In the matter of the General Data Protection Regulation
DPC Complaint Reference:
IMI Ref:
In the matter of a complaint, lodged by with the Italian Data Protection
Authority pursuant to Article 77 of the General Data Protection Regulation, concerning
Record of Amicable Resolution of the complaint and its consequent withdrawal pursuant to
Section 109(3) of the Data Protection Act, 2018
Further to the requirements of Internal EDPB Document 06/2021 on the practical implementation
of amicable settlements (adopted on 18 November 2021)
RECORD OF AMICABLE RESOLUTION FOR THE
PURPOSE OF INTERNAL EDPB DOCUMENT 06/2021 ON
THE PRACTICAL IMPLEMENTATION OF AMICABLE
SETTLEMENTS, ADOPTED 18 NOVEMBER 2021
Dated the 30th day of September 2022
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, Ireland
1
Background
1. On 12 September 2018, (“the Data Subject”) lodged a complaint
pursuant to Article 77 GDPR with the Italian Data Protection Authority (“the Recipient SA”)
concerning (“the
Respondent”).
2. In circumstances where the Data Protection Commission (“the DPC”) was deemed to be the
competent authority for the purpose of Article 56(1) GDPR, the Recipient SA transferred the
complaint to the DPC on 23 September 2020.
The Complaint
3. The details of the complaint were as follows:
a. When the Data Subject attempted to log in to her Account in September
2018 she was denied access. The Data Subject noticed the username assigned to her
account had been changed and when attempting to update her password to regain
access noticed that the email address associated with the account had also been
changed.
b. The Data Subject attempted to report the account for impersonation however, the
Respondent replied advising that the account in question did not breach their
community guidelines.
c. As the Data Subject was not satisfied with the response received from the Respondent
regarding the concerns raised, the Data Subject lodged a complaint with their
supervisory authority.
Action taken by the DPC
4. The DPC, pursuant to Section 109(4) of the Data Protection Act, 2018 (“the 2018 Act”), is
required, as a preliminary matter, to assess the likelihood of the parties to the complaint
reaching, within a reasonable time, an amicable resolution of the subject-matter of the
complaint. Where the DPC considers that there is a reasonable likelihood of such an amicable
resolution being concluded between the parties, it is empowered, by Section 109(2) of the
2018 Act, to take such steps as it considers appropriate to arrange or facilitate such an
amicable resolution.
5. Following a preliminary examination of the material referred to it by the Recipient SA, the DPC
considered that there was a reasonable likelihood of the parties concerned reaching, within a
reasonable time, an amicable resolution of the subject matter of the complaint. The DPC’s
experience is that complaints of this nature are particularly suitable for amicable resolution in
circumstances where there is an obvious solution to the dispute, if the respondent is willing
to engage in the process. In this regard, the DPC had regard to:
2
a. The relationship between the Data Subject and Respondent (being, in this case, an
individual consumer and a service provider); and
b. The nature of the complaint (in this case, an unsuccessful attempt by the Data Subject
to exercise her data subject rights).
6. While not relevant to the assessment that the DPC is required to carry out pursuant to Section
109(4) of the 2018 Act, the DPC also had regard to Internal EDPB Document 06/2021 on the
practical implementation of amicable settlements, adopted on 18 November 2021
(“Document 06/2021”), and considered that:
a. the possible conclusion of the complaint by way of amicable resolution would not
hamper the ability of the supervisory authorities to maintain the high level of
protection that the GDPR seeks to create; and that
b. such a conclusion, in this case, would likely carry advantages for the Data Subject,
whose rights under the GDPR would be vindicated swiftly, as well as for the controller,
who would be provided the opportunity to bring its behaviour into compliance with
the GDPR.
Amicable Resolution
7. The DPC engaged with both the Data Subject (via the Recipient SA) and Respondent in relation
to the subject matter of the complaint. Further to that engagement, and following a review
of the matter by the Respondent, it was confirmed that the account had been compromised.
In the circumstances, the Respondent agreed to take the following actions:
a. The Respondent requested a new secure email address to be associated with the
account. This would enable the Data Subject to regain access to the account from
where she could schedule it for deletion.
b. Upon receipt of a new secure email address, the Respondent agreed to reach out to
the Data Subject directly to assist her further with regards her erasure request.
8. On 06 September 2021, the Data Subject provided the DPC with a new secure email address
to be associated with her account and confirmed that she was willing to be contacted by the
Respondent directly. On 20 October 2021 the DPC provided the Respondent with the new
secure email address of the Data Subject and advised that she could be contacted directly.
9. On 29 October 2021, the Respondent confirmed to the DPC that they had contacted the Data
Subject directly to help them regain access to their account. The Respondent also confirmed
that the Data Subject had successfully scheduled the account for deletion. On 04 January
2022, the DPC wrote to the Data Subject, via the Recipient SA. In its correspondence to the
Data Subject, the DPC requested that the Data Subject notify it, within a specified timeframe,
if she was not satisfied with the actions taken by the Respondent, so that the DPC could take
further action. The Recipient SA confirmed that they issued this update to the Data Subject on
3