Garante per la protezione dei dati personali (Italy) - 10209089

From GDPRhub
Garante per la protezione dei dati personali - 10209089
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(1)(a) GDPR
Article 6(1)(c) GDPR
Article 6(1)(e) GDPR
Article 6(2) GDPR
Article 6(3) GDPR
Article 9(1) GDPR
Article 9(2)(g) GDPR
Type: Complaint
Outcome: Upheld
Started:
Decided: 04.12.2025
Published:
Fine: 1000 EUR
Parties: n/a
National Case Number/Name: 10209089
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: lde

The DPA fined a school €1,000 for unlawfully disclosing students’ personal data by sending an email about vaccination obligations in which all recipients’ email addresses were visible. The DPA held that the indication that students had not received specific vaccinations constituted unlawful processing of sensitive data.

English Summary

Facts

The controller is a public high school in Northern Italy. In order to remind students of their vaccination obligations, the school sent an email to approximately 40 students under the age of 16 who had not complied with the vaccination requirements set by the healthcare system. The email contained a list of vaccines that the recipients had not received within the prescribed time limits.

The email was sent in such a way that all recipients’ email addresses were visible to each other, thus allowing all addressees to identify the other students concerned. As a result, personal data relating to health were disclosed to a broader group of data subjects.

Following the incident, the controller notified the personal data breach to the DPA within 24 hours, stating that the disclosure was the result of a genuine error and that there was no intent to unlawfully share personal data. The controller further argued that no actual health data had been disclosed, as the email merely contained a list of vaccines and did not explicitly state any medical conditions.

One of the affected data subjects subsequently lodged a complaint with the DPA.

Holding

The DPA imposed an administrative fine of €1,000 on the controller and held that the high school unlawfully disclosed students’ personal and health data by sending an email in which all recipients’ email addresses were visible to one another.

The DPA held that the disclosure of recipients’ email addresses constituted unlawful processing of personal data, irrespective of the content of the email. The authority emphasised that email addresses allow the identification of data subjects and should not have been disclosed to third parties without an appropriate legal basis.

Furthermore, the DPA rejected the controller’s argument that no health data had been processed. It found that information indicating whether a person has or has not received specific vaccinations clearly constitutes health data and therefore falls within the scope of special categories of personal data under Article 9 GDPR.

The authority concluded that the controller lacked a valid legal basis for both the disclosure of personal data under Article 6 GDPR and the processing of health data under Article 9 GDPR. In particular, the conditions for processing special category data were not met, and the processing failed to comply with the principle of lawfulness.

As a result, the DPA found infringements of Articles 5(1)(a), 6(1)(c) and (e), 9(1) and 9(2)(g) GDPR and, on top of the fine, ordered the controller to ensure future compliance with data protection requirements.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10209089]

Measure of December 4, 2025

Register of Measures
no. 732 of December 4, 2025

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

SEEN Legislative Decree 30 June 2003, n. 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Pasquale Stanzione;

WHEREAS

1. The complaint.

In a complaint filed with the Authority, Mr. XX and Ms. XX, through their lawyer, claimed that the Roverbella Comprehensive School had sent, from the institutional email address […], an email with the subject line "Vaccination requirements for pupils under 16 years of age – REMINDER" to several interested parties, including the complainant, leaving the email addresses of the various recipients of the message unambiguously.

2. The investigation.

With a note dated XX (ref. No. XX) In response to the Authority's request for information, the Institute stated, in particular, that:

"The communication "Vaccination requirements for students under 16 years of age – REMINDER," fulfilling a duty related to the exercise of public authority pursuant to Law No. 119 of July 31, 2017, was processed, as is customary, maintaining the confidentiality of the various recipients - ref. protocol XX of XX

"The sending of the communication in question, by an administrative assistant, was carried out by leaving the recipients unencrypted due to a mere material error and without any intention";

"It is neither the practice nor the custom of this school to send communications to multiple recipients unencrypted";

"All communications, whether or not containing sensitive data, are sent to multiple recipients using the BCC (blind carbon copy) function";

"On XX, a personal data breach notification was issued pursuant to Article 33 of Regulation (EU) 2016/679 – File XX - Protocol XX of XX – and the related communication was made to the data subjects."

