity of the case at issue in this administrative proceeding, which required investigative investigations involving not only the Province but also the supplier company and the Province of Trento, acquiring essential investigative elements for the purposes of defining the overall investigative framework.

In any case, regarding compliance with the aforementioned 120-day deadline, starting "from the date of discovery of the violation," and within which the "communication of the alleged violations (Article 166, paragraph 5, of the Code)" must be made (see Table B, no. 2, of the aforementioned Regulation of the Garante no. 2/2019), it must be noted that—aside from any assessment of the actual peremptory nature of this deadline in light of the most recent case law of the Court of Justice of the European Union (see judgment C-510/23, Trenitalia, of January 30, 2025)—in this case, this deadline was fully respected. The Province's response to the Office's last request for information (see note of XX, file no. XX) was, in fact, included in the Authority's protocol of XX (no. XX), and therefore, the administrative violation charge of XX was notified to the Province within a timeframe of just 25 days. Only in light of this last response, which specifically concerned the reconstruction of the subjective role of the Province and the Province of Trento in the context of the processing in question, could the overall investigation initiated against the Province be considered concluded and finalized, with the consequent "confirmation of the violation."

Regarding the aforementioned case law, according to which the Authority is required to comply with the aforementioned 120-day deadline, including for the purposes of sending multiple requests for information to the parties involved in the proceedings, aimed at clarifying or supplementing the preliminary information already acquired, it should be noted—without commenting on this case law here—that, in this case, contrary to the Province's assertions in its defense brief, all requests for information formulated during the preliminary investigation complied with this deadline, which is allegedly binding on the supervisory authority. Indeed, the first request for information of XX was responded to with a note of XX, entered into the Authority's records on the same date; the second request for information of XX was therefore submitted within 20 days of the Province's response; the third request for information was made on XX, or within 120 days of the date on which the note of XX was received in the Authority's protocol - no. XX of XX - with which the Province responded to the second request for information; the fourth request for information was made to the Company, with the Province in copy for its information, on XX, or within 118 days of the date on which the note of the same date with which the Province responded to the third request for information was received in the Authority's protocol - no. XX of XX; the fifth request for information was made to the Province on XX, or, taking into account the holiday suspension period from XX to XX, within 113 days of the date on which the note of XX was received in the Authority's protocol - no. XX of XX - with which the Company responded to the fourth request for information. This is without prejudice to the fact that the time of ascertainment of the violation cannot formally coincide with the date on which a specific document was acquired by the Authority. The Office always requires an in-depth assessment and investigation aimed at effectively "ascertaining the violation," taking into account all the investigative elements acquired through the various requests for information, especially in complex investigations, including technological ones, involving various parties, such as the one in question.

3.2. The processing of personal data carried out by the Province and the nature of the personal data collected.

It is established that the Province, starting from the month of XX, has installed 124 cameras in the area affected by the project, equipped with the automated license plate reading function for vehicles in transit. Specifically, the installation of these video devices was carried out according to the following schedule: from XX, 24 cameras; from XX, an additional 7 cameras; From XX, an additional 8 cameras; from XX, an additional 60 cameras; from XX, an additional 12 cameras; from XX, an additional 13 cameras. These devices are capable of extracting information regarding the class of vehicles in transit (motorcycle, car, bus, van, heavy vehicle, other), their nationality, any speed rating, any KEMLER code, as well as the origin and destination of the journey. This allows us to understand and analyze traffic flows within the Dolomites-UNESCO area and to make administrative decisions consistent with the actual characteristics of traffic flows in that area.

The license plate data of vehicles in transit is initially collected in clear text and stored for a maximum of 60 seconds, before being further processed.

In relation to this first phase of processing, it must be noted that license plate numbers are to be considered without any doubt as "personal data" relating to the owners and users of the vehicles associated with them, as they are information relating to identifiable natural persons (Article 4, paragraph 1, no. 1), of the Regulation), also due to the possibility for anyone to consult the public vehicle register (PRA). This is also confirmed by the case law of the Court of Cassation, which has stated that "there is no doubt that the information in question—the license plate of a motor vehicle, as it refers to an identified or identifiable individual—must be considered 'personal data.'" This was the case under Article 4, letter b), of Legislative Decree No. 196/2003 […] [and] it still is, pursuant to Regulation (EU) 2016/679" (Civil Court, First Section, Order of December 18, 2023, No. 35256; see also Civil Court, First Section, Order of July 7, 2021, No. 19270, which states that "particularly important are data that allow […] indirect identification, such as an identification number (for example, […] the license plate number)".

In this regard, As argued by the Province in its defense brief, that no queries are actually carried out by the PRA or that there is no specific interest on the part of the Province or the Company in carrying out such queries, as the project is not aimed at identifying specific natural persons and initiating administrative proceedings against them. The classification of information relating to a natural person as personal data and the recognition of the data subject's right to the protection guaranteed by European data protection legislation is, in fact, independent of the animus of the data controller and his actual will to acquire or not the additional information necessary for the identification of the data subjects, with the only relevant factor being the abstract existence of "means [...] which the data controller or a third party may reasonably use to identify [a] natural person directly or indirectly" (recital 26 of the Regulation). In fact, a different interpretation would result in data subjects being provided or not provided with protection on a case-by-case basis with regard to the processing of their personal data based on a circumstance, or the mere intention, only declared by the data controller. The data controller may decide whether or not to proceed with the identification of the data subject, which would not be objectively verifiable. Furthermore, regardless of the controller's intentions and as highlighted in the aforementioned Article 26 of the Regulation, the identification of a natural person may also be carried out by interested third parties, whether in the context of completely lawful activities (e.g., requests for data acquisition by law enforcement or judicial authorities in the context of criminal investigations) or unlawful activities (e.g., cybercriminal attacks), using the means reasonably available to them to achieve the identification of the data subjects, which, in this case, consisting of public registers, are readily available.

Having clarified this, it is noted that the investigation also revealed that the license plate number of each vehicle in transit is converted, after applying a salt (selected deterministically, including based on the license plate number itself, from among over 200 different salts present in the system), into an initial hash value, calculated using the hashing function. SHA-256. Upon completion of this conversion, which occurs within 60 seconds of transit, the license plate number is deleted. The first hash value thus obtained is then converted, after applying a salt, into a second hash value, calculated using the SHA-256 hashing function. Upon completion of this second processing, which occurs within a further 60 seconds, the first hash value is deleted. A sequential number is then associated with the second hash value. The association between the second hash value and the sequential number, which both constitute unique vehicle identifiers, is stored in a first database; the data relating to the vehicle's transit (sequential number, speed and any KEMLER code of the vehicle, date and time of transit, video device identifier) are stored in a second database and retained for two years.

Contrary to what the Province claimed during the investigation, these operations only result in the pseudonymization of information relating to vehicles in transit. trace them back to them, thus maintaining their personal nature. Pseudonymization is, in fact, a measure that can be adopted to ensure data minimization, selective access to information, in accordance with the principles of privacy by design and by default, as well as a level of security appropriate to the risk, which, however, does not affect the personal nature of the information subjected to it (see Article 32, paragraph 1, letter a), of the Regulation). The cons. 26 of the Regulation clarifies, in fact, that “personal data subjected to pseudonymisation, which could be attributed to a natural person through the use of additional information, should be considered as information on an identifiable natural person” (see, among others, the “Guidelines 1/2022 on data subjects' rights - Right of access”, adopted by the European Data Protection Board on XX, where it is highlighted that “personal data subjected to pseudonymisation are still personal data, unlike anonymised data”; see also the “Opinion 1/2017 on the proposal for a Regulation on privacy and electronic communications (2002/58/EC)” of 4 April 2017 - WP 247, with which the Art. 29 Working Party - now the European Data Protection Board -, albeit with reference to the so-called Mac Addresses and in a different context, clarified that “MAC addresses are personal data and remain so even after the adoption of measures security features such as hashing”).

