Privacy and GDPR: The Supreme Court of Cassation rules on the unlawful processing of personal data.

 

The crime of unlawful processing of personal data, provided for by art. 167 of the Privacy Code, would be the subject of a decriminalization contained in the legislative decree implementing the European Privacy Regulation (GDPR)approved preliminarily by the Council of Ministers on 21 March 2018.

However, the rule has had a fair amount of success in the jurisprudence, as demonstrated by the abundant production of precedents also referred to by the Court of Cassation in a ruling from late 2017, the last known provision on the subject.

The regulatory formulation provides that Art. 167 Unlawful processing of data 1. Unless the act constitutes a more serious crime, anyone who, for the purpose of obtaining profit for himself or others or of causing harm to others, processes personal data in violation of the provisions of Articles 18, 19, 23, 123, 126 and 130, or in application of Article 129, shall be punished, if the act results in harm, with imprisonment from six to eighteen months or, if the act consists in communication or dissemination, with imprisonment from six to twenty-four months.

2. Unless the act constitutes a more serious crime, anyone who, for the purpose of obtaining profit for himself or others or of causing harm to others, processes personal data in violation of the provisions of Articles 17, 20, 21, 22, paragraphs 8 and 11, 25, 26, 27 and 45, shall be punished, if the act causes harm, with imprisonment from one to three years.”

The Court found itself faced with a case in which such unlawful processing had been called into question by the failure to disseminate or communicate the unlawfully obtained data.

The Supreme Court then recalled that "“ As already stated by this Court, the "harm" provided for by art. 167 of Legislative Decree no. 196 of 2003, regardless of its qualification in terms of an objective condition of punishability or a constituent element of the crime, must be understood as legally relevant damage of any nature, pecuniary or non-pecuniary, suffered by the person to whom the protected data or information refers.“

AND "“In light of this framework, the concept of harm, particularly in the non-pecuniary category, as held by the contested ruling, can therefore include the strong concern for one's safety and one's property arising from the communication of personal data to unknown parties in a context characterised by the discovery, together with the images, of a dossier containing information on one's car, which had already been damaged previously, and a photograph of the house with the various access points marked.”

Follow on NOVA-Il sole 24 ore

en_GBEnglish
WeeJay