Italian DPA fines security company EUR 39 000 for violations concerning employees’ data

The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a former employee of La Patria S.p.A., a security and technological security company. The complainant claimed that the company had failed to respond to two requests to access documentation concerning disciplinary proceedings against him, including data collected through a GPS system installed on the company vehicle assigned to him. Furthermore, where a controller decides not to comply with a request, it must inform the data subject of the reasons and of the possibility of lodging a complaint or seeking a judicial remedy.. They also found that the company had failed to provide employees with appropriate information on the processing of geolocation data collected through GPS systems installed on company vehicles. In addition, the company’s privacy notices incorrectly referred to the processing of special categories of personal data, including information concerning philosophical beliefs and sex life, although the company did not actually process such data. In particular, it provided employees with appropriate information concerning the processing of geolocation data and removed incorrect references to special categories of personal data from its privacy notice.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source