The Court of Justice of the European Union itself has stated that "it follows from Article 4(5) of the GDPR, in conjunction with Recital 26 of that regulation, that personal data that have only been pseudonymized and that could be attributed to a natural person through the use of additional information must be considered as information on an identifiable natural person, to which the principles relating to data protection apply" (Case C-683/21, National Visual Rights Council, 5 December 2023, paras. 57 and 58).

Nor is it relevant that the entire pseudonymization process, using hash functions, is carried out not directly by the Province but by its own supplier, who acts, in any case, on its behalf as data controller, even though the Province does not directly have the additional information necessary to attribute the data to specific data subjects (vehicle owners/drivers), gaining knowledge exclusively of data on an aggregate basis. Indeed, it should be emphasized that the data controller, as the entity responsible for decisions regarding the purposes and methods of processing the data subjects' personal data, has "general responsibility" for the processing carried out (see Article 74 of the Regulation; see, among others, Decision No. 409 of 1 December 2022, web doc. No. 9833530 and the previous provisions referred to therein; see also the "Guidelines 07/2020 on the concepts of data controller and data processor under the [Regulation]", adopted by the European Data Protection Board on 7 July 2021, especially paragraph 174). Therefore, “such a data controller may be subject to an administrative fine pursuant to Article 83 of the [Regulation] in a situation where personal data are subject to unlawful processing and it is not such a data controller but a processor, used by it, which has carried out such processing on behalf of the controller”, it being irrelevant that “that entity has not itself carried out processing operations on such data”; Therefore, it follows from "Article 4, point 7, of the GDPR […], read in light of Recital 74 of the GDPR, […] that an entity, where it satisfies the condition laid down in that Article 4, point 7, is the controller not only of any processing of personal data that it carries out itself, but also of any processing carried out on its behalf" (Court of Justice of the European Union, judgment C-683/21, National Visual Standards, 5 December 2023).

Equally irrelevant is the fact that the processing of unencrypted personal data, before the application of the hash function, occurs within a limited time frame of approximately sixty seconds. The duration of processing is, in fact, irrelevant to the assessment of its lawfulness, and even when processing is extremely short, the data controller is not exempt from the obligation to ensure that there is an appropriate legal basis to justify it (see, most recently, provisions of January 11, 2024, no. 5, web doc. no. 9977020, and April 13, 2023, nos. 122 and 123, web doc. no. 9896412 and web doc. no. 9896808).

In this regard, in its defense brief, the Province argued that:

"The 'hash' [...] has specific mathematical characteristics, including irreversibility. That is, it is a one-way function; no one, not even [the Company], not even if they wanted to, is able to invert it, and this is due to objective mathematical impossibility."

"Since it cannot invert it, even if [the Company] retained the original license plates, rather than immediately deleting them (as it does), it would still be completely unable to identify, starting from a hash string, a specific license plate among those (hypothetically) retained. That is, having taken a hash string, it would have to recalculate all the hashes of the hypothetically retained license plates until it found one identical to the one sought, and keep track of the process along the way (i.e., create an association table)."

"But [the Company], by design, neither stores license plates nor tracks the process of generating each individual hash from a given license plate. Only if it stored license plates and a record of the process […] would the hash in question be a pseudonym within the meaning of Article 4.5) [of the Regulation], a provision that requires the separate storage of "additional information." In the absence of storage of the original data and a table associating them with the hashes, the latter are not, within the meaning of the Regulation, "pseudonyms," thus violating the definition in Article 4.5";

"[…] such additional information stored [by the Company] absolutely does not exist, nor does it result from the investigation, and it is clear that a hash, especially a salted one, cannot be submitted to the PRA for consultation, but only a license plate";

"That is, it happens that [the Company]: does not retain any association table between each license plate and each hash; it does not even retain the original license plates, but deletes them as soon as the hash conversion has taken place; that is, it does not have two databases to cross-reference (license plate database and hash database) nor even an association table; it only retains the hashes. Ultimately, therefore, [the Company] is unable, starting from the hashes alone, to reconstruct the original license plates and therefore consult the Public Vehicle Registry."

"[…] the salting process, in this case a double process, allows us to exclude even the theoretical hypothesis of attacks by third parties who illegally gained possession of the hashes, because the data would be completely unusable for them, a point which also demonstrates the quality of the security measures adopted."

"For the purposes of the definition of 'personal data,' two specific cumulative legal conditions are required: 1. the data subject must be specifically identifiable, pursuant to Recital 26 [of the Regulation]; 2. the data must be classified as information on a natural person. […] In this case, neither of these two conditions is met: that is, we have neither specifically identifiable individuals nor information about them."

"The Public Vehicle Register (PRA) cannot be queried by sending a hash. The license plate must be traced, but since it is a one-way function, this is mathematically impossible. Given a certain hash, it is not possible to identify the license plate, which eliminates the significant risk for the data subjects." It is only possible to create the hash from the license plate, not the other way around."

This means that if the Company wanted to expose the interested parties to risk, it would have to: 1. create a massive database of all Italian and foreign license plates in circulation; 2. store it (rather than delete the plates after 60 seconds); 3. recalculate a new hash database from this license plate database, creating (and saving) a license plate-hash association table during this process […]; 4. compare this second hash database with the first and, using the association table, connect the values of the first with the license plate database; 5. then conduct massive queries to the Public Vehicle Register (PRA), at prohibitive costs (millions of euros); 6. thereby violate the contract with the Autonomous Province; 7. decide to act for its own purposes, becoming the data controller, excluding the Province from liability; 8. all of this without any plausible reason.

"In the event, however, that the hashes are stolen by malicious third parties, the double salting step constitutes a mathematically insurmountable constraint, so there is no doubt that the third party would steal unusable data";

"Salted hashes [...] are therefore not covered by Article 4.1) [of the Regulation]."

This defense cannot be accepted. In order to detect the transit of a vehicle entering and exiting the area affected by the project, the system must generate identical identifiers (second hash value and associated progressive number) from the same license plate number, so that the data relating to the transits of that vehicle can be attributed to the same "traffic unit." Specifically, the first unique vehicle identifier (second hash value) is calculated from a vehicle's license plate number using hashing functions (and a limited, non-variable set of salts), which are considered weak pseudonymization techniques and vulnerable to brute-force attacks (see the document "Pseudonymization techniques and best practices" published in November 2019 by the European Union Agency for Cybersecurity - ENISA, especially section 5.1.3). The second unique vehicle identifier (sequential number), associated with the first unique identifier, is assigned upon the first transit and remains unchanged over time. In this context, it is possible, for example, to calculate the second hash value given a specific license plate number and verify its presence in the first database (indicative of the fact that the vehicle in question has made at least one transit through the territory covered by the project). If this hash value is present, it is then possible to retrieve the associated progressive number and search, in the second database, for data relating to the transits associated with that progressive number. Since the set of license plate numbers is limited (for example, in the numbering system currently used in Italy, there are approximately 75 million possible combinations of license plate numbers from AA001AA to GZ999ZZ, not all of which are valid or used), the aforementioned operations can be performed, using means reasonably available to anyone, not only on a single license plate number, but also on the entire set of license plate numbers. It is therefore technically and theoretically possible for the data controller or processor, as well as any third parties who for any reason become aware of the characteristics of the hashing functions used (and the set of salts applied) and information on the relationships between the two unique identifiers (second hash value and progressive number), to associate the transit data with the license plate numbers of the vehicles that performed them.

In light of all the foregoing considerations, it is established that the Province, using a data controller, processed personal data relating to vehicles transiting the areas where the video devices in question were installed.

On the other hand, although the Province stated in its defense brief that "the provision of information pursuant to Article 13 [of the Regulation], the classification of the contract with [the Company] pursuant to Article 28 [of the Regulation], and the other activities compliant with the Regulation undertaken by the Autonomous Province are attributable solely to a prudential approach," no document in the case file suggests that the Authority implemented these measures solely as a precautionary measure. Instead, it can be deduced from this circumstance that the Province was unsure of its own determination regarding the non-attribution of the information collected to the definition of personal data, so much so that it nevertheless decided to fulfill some of the obligations set forth in the Regulation.

