Details:
Summary | The Italian DPA has imposed a fine of EUR 6,000 on ‘Conservatorio di Musica S. Cecilia di Roma’. A student of the educational institution had filed a complaint with the DPA for having received a disciplinary sanction for a statement made during a student assembly. Although it was not supposed to be, the assembly was recorded and the institution used the recordings to base the disciplinary action on it. During its investigation, the DPA determined that the controller did not have a valid legal basis to use the assembly recordings and, therefore, the processing of the student’s personal data was unlawful. Also, the DPA found that the educational institution’s data protection officer was also the institution’s director. The DPA considered this to be an unlawful conflict of interest. |
Link: | link |
Related articles: | Art. 5 GDPR, Art. 6 GDPR, Art. 38 GDPR, Art. 2-ter Codice della privacy |
Type: | Insufficient legal basis for data processing |
Fine: | EUR 6,000 |
Sector | Public Sector and Education |
All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/