"In order to improve IT security measures, the software company that provides the email management program was asked to add a warning whenever multiple recipients are entered in an email, in order to draw the operator's attention and avoid similar errors."

"All employees are compliant with privacy training pursuant to Articles 29 and 32 of Regulation (EU) 2016/679. Furthermore, internal training was conducted on XX, and specific privacy and cybersecurity training was scheduled for XX."

Based on the information acquired, the Office notified the Institute, as data controller, with a note dated XX (Protocol No. XX), pursuant to Article 33 of Regulation (EU) 2016/679. 166, paragraph 5, of the Code, the initiation of proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, concerning the alleged violations of Articles 5, paragraph 1, letters a) and c), 6, and 9 of the Regulation, and Articles 2-ter and 2-sexies of the Code, inviting the aforementioned data controller to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The Institute submitted its defense briefs, with note dated XX (ref. no. XX), stating, in particular, that:

- "It is noted that the contested email expressly refers in its text to the previous email dated XX, a copy of which has been attached (...), demonstrating that, even in this specific case, the Institute had always strictly complied with the legislation on the confidentiality of personal data, including the email addresses of individual recipients";

- "the error was entirely accidental, with no underlying intention or interest that could lead to the presumption of malicious intent in the violation";

- "furthermore, there are no previous incidents of violation reported by the interested parties to the same school or through complaints to the Data Protection Authority. Moreover, in this case, the notification of the violation to the Authority pursuant to Article 33 of the GDPR was made on XX (ref. XX), i.e., the day after receiving the formal notice from the lawyer of the parents involved";

- "It is not believed that in this case, data relating to the health of data subjects, or sensitive data, were unlawfully disclosed. The text of the reminder letter, in fact, contains an absolutely neutral description, devoid of any indication of the presence or absence of vaccines."

- "The reminder in question simply informed families that, in compliance with the regulatory requirement, the document required by the ATS was missing, without being able to even indirectly trace the lack of certain vaccines, or even identify which vaccinations might have been missed."

- "Therefore, this is a reminder regarding a bureaucratic requirement required by law, which, at present, appears not to have been complied with by the parents affected by the communication."

- "Therefore, it is not believed that personal data relating to the health of students was disclosed, an interpretation apparently shared by the complaining parents themselves, who highlighted and complained about the disclosure of their email addresses to unauthorized third parties."

- "The School intends to renew specific training courses on personal data protection for its employees. Furthermore, in order to improve IT security measures, the software company that provides the email management program was asked to add a warning whenever multiple recipients are entered in an email (as is the case in the case of the missing attachment mentioned in the text), in order to draw the operator's attention and prevent similar errors from occurring in the future."

3. Applicable legislation.

3.1 The regulatory framework.

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation") defines "personal data" as "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person" and "data concerning health" as "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about the health of that natural person" (Article 4, points 1 and 15, of the Regulation).

The data protection framework established by the Regulation provides that the processing of personal data by public bodies, such as the Institute, is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

The legal basis for such processing must be established by Union or Member State law, which must pursue "an objective of public interest [and be] proportionate to the objective" (Article 6, paragraph 3, of the Regulation).

In this context, it is established that "Member States may maintain or introduce more specific provisions to adapt the application of the provisions of the […] Regulation with regard to processing in accordance with paragraph 1(c) and (e), by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing […]" (Article 6, paragraph 2, of the Regulation).

The Code has established that "the legal basis provided for in Article 6, paragraph 3, point (b) of the Regulation shall be a law or regulation or general administrative act" (Article 2-ter, paragraph 1).

Specifically, processing operations consisting of the "dissemination" and "communication" of personal data are permitted only when required by law, regulation, or general administrative provisions (Article 2-ter, paragraph 3 of the Code).

With regard to special categories of personal data, processing is generally permitted where "necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection, and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in national legal systems, by laws, regulations, or general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest ground, as well as the suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

The data controller is in any case required to comply with data protection principles, including "lawfulness, fairness, and transparency," according to which data must be processed lawfully, fairly, and transparently with respect to the data subject (Article 5, paragraph 1, letter a) of the Regulation).

