Categories: Insights, Practice

Tag: GDPR


27 May 2022

The Data Protection Authority sanctions whistleblowing systems that do not guarantee the processed data confidentiality

On 7 April 2022, in an injunction order issued against a hospital, the Italian Data Protection Authority (“Garante”) found that the data processing carried out as part of the management of its whistleblowing system was unlawful.

The Authority sanctioned the IT company, which was acting as a data processor, and managed the service for reporting alleged corrupt activities or unlawful conduct within the entity.

The investigation

The Authority noted that under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”), the hospital in its capacity as Data Controller, failed to provide specific and prior information about personal data processing carried out following a report. This was in violation of the principle of “lawfulness, fairness and transparency”, which imposes on the data controller the obligation to provide data subjects specific information about the data processing in advance, by taking “appropriate measures” to reach recipients.

It emerged that the health authority failed (i) to trace the processing operations carried out in the Processing Register under Art. 30 of the GDPR and to carry out a preliminary privacy impact assessment.

The Authority stated that the processing of personal data using systems for acquiring and managing reports has risks for the rights and freedoms of the data subjects due to “the sensitivity of processed information, the “vulnerability” of the data subjects in the workplace, and the confidentiality regime of the whistleblower’s identity under the sector’s legislation.”

Furthermore, it noted that:

  • during the replacement phase of the person in charge of corruption prevention and transparency, proper management of authentication credentials to access the web application had not been adopted, and
  • the IT company appointed by the entity to manage the whistleblowing system had used a (sub) supplier for the application hosting service failing to provide data processing instructions and to inform the health authority (data controller). It used the same hosting service for its own and additional purposes.

The Data Protection Authority’s decision

The Authority fined the hospital and the IT Company € 40,000 and gave the hospital a further 30 days to make its relationship with its supplier compliant with the relevant legislation.

◊◊◊◊

As specified in the communiqué shared by the Data Protection Authority, the investigation carried out, in this case, was part of “a series of inspections on the processing methods of data acquired through whistleblowing systems, particularly those most used in Italy by employers.”

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…

30 Jul 2026

Did you know that… an employee’s natural incapacity does not prevent the time limit for challenging a dismissal from running?

In judgment no. 23486 of 18 July 2026, the Joint Chambers of the Italian Supreme Court (i.e. “Corte di Cassazione”) held that the natural incapacity of an employee…

22 Jul 2026

An employee may not steer clients toward a competitor before resigning (Camera di Commercio Francese in Italia, 22 July 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 1723 of 26 May 2026, the Italian Supreme Court (Corte di Cassazione) confirmed the liability of an employee who, prior to the termination of his…

20 Jul 2026

Access to Naspi (Top24 Lavoro Ai – Il Sole 24 Ore, 20 July 2026 – Vittorio De Luca e Alessandra Zilla)

Regulatory Framework  The New Social Insurance for Employment (NASpI), introduced by Legislative Decree No. 22 of 4 March 2015, is the primary income support scheme for employees who…