Details:
Summary | The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee’s email account active and had access to the data subject’s correspondence, despite the termination of his/her employment. The data subject had not been informed about such a further use of his/her e-mail account, as well as about the storage of all incoming and outgoing e-mails on the company servers and the related processing of his/her personal data. |
Link: | link |
Related articles: | Art. 5 (1) a), c), e) GDPR, Art. 12 GDPR, Art. 13 GDPR |
Type: | Non-compliance with general data processing principles |
Fine: | EUR 20,000 |
Sector | Employment |
All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/