Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement September 22, 2026 5 min

Cameras in the changing rooms since 2007: the defence lists what they did not film, and loses

Eight thousand euros for the company running the sports facilities of the City of Trento. The cameras framed the lockers, not the changing cubicles or the showers. It was not enough: the place itself carries an expectation of privacy that does not depend on where the lens points

In two lines

Italian DPA, decision no. 619 of 3 September 2026 (doc. web no. 10294255): EUR 8,000 against the special agency running the City of Trento's sports facilities for breach of Arts. 5(1)(a) and (e), 6(1)(c) and (e), 12(1) and 13 GDPR, and Art. 2-ter of the Italian Privacy Code.

The cameras were in the changing rooms of the swimming pool at the Trento Nord sports centre, in Gardolo, and framed the locker area where users leave their belongings. They had been installed to stop thefts of wallets and phones, which the operator said had produced «insecurity and a consequent sense of unease among users». The system was covered by an agreement with the company's union representatives signed on 13 September 2007, under Art. 4 of Law no. 300/1970.

What did not hold

A changing room is a place of high expectation of privacy, and that does not depend on which portion of it falls within the frame. The processing was found to lack an adequate legal basis and to be contrary to the principles of lawfulness, fairness and transparency. Shortcomings emerged in the notices to users, and the one for the workers being filmed arrived only after the investigation had started: a notice produced in answer to an inspection is not a notice, it is a patch.

The seventy-two hours, and why they concern every system

The operator declared a retention of seventy-two hours. The authority does not argue that this is too long: it argues that it was not accompanied by a specific assessment showing it was necessary. That is the difference between choosing a period and adopting one. Anyone running a CCTV system has a number of hours or days in their notice: the question is not whether that number is defensible in the abstract, but whether a document exists explaining why it is that number and not half of it. During the proceedings the operator reduced the retention times, besides switching off and removing the changing-room cameras and updating signage and notices.

What to check on every system you oversee

1) Ask for the floor plan with each camera's field of view, not the wiring diagram: the difference between those two documents is where the fines are. 2) Ask for the document that justifies the retention period. If it does not exist, the number in the notice is an unfounded statement, and that is what cost money here. 3) Check that the notice to workers exists and is dated before the system was switched on, not after. 4) Remember that the union agreement under Art. 4 of the Workers' Statute legitimises remote monitoring in employment law, but does not by itself supply the legal basis for the processing: here the 2007 agreement existed, and the fine came anyway.

Official source:Italian Data Protection Authority, decision of 3 September 2026, register no. 619, doc. web no. 10294255

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement

The vendor's bug turned into a criminal conviction

On 7 September 2026, before the Dublin Metropolitan District Court, Brown Thomas Arnotts Limited pleaded guilty to five sample charges out of twenty-one for breaches of the Irish ePrivacy Regulations. Three concerned the absence of a valid opt-out address, two the sending of marketing without valid consent. The sum paid is two thousand euro. The sum is not the point: this was a criminal prosecution.

Sep 07, 2026New 5 min
Enforcement
403million euro, and six months to comply

Google, €403 million: half the findings live in your register

On 21 September 2026 the Irish Data Protection Commission closed the inquiry it opened into Google Ireland in February 2020. Its subject: location data in three features — Web & App Activity, Location History, Location Accuracy — between 25 May 2018 and 4 February 2020. Fines totalling €403 million and six months to come into compliance. The number makes the headlines; for practitioners, the interesting part is elsewhere.

Sep 23, 2026New 6 min
Enforcement
24.000euros for an access authorised by the medical management

«Not unlawful, the medical management authorised it»: the Italian DPA says no, EUR 24,000

The case is small and the lesson is not. A hospital is at once a place of care and the employer of the same person, and when the two capacities touch, the health record becomes the handiest and most wrong tool. The employer had put it in writing to the prosecutor: that access was not unlawful, it was «carried out on the instructions of the medical management» «for the performance of the work». That is precisely the sentence the authority takes apart.

Sep 22, 2026New 6 min