¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
Registry of measures
No 43 of 24 January 2024
GARANTE PER LA PROTEZIONE DEI DATI PERSONALI
At today’s meeting, with the participation of Prof. Pasquale Stanzione, President, Prof. Ginevra Cerrina
Feroni, Vice-President, Dr Agostino Ghiglia and Avv Guido Scorza, members, and Cons. Fabio Mattei, Secretary-
General;
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
(hereinafter ‘the Regulation’), and in particular Articles 32, 33, 34, 56 and 60 thereof;
Having regard to the Personal Data Protection Code, laying down provisions for the adaptation of national
law to Regulation (EU) 2016/679 (Legislative Decree No 196 of 30 June 2003, as amended by Legislative Decree
No 101 of 10 August 2018, hereinafter ‘the Code’);
Having regard to the ‘Guidelines on the notification of personal data breaches under Regulation (EU) 2016/679’ of
the Article 29 Data Protection Working Party of 3 October 2017, as last amended and adopted on 6 February 2018
and endorsed by the European Data Protection Board on 25 May 2018 (hereinafter ‘Guidelines’);
Having regard to the notification of a personal data breach submitted by Stadion s.r.l. on 27 February 2021
relating to a personal data breach suffered the previous day and to the subsequent supplementary notification of
23 April 2021, as well as to the further additions and replies to the requests for information made by the competent
Department, the last of which was received in March 2023;
Noting that the controller notified the personal data breach to the Garante without undue delay after
becoming aware of it;
Whereas the infringement consisted of the unlawful extraction by unknown entities of personal data
relating to 2905 data subjects, who were users of the website operated by the company, i.e., www.stadionaste.it,
as contained in the database of the said website;
Whereas the personal data affected by the breach included first name, last name, address, telephone
number, email address, tax ID number, document type and number;
Whereas the company notified the data subjects of the infringement on 2 March 2021, on the basis of Article
34 of the Regulation;
Piazza Venezia 11 – IT-00187 Rome
Phone + 39 06 696771 | Website www.gpdp.it | Email [email protected]
Whereas the investigation found that the personal data breach occurred by exploiting a vulnerability of the
company’s website to SQL-Injection attacks, in that the attacker managed to access the user database and
extracted the personal data stored therein by the controller;
Noting that the website was only available in Italian, and that nevertheless users were found to be
international in scope and the data breach affected citizens of several Member States of the European Union;
Having found it necessary accordingly to initiate a procedure on the Internal Market Information System
(so-called ‘IMI system’) as lead supervisory authority pursuant to Article 56 of the Regulation, the controller
having its registered office in Italy;
Having regard to the fact that, in the context of the IMI system, 13 authorities from 12 countries declared
themselves to be ‘concerned supervisory authorities’ (CSA) – namely, in chronological order, Slovakia, Germany
(SA Berlin), France, Poland, Slovenia, Luxembourg, Spain, Hungary, Lithuania, the Netherlands, Germany (SA
Rhineland-Palatinate), Austria, Portugal;
Whereas the controller confirmed in light of all the statements made following the breach that it had taken
further measures to enhance the security of processing and prevent further personal data breaches; in particular,
the controller confirmed that it had ‘enhanced the page code of the site [...] to avoid additional SQL Injection
[vulnerabilities]’, that it had adopted cryptographic techniques for storing users’ passwords, that it had ‘raised the
complexity of the passwords by increasing the minimum number of characters required and their type’ and that it had
provided for their ‘regular update’ and put in place ‘regular monitoring of anomalous activities concerning site access
and data requests’;
Whereas the assessment of the documents on file does not point, at present, to any failure to comply with
the requirements under Articles 33 and 34 of the Regulation;
Having regard to Article 60 (3) of the Regulation, whereby the lead supervisory authority ‘shall without
delay submit a draft decision to the other supervisory authorities concerned for their opinion and take due account of their
views’;
Having regard to the final draft decision to close the case as approved by the Garante’s Board via its
decision No 252 of 8 June 2023;
Having regard to the sharing of the final draft decision to close the case as performed via the Internal
Market Information (IMI) System on 11 October 2023;
Whereas none of the concerned supervisory authorities raised relevant and reasoned objections to the final
draft decision within the relevant deadline, i.e., the 9th of November, 2023;
Having regard to Article 60(7) of the Regulation whereby ‘the lead supervisory authority shall adopt and notify
the decision to the main establishment […] of the controller […] and inform the other supervisory authorities concerned and
Piazza Venezia 11 – IT-00187 Rome
Phone + 39 06 696771 | Website www.gpdp.it | Email [email protected]
the Board of the decision in question, including a summary of the relevant facts and grounds’;
Taking into account that, pursuant to Section 19 (6) of the Garante’s Rules of Procedure No 1/2019, this is
in any case without prejudice to the implementation of supervisory activities, also with regard to proceedings
that have already been closed, in the event of supervening factual or legal circumstances or of different,
subsequent evaluations by the Garante;
Having regard to the documentation on file;
Having regard to the observations made by the Secretary-General pursuant to Section 15 of the Garante’s
Regulation No 1/2000 of 28 June 2000;
Acting on the report submitted by Avv. Guido Scorza,
BASED ON THE FOREGOING, PREMISES, THE GARANTE
Adopts this final decision pursuant to Article 60 (7) of the Regulation to close the proceedings against Stadion
s.r.l., VAT No 00821350329, with registered office in Trieste, Riva Tommaso Gulli 10/A, Certified Email (PEC) account:
[email protected], since it does not find any infringement of the Regulation as matters currently stand.
Rome, 24 January 2024
[Digitally signed]
THE PRESIDENT
(Pasquale Stanzione)
THE RAPPORTEUR
(Guido Scorza)
THE SECRETARY GENERAL
(Fabio Mattei)
Piazza Venezia 11 – IT-00187 Rome
Phone + 39 06 696771 | Website www.gpdp.it | Email [email protected]