3.2 The processing of personal data carried out by the Institute.

From the investigation carried out, based on the information acquired and the facts emerging from the investigation, the notification of personal data breach submitted by the Institute pursuant to Article 33 of the Regulation, and subsequent assessments by this Department, it is established that the Institute sent an email from its institutional email address, with the subject line "Vaccination requirements for students under 16 years of age – REMINDER," to approximately thirty-seven data subjects, including the complainant, leaving the email addresses of the various recipients of the message undisclosed.

As a preliminary point, it should be noted that the Guarantor has already had occasion to clarify in the past that sending emails "with an unencrypted mailing list constitutes a de facto communication of personal data (those relating to other email addresses) to third parties, i.e., to the multiple recipients" of the email. It is therefore necessary to keep the email addresses used for sending emails confidential, perhaps by using the "Bcc" function (i.e., "blind carbon copy" forwarding) (See point 5 of the "Guidelines on Promotional Activities and the Fight against Spam" of July 4, 2013, available on the website www.garanteprivacy.it, web doc. no. 2542348).

It should also be noted that, pursuant to Article 4, paragraph 1, no. 15 of the Regulation, "health data" is considered "personal data relating to the physical and mental health of a natural person, including the provision of health care services, which reveal information on that natural person's state of health."

Considering the definition of personal data and health data (Article 4, paragraphs 1 and 15, of the Regulation), it is believed that the reference to vaccination requirements pursuant to Law no. 101 of July 31, 2017, is appropriate. 119, in itself represents information relating to the health status of the students to whom such information is referred.

With regard to the specific case, although, as stated, the communication in question occurred due to a mere material error, the communication of personal data, including health-related data, appears to have occurred without a suitable basis for lawfulness (see Provision No. 403 of July 4, 2024, web doc. No. 10039592).

It should be noted that, as a result of the aforementioned communication and its specific procedures (the relevant addresses were entered clearly in the "recipients" field rather than in the "blind copy" field), each of the recipients of the aforementioned communication was made aware, in addition to the email addresses of the other recipients of the email, of the fact that their children were not up to date with their vaccination requirements and that they should present themselves at their local vaccination center to regularize their vaccination status and request a copy. Certificate.

In light of the foregoing considerations, the school, by sending reminders regarding vaccination requirements for students under 16 years of age using the aforementioned methods and by clearly indicating the email addresses of the recipients of the reminders and of the complainant, has given rise to a "communication" of personal data and special categories of personal data, in violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

4. Conclusions.

In light of the above considerations, it is found that the statements made by the school, as data controller, during the investigation – the veracity of which is questionable may be held accountable pursuant to Article 168 of the Code, although worthy of consideration, do not overcome the findings notified by the Office with the document initiating the proceedings and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Regulation of the Guarantor No. 1/2019, since none of the cases provided for in Article 11 referred to therein apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data carried out by the Institute is found to be unlawful, in violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter e). bb) of the Code).

Violation of the aforementioned provisions gives rise to the administrative sanction provided for in Article 83, paragraph 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation itself, as also referred to in Article 166, paragraph 2, of the Code.

Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the (other) (corrective) measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the Board (of the Guarantor) shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019).

Given that the Institute's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Considering that, in this case, all the violations found – Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation and 2-ter, paragraphs 1 and 3, and 2 sexies, paragraphs 1 and 2, letter bb) of the Code – are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000 (twenty million/00).

The aforementioned administrative pecuniary sanction imposed, depending on the circumstances of each individual case, must be determined in amount taking into due consideration the elements provided for by Article 83, paragraph 2, of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the breach, it should be noted that the data were disclosed to approximately thirty-six recipients (see Article 83, paragraph 2, letter a), of the Regulation);

- with specific regard to the subjective nature of the breach, it occurred due to a mere material error resulting from sending a bulk email to multiple recipients without using the "BCC" option (Article 83, paragraph 2, letter b), of the Regulation);

- with regard to the categories of personal data disclosed, this includes special categories of data (Article 83, paragraph 2, letter g), of the Regulation).

In light of this specific circumstance, it is considered that, in this case, the level of severity of the breach committed by the data controller is medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of May 24, 2023, point 60).