3.3. Lawfulness of processing.

The processing of personal data through video devices by public bodies is generally permitted if it is necessary to comply with a legal obligation to which the data controller is subject or to perform a task carried out in the public interest or in the exercise of official authority vested in the data controller (see Article 5, paragraph 1, letter a), Article 6, paragraphs 1, letter c) and e), Articles 2 and 3 of the Regulation, as well as Article 2-ter of the Code; see the "Guidelines 3/2019 on the processing of personal data through video devices," adopted by the European Data Protection Board on January 29, 2020, paragraph 41; see also the FAQs of the Italian Data Protection Authority on video surveillance, dated December 3, 2020, web doc. no. 9496574).

The data controller is required, in any case, to comply with data protection principles, including "lawfulness, fairness, and transparency" and "data minimization," according to which personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject," as well as "adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed" (Article 5, paragraph 1, letters a) and c), of the Regulation).

During the investigation, the Province stated that the processing of the personal data in question was necessary to "study and understand traffic flows, their dynamics, orientation, type (tourist, commuter, through traffic, residential), and frequency" and then "proceed to substantially reshape traffic flows in the Dolomite area" (note of XX). At present, the video devices in question are not used for the prevention, investigation, detection, or prosecution of crimes.

Preliminary monitoring of traffic flows would be necessary to adequately justify the Province's interventions in this area, which are to be adopted to achieve the objective of ensuring the safety of the Dolomite passes, protected by UNESCO, with respect to the massive traffic flows that pass through them, as established by the Provincial Council resolution of August 6, 2019.

This activity would also be necessary pursuant to Article 19 of Presidential Decree No. 381 of March 22, 1974, pursuant to which, in exercising their landscape and other delegated functions, the Provinces, in agreement with each other and subject to the opinion of the Ministry responsible for infrastructure and mobility, may regulate measures to limit vehicular traffic along the roads connecting their respective territories.

The Province also invoked Article 19 of Presidential Decree No. 381 of March 22, 1974. 13, paragraph 7, and Article 227 of the "New Highway Code" as the basis for the processing of personal data in question.

In this regard, it should be noted that, as stated by the Court of Justice of the European Union, pursuant to Article 52, paragraph 1, first sentence, of the Charter of Fundamental Rights of the European Union ("CFREU"), any limitations on the exercise of the rights and freedoms recognized by the Charter—which include, in particular, the right to respect for private life, guaranteed by Article 7 of the Charter, and the right to the protection of personal data, enshrined in Article 8 of the Charter—must be provided for by law. This implies, in particular, that the legal basis permitting the interference with those rights must itself define the scope of the limitation on the exercise of the right in question. In particular, "to satisfy the requirement of proportionality, which is expressed in Article 5(1)(c) of the Regulation […] the law on which the processing is based must provide clear and precise rules governing the scope and application of the [envisaged] measure and impose minimum requirements so that the individuals whose personal data are affected have sufficient guarantees to effectively protect their data against the risk of abuse. Such law must be legally binding within the national legal system and, in particular, indicate the circumstances and conditions under which a measure providing for the processing of such data may be adopted, thus ensuring that the interference is limited to what is strictly necessary" (judgment C-175/20, Valsts ieņēmumu dienests, 24 February 2022, para. 83).

In this regard, the Court has also held that legislation introducing a measure permitting such interference must provide clear and precise rules governing the scope and application of the measure in question and establishing minimum requirements, so that individuals whose personal data have been processed have sufficient guarantees to effectively protect that data against the risk of abuse (see C-175/20, cited above, para. 55; see Article 6(3) of the Regulation, as well as recital 45 thereof).

Furthermore, any limitations on the fundamental rights to respect for private life and the protection of personal data (and Articles 7 and 8 of the CFREU) "may be made, provided that, in accordance with Article 52(1) of the Charter, they are provided for by law" and "respect the essence of the fundamental rights as well as the principle of proportionality. Pursuant to this principle, limitations may be made only where they are necessary and genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others. They must apply only to the extent strictly necessary, and the legislation causing the interference must lay down clear and precise rules governing the scope and application of the measure in question" (C-184/20, Vyriausioji tarnybinės etikos komisija, 1 August 2022, para. 64).

Similar principles have also been affirmed by the European Court of Human Rights in relation to the admissibility of limitations to the right to respect for private and family life enshrined in Article 7 of the ECHR. 8 of the European Convention on Human Rights, even in cases where the interference concerns activities or conduct taking place in a public place (see Glukhin v. Russia, Application No. 11519/20, 4 July 2023, paras. 64, 75, and 77; Satakunnan Markkinapörssi Oy and Satamedia Oy v. Finland, Application No. 931/13, 27 June 2017, paras. 129-131; Peck v. United Kingdom, Application No. 44647/9, 28 January 2003, para. 59; Copland v. United Kingdom, Application No. 62617/00, 3 April 2007, para. 46).

In accordance with this legal framework and the case law of the two Courts, Article 6(2) and (3) of the Regulation specifies that the basis for the processing of data referred to in paragraph 1(c) and (e) must be established by Union law or the law of the Member State to which the controller is subject. Such law must determine the purpose of the processing and contain specific provisions to adapt the application of the provisions of the Regulation. It is understood that Union or Member State law must, in any case, pursue an objective of public interest and be proportionate to the legitimate aim pursued.

In implementing the provisions of Article 6(2) and (3) of the Regulation, the national legislator has specified that the legal basis provided for in Article 6(3)(e) is: 6(1)(b) of the Regulation, i.e., "the law of the Member State to which the data controller is subject" and on which "the processing of the data referred to in paragraph 1(c) and (e) [of Article 6 of the Regulation] is based," consists of "a law or regulation or general administrative act" (see Article 2-ter, paragraph 1, of the Code).

That said, with regard to the specific case, it is noted that the Province has not demonstrated the existence of a qualitatively adequate legal framework to justify the processing of the license plate numbers of vehicles in transit for the processing purposes envisaged.

In particular, it is noted that the Province referred, first and foremost, to Articles 13, paragraph 7, and 227 of Legislative Decree No. 285 of 30 April 1992 (New Highway Code), which, however, do not provide for the possibility of acquiring the license plate numbers of vehicles in transit and tracking the frequency of their passage and the routes taken by specific vehicles. Nor did the Province refer to specific "directives issued by the Ministry of the Environment and Land Protection, after consulting the Ministry of Infrastructure and Transport" which, for the purposes of these provisions, would cover the processing of personal data in question.

The Province also noted that the initiative in question is the subject of Provincial Council Resolution No. 683 of August 6, 2019, concerning "Approval of the draft agreement between the Province [...] of Trento and the Province [...] of Bolzano for the management of a structural monitoring system for vehicular traffic on the Dolomite passes," adopted pursuant to Article 19 of Presidential Decree No. 381 of March 22, 1974. This resolution concerns the "Approval of the draft agreement between the Province [...] of Trento and the Province [...] of Bolzano for the management of a structural monitoring system for vehicular traffic on the Dolomite passes." Through this agreement, the two Provinces, in order to “to adopt more suitable measures [than the scheduled access], [they intended to start] a process of systematic data collection for traffic monitoring through four Dolomite passes”. The aim “of this monitoring is to be able to build, for the entire season, an O/D matrix [, i.e. origin/destination,] on the vehicular traffic that currently travels through the Dolomite passes, through a system of cameras and the creation of specific software, associated with a related database, which will remain the property of the two Administrations, which will allow the classification into at least 4 categories of vehicles (motorcycles, cars, buses, other) and in different speed classes as well as the possibility of a possible homologation for sanctioning purposes”. The “structural monitoring project starting from the summer of 2019, consists of the installation and management of a system of 24 fixed cameras for a period of 8 years […]”. It is also stated that “the management of the monitoring system will be the responsibility of the Province of Bolzano, while the data flow will be accessible from both Provinces. The system will remain the property of the two administrations."

