Details:

Summary The Italian DPA has imposed a fine of EUR 6,000 on ‘Conservatorio di Musica S. Cecilia di Roma’. A student of the educational institution had filed a complaint with the DPA for having received a disciplinary sanction for a statement made during a student assembly. Although it was not supposed to be, the assembly was recorded and the institution used the recordings to base the disciplinary action on it. During its investigation, the DPA determined that the controller did not have a valid legal basis to use the assembly recordings and, therefore, the processing of the student’s personal data was unlawful. Also, the DPA found that the educational institution’s data protection officer was also the institution’s director. The DPA considered this to be an unlawful conflict of interest.
Link: link
Related articles:  Art. 5 GDPR, Art. 6 GDPR, Art. 38 GDPR, Art. 2-ter Codice della privacy
Type: Insufficient legal basis for data processing
Fine: EUR 6,000
Sector Public Sector and Education

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law