While noting that the data controller is an educational institution and, therefore, a small entity, the following mitigating circumstances must also be considered:

- there are no previous relevant violations committed by the data controller (Article 83, paragraph 2, letter e), of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83, paragraph 2, letter f), of the Regulation);

- the institution has committed to providing training courses on personal data protection to teachers and school staff (Article 83, paragraph 2, letter k), of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to set the fine at €1,000.00 (one thousand/00) for violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, this chapter containing the injunction order must be published on the Guarantor's website.

This is in consideration of the specific circumstances of this specific case, regarding the communication to the various families of the interested parties of information regarding the health status of several minor pupils, and therefore particularly vulnerable individuals.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW CONSIDERING ALL THE ABOVE, THE GUARANTOR

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Roverbella State Comprehensive School in the terms set out in the grounds is unlawful, due to the violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1 and 2 of the Regulation. 1, 2, letter g), and 4 of the Regulations and 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code);

ORDERS

pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulations, as well as Article 166 of the Code, the Istituto Comprensivo Statale di Roverbella, located at Via Trento Trieste, no. 2 - 46048 Roverbella (MN), Fiscal Code 93034770201, to pay the total sum of €1,000.00 (one thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine;

ORDERS

the Roverbella Comprehensive Institute (Mantua):

- to pay the total sum of €1,000.00 (one thousand/00) in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, the publication of the injunction order on the Guarantor's website;

- Pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Italian Data Protection Authority Regulation No. 1/2019, the publication of this provision on the Italian Data Protection Authority's website;

- Pursuant to Article 17 of the Italian Data Protection Authority Regulation No. 1/2019, the recording of this provision in the Authority's internal register, as required by Article 57, paragraph 1, letter u), of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, December 4, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Montuori

[web doc. no. 10209089]

Measure of December 4, 2025

Register of Measures
no. 732 of December 4, 2025

THE DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia and Guido Scorza, members, and Dr. Luigi Montuori, Secretary General;

HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, "General Data Protection Regulation" (hereinafter, the "Regulation");

HAVING REGARD to Legislative Decree no. 196 of 30 June 2003 196 of 30 April 2019, containing the "Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Code");

CONSIDERING Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved with Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and on www.gpdp.it, web doc. No. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority No. 1/2019");

Having seen the documentation on file;

Having seen the observations made by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000 on the organization and functioning of the Office of the Guarantor for the Protection of Personal Data, web doc. No. 1098801;

Rapporteur: Professor Pasquale Stanzione;

WHEREAS

1. The complaint.

In a complaint filed with the Authority, Mr. XX and Ms. XX, through their lawyer, claimed that the Roverbella Comprehensive School had sent, from the institutional email address […], an email with the subject line "Vaccination requirements for pupils under 16 years of age – REMINDER" to several interested parties, including the complainant, leaving the email addresses of the various recipients of the message unambiguously.

2. The investigation.

With a note dated XX (ref. No. XX) In response to the Authority's request for information, the Institute stated, in particular, that:

"The communication "Vaccination requirements for students under 16 years of age – REMINDER," fulfilling a duty related to the exercise of public authority pursuant to Law No. 119 of July 31, 2017, was processed, as is customary, maintaining the confidentiality of the various recipients - ref. protocol XX of XX

"The sending of the communication in question, by an administrative assistant, was carried out by leaving the recipients unencrypted due to a mere material error and without any intention";

"It is neither the practice nor the custom of this school to send communications to multiple recipients unencrypted";

"All communications, whether or not containing sensitive data, are sent to multiple recipients using the BCC (blind carbon copy) function";

"On XX, a personal data breach notification was issued pursuant to Article 33 of Regulation (EU) 2016/679 – File XX - Protocol XX of XX – and the related communication was made to the data subjects."

"In order to improve IT security measures, the software company that provides the email management program was asked to add a warning whenever multiple recipients are entered in an email, in order to draw the operator's attention and avoid similar errors."

"All employees are compliant with privacy training pursuant to Articles 29 and 32 of Regulation (EU) 2016/679. Furthermore, internal training was conducted on XX, and specific privacy and cybersecurity training was scheduled for XX."