The law to which the resolution refers, namely Article 19 of Presidential Decree No. 381 of March 22, 1974, limits itself, however, to contemplating the possibility of "regulating measures to limit vehicular traffic along the roads connecting the respective territories," providing for a general obligation to justify such measures, but without any specific reference to the need to track the routes taken by specific vehicles using license plate detection technologies.

In this context, neither Resolution No. 683 of the Provincial Council of Bolzano of August 6, 2019, nor the related Resolution No. 683 of the Provincial Council of Trento of August 6, 2019, provide any specific justification for such measures. 1192 of 12 August 2019 can be considered adequate in terms of the quality of the legal basis (see Article 6, paragraph 3, of the Regulation), given that they do not specifically regulate the types of data processed, the data retention periods, and the processing operations and procedures, including measures to ensure lawful and fair processing. In particular, the resolutions make no explicit reference to the collection and processing of license plate data and their retention for a period of two years in order to reconstruct vehicle routes. There is only a generic reference to the creation of an "Origin/Destination matrix" for vehicle traffic currently traveling through the Dolomite passes. These aspects were, in fact, defined by the Province solely through internal organizational documents and within the contractual relationship with the data controller. Nor can the argument, advanced by the Province in its defense brief, be accepted, according to which the "[...] resolution of the Provincial Council [...] prescribes both the need to construct the O/D matrix (which requires the recognition of the same vehicle when passing through at least two different locations, therefore requiring the use of video cameras) and the need to classify vehicles (which, combined with the O/D matrix, requires the use of video cameras), as well as the different speed classes (which also requires video cameras)", given that, as highlighted above, legislation that infringes on the right to data protection must contain clear and precise provisions governing its scope and application, satisfying the quality requirements set out in the Regulation, thus ensuring that the processing is foreseeable for the data subjects. These requirements cannot be considered satisfied where, as argued by the Province, the processing is merely deducible from the overall wording of the provision on which it is based.

The Province, in its defense briefs, also stated that, in the unlikely event that personal data processing is deemed to exist, it must be considered that "the legal basis for the processing is that of Article 6.1.e) [of the Regulation], therefore, pursuant to Article 6.3, it is not necessary for the relevant provision to indicate the purpose, it being sufficient that it be 'necessary' for the task of public interest, nor, above all, that it indicate the categories of personal data and the other elements of the processing, as is clearly deduced from the use, in Article 6.3, of the verb "may" (or "could contain"), moreover in the conditional tense "may contain, etc." Likewise, Article 2-ter, paragraph 1-bis [of the Code] confirms the lawfulness of the processing."

In this regard, it should be noted that, as stated by the Court of Justice of the European Union, "the lawful processing of personal data […] on the basis of Article 6(1)(e) of the GDPR presupposes not only that [the controllers] can be regarded as carrying out a task carried out in the public interest, but also that the processing of personal data for the performance of such a task relies on a legal basis provided for in Article 6(3) of that regulation" (judgment of 20 October 2022, Koalitsia «Demokratichna Bulgaria – Obedinenie» - C‑306/21, paras. 48-52). In particular, the legal basis for the processing under Article 6(1)(e) of the GDPR is the processing of personal data pursuant to Article 6(1)(e). (e) of the Regulation, “in accordance with Article 6(3) of the GDPR, in conjunction with recital 45 thereof […] must be established by Union law or by the law of the Member State to which the controller is subject. Furthermore, Union law or Member State law must pursue an objective of public interest and be proportionate to the legitimate aim pursued. The combined provisions of Article 6(1)(e) of the GDPR and Article 6(3) of that Regulation therefore require a legal basis, in particular a national legal basis, for the processing of personal data by controllers acting in the performance of a task carried out in the public interest or in the exercise of official authority” (judgment of 2 March 2023, C-268/21 - Norra Stockholm Bygg, paras. 30-32; see also judgment of 30 March 2023, C-34/21 - Hauptpersonalrat der Lecturers and Teachers, paragraph 87). Therefore, in the absence of specific legal provisions (see Article 2-ter, paragraph 1, of the Code) that contemplate and regulate, with the necessary quality requirements, the processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the data controller cannot generically invoke the legal basis set out in Article 6, paragraph 1, letter e), of the Regulation (see Article 2-ter, paragraph 1, of the Code, which, while permitting processing "necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in them," nevertheless requires "compliance with Article 6 of the Regulation").

Having clarified this regarding the quality requirements of the legal basis, it should be noted that the processing of personal data may find its legal basis in Article 6, paragraph 1, letter e), of the Regulation. 1.1(e) of the Regulation if and to the extent that it is "necessary" for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. This condition must be examined in conjunction with the principle of data minimization enshrined in Article 6(1)(c) of the Regulation, according to which personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This is because, as highlighted above, in accordance with the aforementioned Article 52(1) of the Charter of Fundamental Rights of the European Union, the fundamental rights to respect for private life and to the protection of personal data, set out in Articles 7 and 8 of the Charter, may be subject to limitations only if they are provided for by law and respect the essence of the fundamental rights as well as the principle of proportionality, expressly referred to in Article 6(3) of the Regulation. By virtue of this principle, such limitations must be necessary and genuinely meet objectives of general interest recognized by the Union or the need to protect the rights and freedoms of others, operating only to the extent strictly necessary.

Therefore, in order to determine whether processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, it is necessary to verify in particular whether, in light of the seriousness of the interference with the fundamental rights to respect for private life and the protection of personal data caused by the processing, the latter is justified and, in particular, proportionate to the achievement of the objectives pursued. As highlighted by Council 39 of the Regulation, this requirement of necessity is not satisfied when the general interest objective in question can reasonably be achieved equally effectively by other means that are less prejudicial to the fundamental rights of the data subjects, in particular the rights to respect for private life and to the protection of personal rights guaranteed by Articles 7 and 8 of the Charter, given that derogations and restrictions to the principle of protection of such data must be limited to what is strictly necessary (see Court of Justice of the European Union, judgments C-184/20, Vyriausioji tarnybinės etikos komisija, of 1 August 2022, paras. 73, 82, 85, 93, 94, 98, 99; C-439/19, Latvijas Republikas Saeima, of 22 June 2021, paras. 99, 105, 106, and 113).

In this case, the documentation does not show that the Province carried out specific and preliminary assessments regarding the actual necessity of processing the personal data in question and its proportionality to the objective pursued (see Article 6, paragraph 3, of the Regulation). It is not theoretically possible to exclude that there were sufficiently effective tools and solutions, but less impactful on the rights and freedoms of the data subjects, to justify any traffic limitation measures adopted pursuant to the aforementioned Article 19 of Presidential Decree no. 22 March 1974. 381. On the other hand, as highlighted by the European Data Protection Board, albeit in a different context, "location data are particularly suited to providing insights into the lifestyle habits of data subjects. The journeys made have the particular characteristic of allowing the driver's place of work and residence, as well as his/her interests (leisure), to be traced" ("Guidelines 01/2020 on the processing of personal data in the context of connected vehicles and mobility-related applications", 9 March 2021, p. 17). Only in its defense brief did the Province, in fact, argue that "the reality is that there is no reliable alternative technical solution, one applied in response to the state of the art [...] Any other alternative solution (e.g. interviews with drivers; home investigations; telephone interviews; postal questionnaires; collaboration with telephone operators) is certainly inferior, since it would not only require an extraordinary search for personal data, subsequent massive processing, sometimes not even possible or even relevant, and in any case unjustified interference in the personal sphere, but it would also be prohibitively expensive", further stating that it would be "the burden of this Office [of the Guarantor] to prove otherwise". It should be remembered, however, that in accordance with the accountability principle (see Articles 5, paragraph 2, and 24 of the Regulation), which informs all European data protection legislation, the data controller must ensure, before starting the processing, compliance with data protection principles, including those of "data minimization" (Article 5, paragraph 1, letter c), of the Regulation, which, as mentioned, is reflected in the requirement of "necessity" for processing in the legal bases referred to in Article 6, paragraph 1, letters b) to e), of the same Regulation, and "be able to demonstrate this."

