Categories: Insights, Publications · News, Publications

Tag: Privacy


13 Jun 2022

Computer incident, the Data Protection Authority sanctions INAIL for unlawful data processing (Norme & Tributi Plus Diritto – of Il Sole 24 Ore, 13 June 2022 – Vittorio De Luca, Elena Cannone)

Human error is the data controller’s responsibility The Italian Data Protection Authority (“Garante”), in its 28 April 2022 injunction imposed a € 50,000 fine on the National Institute for Insurance against Accidents at Work (“INAIL” or the “Institute”) after three computer incidents. These incidents allowed users to access data relating to others.
INAIL, in its capacity as data controller, had notified the Data Protection Authority under art. 33 of the EU Regulation on personal data protection (the “Regulation”), three personal data breaches that occurred between 2019 and 2020. These breaches concerned the online service “Sportello Virtuale Lavoratori” (Virtual Workers’ Desk), which allows employees who have suffered an accident or are victims of occupational illnesses to view the progress of their files and measures issued by the Institute. The investigation initiated by the Data Protection Authority revealed that the “Sportello Virtuale Lavoratori” allowed some workers to accidentally consult the files of other workers and view personal information (e.g. first name, surname) and data relating to their health status (“sensitive data”). It was verified that one of the three reported violations was caused by a “human error” which, as stated in the order, “is
the data controller’s responsibility.”

Continue reading the full version published in Norme & Tributi Plus Diritto of Il Sole 24 Ore.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 marzo 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…

3 Mar 2026

Employee monitoring: when “bossware” becomes a legal risk (Agenda Digitale, 2 marzo 2026 – Martina De Angeli)

Monitoring workers through digital tools is a rapidly expanding practice, accelerated by the spread of remote work and the digital transformation of companies. Before adopting these systems, however,…

3 Mar 2026

Melismelis signs the campaign for the 50th anniversary of De Luca & Partners

For the historic labor law firm, the agency developed the 50th-anniversary logo and advertising campaign, managed online and offline media planning, and renewed the website’s visual identity. Milan,…

27 Feb 2026

Dismissals: the Corte costituzionale grants broader discretion to judges and greater scope for reinstatement (I Focus del Sole 24 Ore, 26 febbraio 2026 – Vittorio De Luca e Alessandra Zilla)

The regulation of dismissals continues to represent one of the central pillars of Italian labour law, an area of constant tension between freedom of economic initiative and the…