Based on the information acquired, the Office notified the Institute, as data controller, with a note dated XX (Protocol No. XX), pursuant to Article 33 of Regulation (EU) 2016/679. 166, paragraph 5, of the Code, the initiation of proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation, concerning the alleged violations of Articles 5, paragraph 1, letters a) and c), 6, and 9 of the Regulation, and Articles 2-ter and 2-sexies of the Code, inviting the aforementioned data controller to submit written defenses or documents to the Guarantor or to request a hearing with the Authority (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The Institute submitted its defense briefs, with note dated XX (ref. no. XX), stating, in particular, that:

- "It is noted that the contested email expressly refers in its text to the previous email dated XX, a copy of which has been attached (...), demonstrating that, even in this specific case, the Institute had always strictly complied with the legislation on the confidentiality of personal data, including the email addresses of individual recipients";

- "the error was entirely accidental, with no underlying intention or interest that could lead to the presumption of malicious intent in the violation";

- "furthermore, there are no previous incidents of violation reported by the interested parties to the same school or through complaints to the Data Protection Authority. Moreover, in this case, the notification of the violation to the Authority pursuant to Article 33 of the GDPR was made on XX (ref. XX), i.e., the day after receiving the formal notice from the lawyer of the parents involved";

- "It is not believed that in this case, data relating to the health of data subjects, or sensitive data, were unlawfully disclosed. The text of the reminder letter, in fact, contains an absolutely neutral description, devoid of any indication of the presence or absence of vaccines."

- "The reminder in question simply informed families that, in compliance with the regulatory requirement, the document required by the ATS was missing, without being able to even indirectly trace the lack of certain vaccines, or even identify which vaccinations might have been missed."

- "Therefore, this is a reminder regarding a bureaucratic requirement required by law, which, at present, appears not to have been complied with by the parents affected by the communication."

- "Therefore, it is not believed that personal data relating to the health of students was disclosed, an interpretation apparently shared by the complaining parents themselves, who highlighted and complained about the disclosure of their email addresses to unauthorized third parties."

- "The School intends to renew specific training courses on personal data protection for its staff. Furthermore, in order to improve IT security measures, the software company that provides the email management program was asked to add a warning whenever multiple recipients are entered in an email (as is the case in the case of the missing attachment mentioned in the text). This is intended to draw the operator's attention and prevent similar errors from occurring in the future."

3. Applicable legislation.

3.1 The regulatory framework.

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation") defines "personal data" as "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person" and "data concerning health" as "personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about the health of that natural person" (Article 4, points 1 and 15, of the Regulation).

The data protection framework established by the Regulation provides that the processing of personal data by public bodies, such as the Institute, is lawful if necessary "for compliance with a legal obligation to which the controller is subject" or "for the performance of a task carried out in the public interest or in the exercise of official authority" (Article 6, paragraph 1, letters c) and e), paragraphs 2 and 3 of the Regulation; Article 2-ter of the Code.

The legal basis for such processing must be established by Union or Member State law, which must pursue "an objective of public interest [and be] proportionate to the objective" (Article 6, paragraph 3, of the Regulation).

In this context, it is established that "Member States may maintain or introduce more specific provisions to adapt the application of the provisions of the […] Regulation with regard to processing in accordance with paragraph 1(c) and (e), by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing […]" (Article 6, paragraph 2, of the Regulation).

The Code has established that "the legal basis referred to in Article 6, paragraph 3, point (b) of the Regulation shall be a law or regulation or general administrative act" (Article 2-ter, paragraph 1).

In particular, processing operations consisting of the "dissemination" and "communication" of personal data are permitted only when provided for by a law, regulation, or general administrative act (Article 2-ter, paragraph 3 of the Code).

With regard to special categories of personal data, processing is generally permitted where "necessary for reasons of substantial public interest, on the basis of Union or Member State law, which must be proportionate to the aim pursued, respect the essence of the right to data protection, and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 9, paragraph 2, letter g), of the Regulation), provided that the processing is "provided for by European Union law or, in national legal systems, by laws, regulations, or general administrative acts specifying the types of data that may be processed, the operations that may be performed, the substantial public interest ground, as well as the suitable and specific measures to safeguard the fundamental rights and the interests of the data subject" (Article 2-sexies, paragraph 1, of the Code).