Finally, regarding the fact that, as stated, data relating to vehicles in transit may be processed broadly for "statistical analysis," it should be noted that, although this processing purpose has not been specifically invoked by the Province, there is no proven legal basis justifying such processing for statistical purposes. The Province has not cited any law, or, where required by law, any regulation, appropriate in terms of rank and quality, that expressly provides for such processing, regulating its essential characteristics, nor has it established the applicability of industry-specific ethical rules (see Articles 6, paragraph 1, letter a), and paragraphs 2 and 3, and 89 of the Regulation, as well as Articles 2-ter, 2-quater, paragraph 4, and Chapter III of the Code).

In light of all the foregoing considerations, it is established that the Province processed the personal data in question, relating to vehicles in transit, using video devices installed on public roads, in a manner inconsistent with the principles of lawfulness, fairness, and transparency, and in the absence of an appropriate legal basis, in violation of Articles 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, of the Regulation, as well as Article 2-ter of the Code.

3.4. The principle of storage limitation

Under the principle of "storage limitation," personal data must be retained in a form that permits identification of data subjects for no longer than is necessary for the purposes for which they are processed (Article 5, paragraph 1, letter e), of the Regulation).
The Province has stated that it will retain pseudonymized personal data for a period of two years from the date of collection, as "it is possible to query the software to create reports based on historical data for up to two years."

This extremely long retention period cannot be considered proportionate to the purposes of the processing, given that, once the relevant characteristics of each vehicle in transit (class; speed class; origin and destination) have been identified and the relevant information acquired for the purposes of processing aggregated data, there is no reason to retain license plate data, even pseudonymized, for such a long period of time, exposing data subjects to a significant risk to their fundamental rights and freedoms, resulting from the fact that their movements across the territory can be systematically tracked and reconstructed.

Furthermore, there is no evidence in the documents that the data relating to the unique identifiers (second hash value and sequential number) of vehicles transiting the reference territory are also subject to deletion after this period. Their retention, even after deletion of information relating to individual transits, is sufficient to disclose the fact that at least one transit has occurred.

For these reasons, the Province acted inconsistently with the principle of "retention limitation," in violation of Article 5, paragraph 1, letter e), of the Regulation.

3.5. Transparency towards data subjects.

In accordance with the principles of "lawfulness, fairness, and transparency," the data controller must take appropriate measures to provide the data subject, prior to processing, with all the information required by the Regulation in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (Articles 5(1)(a), 12, and 13 of the Regulation).

When video devices are used, the data controller, in addition to providing first-level information by placing warning signs near the area subject to video surveillance, must also provide data subjects with "second-level information", which must "contain all the mandatory elements pursuant to Article 13 of the [Regulation]" and "be easily accessible to the data subject, for example through a complete information page made available in a central hub […] or posted in an easily accessible place" ("Guidelines 3/2019 on the processing of personal data through video devices" of the European Data Protection Board, adopted on 29 January 2020, in particular par. 7; but see already the "Provision on video surveillance" of the Garante of 8 April 2010, web doc. n. 1712680, in particular par. 3.1; lastly, see the Garante's FAQs on video surveillance". video surveillance, web doc. no. 9496574, no. 4; see also provisions of April 29, 2025, no. 244, web doc. no. 10144974; April 10, 2025, no. 201, web doc. no. 10139433; March 27, 2025, no. 168, web doc. no. 10138999; December 19, 2024, no. 805, web doc. no. 10107263; February 22, 2024, no. 100, web doc. no. 9990659; January 11, 2024, no. 5, web doc. no. 9977020 and the related press release of January 25, 2024, Web Doc. No. 9977299; October 20, 2022, No. 341, Web Doc. No. 9831369; April 28, 2022, No. 162, Web Doc. No. 9777974; April 7, 2022, No. 119, Web Doc. No. 9773950; September 16, 2021, No. 327, Web Doc. No. 9705650; and March 11, 2021, No. 90, Web Doc. No. 9582791).

First-level information (warning sign) "should communicate the most important information, such as the purposes of the processing, the identity of the controller, and the existence of the data subject's rights, together with information on the most significant impacts of the processing" (ECB Guidelines, cited above, para. 114). Furthermore, the signage must also contain information that may be unexpected for the data subject. This could include, for example, the transmission of data to third parties, particularly if located outside the EU, and the retention period. If this information is not provided, the data subject should be able to trust that only real-time monitoring is taking place (without any data recording or transmission to third parties) (ECB Guidelines, cited above, para. 115). First-level warning signage must contain a clear reference to the second-level information, for example, by indicating a website where the full privacy notice can be found.

Regarding the transparency of the processing, it should first be noted that the data subjects are not only the owners of the vehicles detected but also any other drivers of those vehicles, in the case of rented vehicles or vehicles otherwise granted for use to third parties, including within a family context. Furthermore, the data subjects are also all other persons who, regardless of whether the license plate number was acquired, appear in the videos, which, albeit for a short period of time, are captured by video devices placed on public roads for license plate reading purposes.

The Province has filed a copy of the first-level information (warning sign) that was allegedly provided to data subjects (see Annex XX to note XX, cited). However, this information does not comply with the requirements of Articles 5, paragraph 1, letter a), and 13 of the Regulation, as:

it does not mention the Province of Trento as a joint controller of the processing (see Article 13, paragraph 1, letter a), of the Regulation; see (see also paragraph 3.6 of this provision);

indicates a purpose for the processing ("road safety") that is completely irrelevant to the purpose allegedly pursued (see Article 13, paragraph 1, letter c), of the Regulation);

does not mention the rights of data subjects under Articles 15-22 of the Regulation (see Article 13, paragraph 2, letter b), of the Regulation);

does not provide information on the most significant impacts of the processing, particularly with regard to the automated reading of license plates of vehicles in transit (see Article 5, paragraph 1, letter a), of the Regulation);

does not refer to the data retention period of two years from collection, as this information could be unexpected for data subjects (see Article 5, paragraph 1, letter a), of the Regulation);

does not contain a clear reference to the second level of information, for example by indicating a website on which it is possible to consult the text of the extended information (see art. 5, par. 1, letter a), of the Regulation). In this regard, it is irrelevant when the Province argued in its defence that "the information sign initially used [...] was the one pro tempore suggested [by] the Guarantor [, or the one referred to in the general provision on video surveillance of 8 April 2010], which did not contain a link [to the second level information]"; this is because the indications regarding the elements that must make up the first level information were provided by the European Data Protection Board as early as XX with the aforementioned Guidelines 3/2019 on the processing of personal data through video devices, prior to the period in which the Province installed the video devices for the execution of the project (XX); as regards the circumstance that, as always stated in the defence brief, "and that "art. 13 [of the Regulation] does not include the inclusion of the aforementioned link among the essential requirements of the information, therefore it can reasonably be considered an appropriate, but not necessary, element”, it must be noted that, as a rule, the data controller must provide data subjects with all the information referred to in art. 13 of the Regulation and that the same can benefit from the possibility of providing them with a layered information, composed of a simplified first-level information and an extended second-level information, only on condition that the first-level information contains a reference to the second-level information, thus allowing data subjects, if they so wish, to acquire all the information relating to the processing (see the aforementioned Guidelines 3/2019, paragraphs 111 and 117, where it is highlighted that “data controllers may follow a tiered approach, opting for a combination of methods in order to ensure transparency […]. As regards video surveillance, the most important information must be indicated on the warning sign itself (first level), while further mandatory details may be provided with other means (second level)”, it being understood that “the first level warning signs must contain a clear reference to this second level of information”).

The Province also stated that it replaced the initial warning signs with "the current signs containing the first-level information [which] were installed between 20th and 20th, replacing the previous signs," i.e., after the Authority initiated its investigation (see Appendix 20th to the note dated 20th).

