Categories: Insights, Publications · News, Publications

Tag: Privacy


13 Jun 2022

Computer incident, the Data Protection Authority sanctions INAIL for unlawful data processing (Norme & Tributi Plus Diritto – of Il Sole 24 Ore, 13 June 2022 – Vittorio De Luca, Elena Cannone)

Human error is the data controller’s responsibility The Italian Data Protection Authority (“Garante”), in its 28 April 2022 injunction imposed a € 50,000 fine on the National Institute for Insurance against Accidents at Work (“INAIL” or the “Institute”) after three computer incidents. These incidents allowed users to access data relating to others.
INAIL, in its capacity as data controller, had notified the Data Protection Authority under art. 33 of the EU Regulation on personal data protection (the “Regulation”), three personal data breaches that occurred between 2019 and 2020. These breaches concerned the online service “Sportello Virtuale Lavoratori” (Virtual Workers’ Desk), which allows employees who have suffered an accident or are victims of occupational illnesses to view the progress of their files and measures issued by the Institute. The investigation initiated by the Data Protection Authority revealed that the “Sportello Virtuale Lavoratori” allowed some workers to accidentally consult the files of other workers and view personal information (e.g. first name, surname) and data relating to their health status (“sensitive data”). It was verified that one of the three reported violations was caused by a “human error” which, as stated in the order, “is
the data controller’s responsibility.”

Continue reading the full version published in Norme & Tributi Plus Diritto of Il Sole 24 Ore.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

8 Apr 2026

Management of corporate email after termination of employment: the limits according to the Italian Data Protection Authority

The Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) has once again provided guidance on how employers should manage corporate email accounts after the…

8 Apr 2026

Oral dismissal: the burden of proof on the employee

With order no. 4077 of 23 February 2026, the Italian Supreme Court addressed the issue of oral dismissal, holding that an employee challenging the termination of the employment…

8 Apr 2026

DID YOU KNOW THAT… incompatibility between colleagues may justify the transfer of an employee? 

The Italian Supreme Court, with order no. 4198 of 25 February 2026, held that an employee’s transfer may be lawfully implemented also in the presence of a situation…

7 Apr 2026

The boundary between rest and inactivity in the management of working hours (AIDP – HR Online, 7 April 2026 – Vittorio De Luca, Alesia Hima)

In the organizational language of companies, terms such as “breaks,” “waiting times,” or “downtime” are often used. In operational practice, these expressions tend to be treated almost as…

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 March 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 March 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…