High School Data Breach: Curriculum Info Sent to Families

by Grace Chen

Italian High School Fined €3,000 for Data Privacy Breach in Teacher Selection Process

A Turin high school has been penalized €3,000 by the Guarantor for the Protection of Personal Data for violating data privacy regulations during its teacher recruitment process. The sanction, confirmed by Provision 9 October 2025 [10197090], stems from the school’s practice of sharing full teacher candidates’ curriculum vitae with forty-four families of students.

The case originated from a complaint filed by a teacher who objected to the widespread distribution of her personal information. According to the complaint, the CVs included details about the candidates’ personal lives, specifically mentioning “numerous training interventions in the parish and oratory,” which revealed a clear Catholic affiliation and, consequently, religious orientation. The school intended to allow families to provide input on teacher selections as part of an initiative to combat student dropout rates.

The high school defended its actions, asserting that individuals had been “duly informed of the transmission of the curricula” and that the data sharing was based on either explicit consent or a “legitimate interest” in fostering family participation, aligning with constitutional principles. School officials also argued that the parish/oratory activities did not constitute sensitive data regarding religious beliefs.

However, the Guarantor’s investigation rejected these arguments. A key finding was the lack of a valid legal basis for sharing the data with families. The office determined that the school’s selection notice did not authorize the disclosure of personal information to third parties, and that lower-level administrative acts cannot supersede higher-level data protection rules. This constituted a violation of Articles 6 and 2-ter of the relevant code.

Furthermore, the Guarantor emphasized the principle of data minimization, stating that the school could have achieved its objectives through less intrusive methods than distributing complete CVs. The office also reaffirmed that consent is often invalid in employment contexts due to inherent power imbalances, and that invoking “legitimate interest” is generally inappropriate for public authorities like educational institutions.

While the Guarantor acknowledged that the CV information regarding parish/oratory involvement was not, on its own, sufficient to definitively establish a candidate’s religious beliefs, thus avoiding a violation of Article 9 of the Regulation, the broader data privacy breaches remained significant.

The processing of personal data – specifically, the communication of the four candidates’ CVs to the forty-four families – was deemed unlawful due to violations of Articles 5(1)(a) and (c), and 6 of the Regulation, alongside Article 2-ter of the Code, concerning lawfulness, correctness, transparency, and data minimization.

Despite the severity of the infraction, the Guarantor reduced the fine to €3,000, citing several mitigating factors. These included the “appreciable purpose” of the initiative to combat school dropout, the fact that the violation was committed through negligence – compounded by the school’s failure to consult its Data Protection Officer (DPO) beforehand – and the school’s subsequent cooperation with the Authority and implementation of “more restrictive internal procedures” requiring prior DPO consultation.

The Guarantor deemed the €3,000 fine “effective, proportionate, and dissuasive,” given the nature of the data controller as an educational institution. The Authority also mandated the publication of the injunction order on its website, recognizing the wide dissemination of the data. This case serves as a critical reminder to educational institutions and other organizations of the importance of adhering to stringent data privacy regulations and prioritizing the protection of personal information.

Leave a Comment