This new version of the first-level information on data processing also does not fully comply with the requirements of Article 5, paragraph 1, letter a), and Article 13 of the Regulation, as:

it does not mention the Province of Trento as a joint data controller (see Article 13, paragraph 1, letter a), of the Regulation; see also paragraph 3.6 of this provision);

It incorrectly names the Provincial Roads Service as the data controller and the Province itself as the Data Protection Officer (see Article 13, paragraph 1, letters a) and b), of the Regulation.

It fails to mention the rights of data subjects under Articles 15-22 of the Regulation (see Article 13, paragraph 2, letter b), of the Regulation).

It fails to mention the data retention period of two years from collection, as this information could be unexpected for data subjects (see Article 5, paragraph 1, letter a), of the Regulation).

Regarding the second-level information on the processing of personal data, the Province stated that "the second-level information was made available to interested parties at the Technical Offices of the Road Services Department of the Autonomous Province of Bolzano starting October 25, 2019 [...]" and that "as part of the accountability process, a revision of the text was therefore carried out, resulting in a second updated version, dated XX, made available at the same offices [...]." This version "was also made available on XX both at the offices and online at the link https://www.provincia.bz.it/turismo-mobilita/strade/manutenzione/monitoraggio-del-traffico.asp, on the institutional website of the Road Services Department of the Autonomous Province of Bolzano."

With regard to the first version of the extended information notice, provided starting from October 25, 2019, it is noted that data subjects are informed that "furthermore, there is no possibility of tracing the personal data after its conversion," a statement that does not reflect the actual characteristics of the processing, given that, as illustrated above, the data controller, acting on behalf of the Province, is in possession of the information necessary to associate the data with license plate numbers, as these are merely pseudonymized data. Likewise, for the same reasons, it is incorrect that "the processing of personal data is therefore of minimal duration," as "the alphanumeric license plate code is immediately anonymized," making it "impossible to trace the original license plate," and that "the retention period of the personal data is minimal," also considering that, as highlighted above, pseudonymized data are retained for a period of two years. These statements constitute a violation of Articles 5, paragraph 1, letter a), and 13, paragraph 1, letter c), of the GDPR. 2(a) of the Regulation.

Furthermore, paragraph 6 of the privacy policy states that "the specific functioning of the encryption system, which immediately transforms personal data into anonymous data through encryption, means that processing is not carried out other than at a purely theoretical level using software" and that, therefore, "the processing does not constitute processing that allows the data subject to exercise his or her rights." In light of the above considerations regarding the full existence of personal data processing for an extended period of two years, this incorrect statement constitutes a violation of Articles 5(1)(a) and 13(2)(b) of the Regulation.

It should also be noted that the right to object under Article 21 of the Regulation was not explicitly brought to the attention of the data subjects and was not presented clearly and separately from any other information, thus also violating Article 21(4) of the Regulation.

Furthermore, the privacy notice in question does not clearly indicate the potential recipients or categories of recipients of the personal data, as there is no reference to the provider that, as data processor, processes the personal data on behalf of the Province. This therefore violates Article 13(1)(e) of the Regulation.

More generally, it should be noted that the fact that this version of the complete second-level privacy notice was made available to data subjects only in paper form at the "Technical Offices of the Roads Department of the Autonomous Province of Bolzano," without also publishing the text on the Province's official website, cannot be considered compliant with Articles 12(1) and 13 of the Regulation. Article 12(1) of the Regulation requires that the privacy notice referred to in Article 13 of the Regulation be "easily accessible" to data subjects. In this regard, the European Data Protection Board has stated that "second-level information must be easily accessible to the data subject, for example through a comprehensive information page made available at a central point (information desk, reception, cashier's desk, etc.) or posted in an easily accessible location" ("Guidelines 3/2019 on the processing of personal data through video devices", adopted on XX, para. XX), but on the assumption that this central point is located near the area subject to video surveillance. Otherwise, when, as in the present case, the video surveillance devices are distributed over large areas and distant from the data controller's premises, the first-level information notice must necessarily link to a second-level information notice available online, so that data subjects can easily access it without having to physically visit the data controller's premises. Therefore, Articles 12, paragraph 1, and 13 of the Regulation were comprehensively violated in the period between the start date of processing and XX, the date on which the information was published online.

Regarding the information on data processing, made available to data subjects starting from XX and published on the Province's institutional website starting from XX, following the initiation of the investigation by the Authority, it should be noted that this version of the document also incorrectly states that "furthermore, there is no possibility of tracing the personal data," that "the processing of personal data is therefore of minimal duration: through a specific cryptographic function, the license plate's alphanumeric code is immediately anonymized and used for statistical purposes," that "the cryptographic function [...] ensures that it is impossible to trace the original license plate after its conversion," and that "the retention period of the personal data is minimal, according to the time technically necessary to convert the license plate of the vehicle in transit into an encrypted code (60 seconds)." These statements constitute a violation of Articles 5(1)(a) and 13(2)(a) of the Regulation.

Furthermore, paragraph 6 of the privacy policy states that "the personal data collected is immediately transformed into anonymous data for statistical purposes, which could result in derogations from the exercise of your rights as a data subject." In light of the above considerations regarding the full existence of personal data processing for an extended period of two years, this incorrect statement constitutes a violation of Articles 5(1)(a) and 13(2)(b) of the Regulation.

It should also be noted that the right to object under Article 21 of the Regulation was not explicitly brought to the attention of the data subjects and was not presented clearly and separately from any other information, thus also violating Article 21(4) of the Regulation.

Furthermore, the privacy policy in question does not clearly indicate the recipients or categories of recipients of the personal data, as there is no reference to the provider who, as data processor, processes the personal data on behalf of the Province. This constitutes a violation of Article 13, paragraph 1, letter e), of the Regulation.

The lack of transparency towards data subjects is further aggravated by the fact that, as highlighted in paragraph 3.2 above, the legal basis on which the processing was based cannot be considered qualitatively adequate to meet the requirements of the European and national data protection legal framework, as it does not contain a detailed description of the data being processed, the data subjects, and the permitted processing operations.

In light of all the above considerations, it must be concluded that:

- from the date of activation of the video devices until XX, the date on which the new signs containing the first-level information were installed, including instructions on how to access the second-level information, the Province failed to fulfill its information obligations towards the interested parties (owners/drivers of the vehicles/other filmed individuals), having therefore acted in violation of Articles 5, paragraph 1, letter a), 12, paragraph 1, and 13 of the Regulation;

- starting from XX, the date on which the new signs containing the first-level information were installed, the Province provided the interested parties (owners/drivers of the vehicles/other filmed individuals) with a first-level information that was not entirely adequate, in violation of Articles 5, paragraph 1, letter a), 13, paragraph 1, letters a) and b), and paragraph 2, letter c). b) of the Regulation, as well as an inappropriate second-level disclosure that is not entirely appropriate, in violation of Articles 5, paragraph 1, letter a), and 13, paragraphs 1, letter e), and 2, letters a) and b), and 21, paragraph 4, of the Regulation.

3.6. Joint controllership with the Autonomous Province of Trento.

Pursuant to Article 4, paragraph 1, point 7, of the Regulation, the data controller is "the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law."

When two or more controllers jointly determine the purposes and means of processing, "they shall be joint controllers" and must "determine in a transparent manner, by means of an internal agreement, their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercise of the rights of the data subject, and their respective duties to provide the information referred to in Articles 13 and 14, unless and insofar as their respective responsibilities are determined by Union or Member State law to which the controllers are subject. Such an agreement may designate a contact point for the data subjects" (Article 26(1) of the Regulation). The agreement between the joint controllers "shall adequately reflect the respective roles and the relationship of the joint controllers with the data subjects" and "the essential content of the agreement [must be] made available to the data subject" (Article 26(2) of the Regulation).