The data controller is in any case required to comply with data protection principles, including "lawfulness, fairness, and transparency," according to which data must be processed lawfully, fairly, and transparently with respect to the data subject (Article 5, paragraph 1, letter a) of the Regulation).

3.2 The processing of personal data carried out by the Institute.

From the investigation carried out, based on the information acquired and the facts emerging from the investigation, the notification of personal data breach submitted by the Institute pursuant to Article 33 of the Regulation, and subsequent assessments by this Department, it is established that the Institute sent an email from its institutional email address, with the subject line "Vaccination requirements for students under 16 years of age – REMINDER," to approximately thirty-seven data subjects, including the complainant, leaving the email addresses of the various recipients of the message undisclosed.

As a preliminary point, it should be noted that the Guarantor has already had occasion to clarify in the past that sending emails "with an unencrypted mailing list constitutes a de facto communication of personal data (those relating to other email addresses) to third parties, i.e., to the multiple recipients" of the email. It is therefore necessary to keep the email addresses used for sending emails confidential, perhaps by using the "Bcc" function (i.e., "blind carbon copy" forwarding) (See point 5 of the "Guidelines on Promotional Activities and the Fight against Spam" of July 4, 2013, available on the website www.garanteprivacy.it, web doc. no. 2542348).

It should also be noted that, pursuant to Article 4, paragraph 1, no. 15 of the Regulation, "health data" is considered "personal data relating to the physical and mental health of a natural person, including the provision of health care services, which reveal information on that natural person's state of health."

Considering the definition of personal data and health data (Article 4, paragraphs 1 and 15, of the Regulation), it is believed that the reference to vaccination requirements pursuant to Law no. 101 of July 31, 2017, is appropriate. 119, in itself represents information relating to the health status of the students to whom such information is referred.

With regard to the specific case, although, as stated, the communication in question occurred due to a mere material error, the communication of personal data, including health-related data, appears to have occurred without a suitable basis for lawfulness (see Provision No. 403 of July 4, 2024, web doc. No. 10039592).

It should be noted that, as a result of the aforementioned communication and its specific procedures (the relevant addresses were entered clearly in the "recipients" field rather than in the "blind copy" field), each of the recipients of the aforementioned communication was made aware, in addition to the email addresses of the other recipients of the email, of the fact that their children were not up to date with their vaccination requirements and that they should present themselves at their local vaccination center to regularize their vaccination status and request a copy. Certificate.

In light of the foregoing considerations, the school, by sending reminders regarding vaccination requirements for students under 16 years of age using the aforementioned methods and by clearly indicating the email addresses of the recipients of the reminders and of the complainant, has given rise to a "communication" of personal data and special categories of personal data, in violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code.

4. Conclusions.

In light of the above considerations, it is found that the statements made by the school, as data controller, during the investigation – the veracity of which is questionable may be held accountable pursuant to Article 168 of the Code, although worthy of consideration, do not overcome the findings notified by the Office with the document initiating the proceedings and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Regulation of the Guarantor No. 1/2019, since none of the cases provided for in Article 11 referred to therein apply.

Therefore, the Office's preliminary assessments are confirmed and the processing of personal data carried out by the Institute is found to be unlawful, in violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter e). bb) of the Code).

Violation of the aforementioned provisions gives rise to the administrative sanction provided for in Article 83, paragraph 5, of the Regulation, pursuant to Articles 58, paragraph 2, letter i), and 83, paragraph 3, of the Regulation itself, as also referred to in Article 166, paragraph 2, of the Code.

Considering, in any case, that the conduct has exhausted its effects, the conditions for the adoption of further corrective measures pursuant to Article 58, paragraph 2, of the Regulation are no longer met.

5. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letters i and 83 of the Regulation; Article 166, paragraph 7, of the Code).

The Guarantor, pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulation as well as Article 166 of the Code, has the power to "impose a pecuniary administrative sanction pursuant to Article 83, in addition to the (other) (corrective) measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the Board (of the Guarantor) shall adopt the injunction order, by which it also orders the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019).

