Details:

Summary The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee’s email account active and had access to the data subject’s correspondence, despite the termination of his/her employment. The data subject had not been informed about such a further use of his/her e-mail account, as well as about the storage of all incoming and outgoing e-mails on the company servers and the related processing of his/her personal data.
Link: link
Related articles:  Art. 5 (1) a), c), e) GDPR, Art. 12 GDPR, Art. 13 GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 20,000
Sector Employment

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law