As clarified by the Court of Justice of the European Union, "a natural or legal person who influences, for purposes proper to him, the processing of personal data and is therefore involved in determining the purposes and means of such processing may be considered a controller within the meaning of Article 4, point 7, of the GDPR" (judgments C-604/22, IAB Europe, of 7 March 2024, para. 57, and C 25/17, Jehovan todistajat, of 10 July 2018, para. 68). Therefore, "pursuant to Article 26, paragraph 1, of the GDPR, 'joint controllers' exist when two or more controllers jointly determine the purposes and means of processing" (judgments C-604/22, cited above, para. 57, and C-683/21, National Visual Control Commission, dated 5 December 2023, para. 40).

The investigation revealed that the video devices in question were also located within the Autonomous Province of Trento, pursuant to an agreement signed between the two provinces.

The agreement states that the database created as part of the project "will remain the property of the two administrations," that "the monitoring system will be managed by the Province of Bolzano," that "the data flow will be accessible by both provinces," and that "the system will remain the property of the two administrations" (see Resolution of the Provincial Council of Bolzano No. 683 of August 6, 2019, and Resolution of the Provincial Council of Trento No. 1192 of August 12, 2019). The Province of Trento, which co-financed the project, therefore has the right to request the Province to receive the aggregated output data.

Based on these elements, it must be considered that, by entering into the aforementioned agreement, co-financing the project (50%) and implementing it in their respective territories in order to obtain aggregated information on traffic flows within those territories, the two provinces acted as joint data controllers.

As clarified by the European Data Protection Board, "the general criterion for the existence of joint controllership is the joint participation of two or more entities in defining the purposes and means of a processing operation. Joint participation may take the form of a joint decision taken by two or more entities [...]" ("Guidelines 07/2020 on the concepts of controller and processor under the GDPR," adopted on July 7, 2021, para. 53). To this end, "an important criterion is that the processing would not be possible without the participation of both entities, in the sense that the processing operations performed by each entity are inseparable, or inextricably linked." In this case, by co-financing the project, authorizing the Province of Bolzano to contract out the work on its own behalf, and to install the video devices in its territory, the Province of Trento enabled the overall processing of personal data within the project, which, without its collaboration with the Province of Bolzano, would not have been possible.

Although during the preliminary investigation, both Provinces maintained that all decisions regarding the purpose and means of data processing were made solely by the Province of Bolzano and that the fact that the Autonomous Province of Trento financed the project is not decisive for the existence of a joint ownership situation, it should be noted that the agreement was stipulated "for the management of the monitoring program, for the year 2019 and following, of vehicle traffic on the Dolomite passes" and that the Province of Bolzano awarded the contract for the supply, installation, and management of the monitoring system, being "authorized to sign the contract also on behalf of the Province of Trento," so much so that the Province of Bolzano "through the successful tenderer was authorized to carry out installation work of the monitoring system also on the road network managed by the Province of Trento."

Furthermore, the project's results, in terms of aggregated traffic flow data, benefit both Provinces, as they can access and use this data for their own mobility policies (see "Guidelines 07/2020 on the concepts of data controller and data processor under the GDPR," cited above, paragraph 60, which states that "[...] joint data controllership may also exist when the entities pursue closely related or complementary purposes. This may occur, for example, when there is a mutual benefit resulting from the same processing operation [...]").

In this regard, it is worth noting that, as stated by the Court of Justice of the European Union, the existence of joint responsibility does not necessarily imply equivalent responsibility for the same processing of personal data among the different entities involved. Conversely, such entities may be involved in different phases of such processing and at different levels, so that the degree of responsibility of each of them must be assessed taking into account all the relevant circumstances in the specific context (judgments C-604/22, cited above, para. 58, and C-25/17, cited above, paras. 66 and 69; see the "Guidelines 07/2020 on the concepts of controller and processor under the GDPR", cited above, para. 58). Furthermore, it is not necessary for the purposes and means of processing to be determined by written instructions or mandates from the controller. Therefore, a data controller may be considered a natural or legal person who, for purposes specific to it, influences the processing of personal data and therefore participates in determining the purposes and means of such processing (see judgments C-604/22, cited above, para. 61, and C-25/17, cited above, para. 68; cf. the "Guidelines 07/2020 on the concepts of data controller and data processor under the GDPR," cited above, paras. 57 and 58).

The fact that the Province of Trento does not have access to the personal data being processed and does not store it in its own databases is irrelevant in this regard. This is because, again recalling the case law of the Court of Justice of the European Union, "the joint responsibility of several entities for the same processing, pursuant to that provision, does not presuppose that each of them has access to the personal data in question" (judgment C-40/17, Fashion ID, of 29 July 2019, para. 69; see also judgments C 25/17, cited above, para. 69, and C 210/16, Wirtschaftsakademie Schleswig-Holstein, of 5 June 2018, para. 38; see also the "Guidelines 07/2020 on the concepts of controller and processor under the GDPR", cited above, para. 56).

In light of the foregoing considerations and in line with previous public sector measures adopted by the Authority (see measures dated January 24, 2024, Nos. 31 and 32, web doc. Nos. 9992914 and 9992986; April 13, 2023, No. 122, web doc. No. 9896412), it must be considered that, within the scope of the project in question, the two Provinces processed personal data as joint data controllers, although they did not previously enter into a joint data controllership agreement, in violation of Article 26 of the Regulation.

3.7. Data protection impact assessment.

In the event of high risks to data subjects—for example, resulting from the use of new technologies—the data controller must conduct a data protection impact assessment, in order to adopt, in particular, appropriate measures to address such risks, after consulting the Garante in advance, where applicable (see Articles 35 and 36, paragraph 1, of the Regulation).

In this case, the Province failed to demonstrate that it had prepared a data protection impact assessment before starting the processing in question.

This impact assessment was, however, required, given that a data protection impact assessment is always required when the processing involves "systematic monitoring on a large scale of a publicly accessible area" (see Article 35, paragraph 3, letter c), of the Regulation; see "Guidelines 3/2019 on the processing of personal data through video devices," cited above, paragraph 1. 10)

The obligation to conduct an impact assessment was, moreover, also considered to be integrated pursuant to Article 35, paragraph 1, of the Regulation, given that at least three of the criteria indicated by the Article 29 Working Party in the "Guidelines on data protection impact assessment and determining whether processing is likely to result in a high risk" for the purposes of Regulation (EU) 2016/679" of 4 April 2017 were met, namely systematic monitoring, processing of highly personal data (location data), and large-scale data processing (see section III).

Given that the Authority has therefore charged the Province with violating Article 35 of the Regulation, it should be noted that only in its defense brief did the Authority argue that "the impact assessment was actually conducted" and that "it was not produced earlier due to a mere oversight [...]".

While noting that, in this regard only, the Province's conduct in its relations with the Authority cannot be considered compliant with the principle of "accountability" (Article 5, paragraph 2, of the Regulation), it should nevertheless be noted that the documentation submitted in the case file (see attachments to note XX) consists of two documents, both titled "Data Protection Impact Assessment relating to the Vehicle Traffic Flow Detection System on the Dolomite Passes," which merely contain temporal references ("XX" and "XX") but lack a specific date (for example, through acquisition into the Authority's IT system). In any case, these documents do not meet the substantive requirements set out in art. 35 of the Regulation, since an assessment has not been carried out of the probability and severity of the risks arising in theory from the processing, of the effectiveness of the technical and organizational measures envisaged for the purpose of mitigating such risks (see art. 35, paragraph 7, letters c) and d) of the Regulation) and of the overall level of risk remaining following the aforementioned measures (see art. 36, paragraph 1, of the Regulation; see the “Guidelines on data protection impact assessment and determining whether processing is likely to result in a high risk” for the purposes of Regulation (EU) 2016/679” of the Article 29 Working Party, adopted on 4 October 2017 - WP 248 rev.01, endorsed by the European Data Protection Board with “Endorsement 1/2018” of 25 May 2018, which highlights that “whenever the data controller is unable to find adequate measures sufficient to reduce the risks to an acceptable level (i.e. residual risks remain high) it is necessary to consult the supervisory authority”); see also the “Annex 2 - Criteria for an acceptable data protection impact assessment” of the same Guidelines, which requires that in the impact assessment “the risks to the rights and freedoms of data subjects are managed (Article 35, paragraph 7, letter c))”, determining “the origin, nature, particularity and severity of the risks (see recital 84) or, more specifically, for each risk (illegitimate access, unwanted modification and disappearance of data) […] from the perspective of data subjects; the sources of risk are considered (recital 90)”, identifying “the potential impacts on the rights and freedoms of data subjects in case of events including illegitimate access, unwanted modification and disappearance of data”, as well as “threats that could lead to illegitimate access, unwanted modification and disappearance of data”, estimating “the likelihood and severity (recital 90)”, and then determining “the measures envisaged to manage such risks (Article 35, paragraph 7, letter c)”. 7, letter d) and recital 90).