Given that the Institute's violation of the above provisions occurred as a result of a single act, Article 83, paragraph 3, of the Regulation applies, pursuant to which the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the most serious violation. Considering that, in the specific case, all the violations ascertained – Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3 and 9, paragraphs 1, 2, letter g) and 4 of the Regulation and 2-ter, paragraphs 1 and 3, and 2 sexies, paragraphs 1 and 2, letter bb) of the Code) – are subject to the sanction provided for by Article 83, paragraph 5, of the Regulation, as also referred to in Article 166, paragraph 2, of the Code, the total amount of the sanction is to be quantified up to €20,000,000 (twenty million/00).

The aforementioned administrative fine imposed, based on the circumstances of each individual case, must be determined in amount, taking due account of the factors set forth in Article 83, paragraph 2, of the Regulation.

Considering that:

- with specific regard to the nature, severity, and duration of the violation, it must be considered that the data were communicated to approximately thirty-six recipients (see Article 83, paragraph 2, letter a), of the Regulation);

- with specific regard to the subjective nature of the violation, it occurred due to a mere material error resulting from the sending of a bulk email to multiple recipients, without using the "BCC" option (Article 83, paragraph 2, letter b), of the Regulation);

- with regard to the categories of personal data communicated, this includes special categories of data (Article 83, paragraph 2, letter g), of the Regulation).

In light of this specific circumstance, it is considered that, in this case, the severity of the breach committed by the data controller is medium (see European Data Protection Board, "Guidelines 4/2022 on the calculation of administrative fines under the GDPR" of May 24, 2023, point 60).

While noting that the data controller is an educational institution and, therefore, a small entity, the following mitigating circumstances must also be considered:

- there are no previous relevant breaches committed by the data controller (Article 83(2)(e) of the Regulation);

- the degree of cooperation demonstrated by the data controller with the supervisory authority (Article 83(2)(f) of the Regulation);

- the institution has committed to providing training on personal data protection to teachers and school staff (Article 83(2)(k) of the Regulation).

Based on the above factors, assessed as a whole, it is deemed appropriate to set the fine at €1,000.00 (one thousand/00) for violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter g), and 4 of the Regulation, and Article 2-ter, paragraphs 1 and 3, and Article 2-sexies, paragraphs 1 and 2, letter bb) of the Code, as an administrative fine deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive.

In this context, it is also considered that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor no. 1/2019, this chapter containing the injunction order should be published on the Authority's website.

This is in consideration of the specific circumstances of this specific case, regarding the communication to the various families of the interested parties of information regarding the health status of several minor students, and therefore particularly vulnerable individuals.

Finally, it is noted that the conditions set out in Article 17 of Regulation No. 1/2019 are met.

NOW CONSIDERING ALL THE ABOVE, THE AUTHORITY

declares, pursuant to Articles 57, paragraph 1, letter f), and 83 of the Regulation, that the processing carried out by the Roverbella State Comprehensive School in the terms set out in the grounds is unlawful, due to the violation of Articles 5, paragraph 1, letter a), 6, paragraphs 1, letter c) and e), 2 and 3, and 9, paragraphs 1, 2, letter e). g) and 4 of the Regulations and 2-ter, paragraphs 1 and 3, and 2-sexies, paragraphs 1 and 2, letter bb) of the Code);

ORDERS

pursuant to Articles 58, paragraph 2, letter i) and 83 of the Regulations, as well as Article 166 of the Code, the Istituto Comprensivo Statale di Roverbella, located at Via Trento Trieste, no. 2 - 46048 Roverbella (MN), Fiscal Code 93034770201, to pay the total sum of €1,000.00 (one thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half of the imposed fine;

ORDER

the Roverbella Comprehensive Institute (Mantua):

- to pay the total sum of €1,000.00 (one thousand/00) in the event of failure to resolve the dispute pursuant to Article 166, paragraph 8, of the Code, according to the procedures indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981;

ORDERS

- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019, the publication of the injunction order on the Guarantor's website;

- pursuant to Article 154-bis, paragraph 3 of the Code and Article 37 of the Guarantor Regulation No. 1/2019, the publication of this provision on the Authority's website;

- pursuant to Article 17 of the Authority's Regulation No. 1/2019, the annotation of this provision in the Authority's internal register, as provided for by Article 57, paragraph 1, letter u), of the Regulation.

Pursuant to Articles 78 of the Regulation, 152 of the Code, and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad.

Rome, December 4, 2025

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Montuori