It is therefore confirmed that the Province acted in violation of Article 35 of the Regulation.

4. Conclusions.

In light of the above assessments, it is noted that the statements made by the data controller during the investigation – the veracity of which may be held accountable pursuant to Article 168 of the Code – although worthy of consideration, do not overcome the concerns notified by the Office with the document initiating the proceedings and are insufficient to allow the dismissal of the present proceedings. Furthermore, none of the cases provided for by Article 11 of the Garante Regulation No. 1/2019 apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data carried out by the Province is found to be unlawful, having carried out processing of personal data via video devices in violation of Articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulation, as well as Article 2-ter of the Code.

Given that the violation of the aforementioned provisions occurred as a result of a single act (the same processing or related processing), Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction does not exceed the amount specified for the most serious violation. Considering that, in the case at hand, the most serious violations, relating to Articles 5, 6, 12, 13, and 21 of the Regulation, as well as Article 2-ter of the Code, are subject to the sanction provided for in Article 83, paragraph 5, of the Regulation, as also referred to in Article 83, paragraph 3, of the Regulation. 166, paragraph 2, of the Code, the total amount of the fine is up to €20,000,000.

5. Corrective measures (Article 58, paragraph 2, letters d) and f), of the Regulation).

Given that the documentation in the file only shows evidence of the deactivation of video devices located within the Province of Trento, at the express request of the latter (see the Province's note of 20th June, file no. XX, which confirmed this circumstance) and given the unlawful processing, it is necessary to order the Province, pursuant to Article 58, paragraph 2, letter d), of the Regulation, to promptly delete the personal data collected as part of the project, as well as to require the Province, pursuant to Article 58, paragraph 2, letter f), to: f) of the Regulation, the prohibition of any further processing using video devices installed on its own territory or, pursuant to agreements or other contractual arrangements, on the territory of other public entities and used in the context of the same project.

Pursuant to Articles 58, paragraph 1, letter a) of the Regulation and 157 of the Code, the Province shall notify this Authority, providing adequately documented feedback, within thirty days of notification of this order, of the steps taken to implement the above order pursuant to the aforementioned Article 58, paragraph 2, letters d) and f) of the Regulation.

6. Adoption of the injunction order for the application of the administrative fine and additional penalties (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel shall adopt the injunction order, by which it shall also order the publication of the injunction, in full or in extract, on the Garante's website pursuant to Article 166, paragraph 7, of the Code, as an additional administrative sanction" (Article 16, paragraph 1, of the Garante's Regulation No. 1/2019).

In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the aforementioned provisions is subject to the application of the pecuniary administrative sanction provided for in Article 83, paragraph 1, of the Code. 5 of the Regulation.

The aforementioned administrative fine imposed, based on the circumstances of each individual case, must be determined in amount, taking into account the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

Although the Province retained data relating to vehicles in transit for an extended period of time, thus theoretically being able to obtain sensitive information regarding the movements of a large number of data subjects within the observed territory, it did not process such data within the administrative proceedings under its jurisdiction; the Authority therefore acted with the intent to serve the public interest, albeit negligently, in the mistaken belief that there was an appropriate legal framework for the sector to support the initiative undertaken or that the information collected did not constitute personal data (Article 83, paragraph 2, letters a) and b), of the Regulation);

The Province has adopted measures to pseudonymize the data processed, thus mitigating the risk of data subjects being identified by third parties (Article 83, paragraph 2, letter a), of the Regulation);

The processing operations carried out, while potentially affecting the use of public spaces by data subjects, especially in the absence of adequate information on data processing, have not had detrimental consequences for their legal rights, as the video devices were not used to make decisions concerning them (Article 83, paragraph 2, letter a), of the Regulation);

Although inadequately, the Province had nevertheless posted information signs regarding the use of video devices in the affected areas (Article 83, paragraph 2, letter a), of the Regulation);

The processing did not involve special categories of data as defined in Article 83, paragraph 2, letter a), of the Regulation. 9 of the Regulation (see Article 83, paragraph 2, letter g), of the Regulation),

In this case, the severity of the violation committed by the data controller is considered to be medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative pecuniary sanctions under the GDPR," dated May 24, 2023, point 60).

That said, considering that the data controller is a public entity of provincial importance, it is believed that, for the purposes of quantifying the sanction, the following circumstances should be taken into account:

There are no previous relevant violations committed by the Province in the same context (Article 83, paragraph 2, letter e), of the Regulation);

The Province cooperated effectively with the Authority during the investigation (Article 83, paragraph 2, letter f), of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to determine the amount of the pecuniary sanction at €32,000 (thirty-two thousand) for the violation of Articles 5, paragraph 1, letters a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulation, as well as Article 2-ter of the Code, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

It is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor no. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the processing involved data relating to vehicles transiting the area affected by the project, information of particularly sensitive nature. Although the investigation revealed that the Province had not initiated any proceedings against individuals identified by license plate numbers, their analysis may theoretically yield information regarding the data subjects' movements within the said area. Furthermore, the processing occurred over an extended period of time.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW WITH ALL THE FOREGOING, THE GUARANTOR

declares, pursuant to Article 57, paragraph 1, letter f), of the Regulation, the unlawfulness of the processing carried out by the Autonomous Province of Bolzano for violation of Articles 5, paragraph 1, letter e), and a) and e), 6, paragraph 1, letters c) and e), and paragraphs 2 and 3, 12, paragraph 1, 13, 21, paragraph 4, 26, and 35 of the Regulations, as well as 2-ter of the Code, within the time limits set forth in the reasons;

ORDERS

the Autonomous Province of Bolzano, represented by its legal representative pro tempore, with registered office at Piazza Silvius Magnago 1 - 39100 Bolzano (BZ), Tax Code 00390090215, to pay the sum of €32,000 (thirty-two thousand) as an administrative fine for the violations indicated in the reasons. It is hereby stated that the offender, pursuant to art. 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

- the aforementioned Province, in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €32,000 (thirty-two thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

- the aforementioned Province, pursuant to Article 58, paragraph 2, letters d) and f), of the Regulation, to immediately delete the personal data collected in the context of the project in question, and imposes a ban on any further processing by means of video devices installed on its territory or, pursuant to agreements or other contractual arrangements, on the territory of other public entities and employed in the context of the same project. It also provides the Guarantor, within the same deadline, pursuant to Articles 58, paragraph 2, letters d) and f), of the Regulation. 1, letter a), of the Regulation and Article 157 of the Code, an adequately documented report on the initiatives undertaken to implement the order;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, the publication of the injunction order on the Italian Data Protection Authority's website;

- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Italian Data Protection Authority Regulation No. 1/2019, the publication of this provision on the Authority's website;

- pursuant to Article 17 of the Italian Data Protection Authority Regulation No. 1/2019, the recording of the violations and measures adopted in accordance with Article 58, paragraph 2, of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, of the Italian Data Protection Authority's internal register. 1, letter u) of the Regulations.

Pursuant to Articles 78 of the Regulations, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this decision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the decision itself, or within sixty days if the appellant resides abroad.

Rome, September 25, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Scorza

THE SECRETARY GENERAL
Fanizza