← All articles

consultant

Art. 28 GDPR: Garante fines Velletri over sub-processing chain

On 12 Feb 2026, the Italian Garante fined Velletri Servizi for non‑compliant sub‑processing contracts under Art. 28(4) GDPR and insufficient oversight. Key takeaway: document and audit the entire sub‑processing chain.

Excerpt — On 12 February 2026, the Italian DPA (Garante) fined Velletri Servizi for incomplete Art. 28 contracts with its sub‑processors STUP and ISSAM. Key takeaway for Luxembourg: document and audit the entire sub‑processing chain, not just the main DPA. (garanteprivacy.it)

The case

On 12 February 2026, the Garante per la protezione dei dati personali sanctioned Velletri Servizi, a municipal funeral services operator, for infringing Article 28(4) GDPR. Reason: sub‑processing agreements with STUP and ISSAM lacked essential elements (purpose, nature and ends, categories of data and data subjects, obligations and rights), and Velletri Servizi did not adequately oversee these sub‑processors. The fine of €2,000 was set considering Article 83(2) GDPR criteria. The Garante also noted governance issues (broad “general” sub‑processing authorisations, functional changes to the application by a sub‑processor without written instructions, additional collection of ID documents) that blurred roles and responsibilities. See the official decision: Provvedimento of 12 February 2026, no. 10225702.

Key points

  • Sub‑processing chain: STUP and ISSAM acted as sub‑processors under Art. 28(4) GDPR, but their contracts did not, in substance, impose the same obligations as the main DPA. (garanteprivacy.it)
  • Oversight duty: Velletri Servizi failed to exercise adequate vigilance over the services and processing carried out by STUP/ISSAM. (garanteprivacy.it)
  • Fine calculation: reminder of Art. 83(2) GDPR factors (gravity/duration, intent/negligence, cooperation). Official GDPR text: EUR‑Lex — 2016/679.

Legal reasoning

  • Basis: Articles 28(3) and (4) GDPR — any “on behalf of” processing must be governed by a written contract specifying at least the subject matter, duration, nature and purpose, types of data, categories of data subjects, and the controller’s obligations/rights. In sub‑processing chains, the initial processor must flow down “the same obligations” to any sub‑processor and remains accountable. Texts: CNPD — Chapter IV (Art. 28); EUR‑Lex — Chap. IV.
  • EDPB interpretation: The Guidelines 07/2020 state that lack of a compliant contract breaches Art. 28(3); the full chain must be covered by written agreements imposing, in substance, identical obligations (auditability, assistance, security, confidentiality, breach support, deletion/return, etc.). The Garante explicitly relied on these (paras. 103 and 160).
  • Fines: Article 83(4) GDPR sets a ceiling of €10m or 2% of worldwide turnover for Art. 28 infringements; proportionality and deterrence guide the final amount (Art. 83(1)–(2)). See EUR‑Lex.
  • CNPD (Luxembourg) position: the CNPD requires controllers to “verify and evidence” sub‑processor safeguards, conclude Art. 28 contracts, and include security, confidentiality and assistance clauses. See CNPD — Sub‑processors and CNPD — Documentation & accountability.

What changes in practice (Luxembourg, BE/FR/DE cross‑border)

  1. Map your sub‑processing chain down to the last critical sub‑processor. Maintain a contractual inventory linking controller → processor → sub‑processor (cloud, SaaS, managed services, payroll, ticketing, call centres, third‑party hosting, add‑on vendors). Each link must be bound by a written agreement that, in substance, mirrors Art. 28(3). (edpb.europa.eu)
  2. Demand functional clauses, not copy‑paste DPAs. Sub‑processing contracts must describe the real subject matter, nature and purposes; categories of data subjects and data (including identifiers, logs, ID documents if collected); data subject support; security measures (Art. 32); breach handling support; and audit/inspection rights. In Luxembourg, the CNPD expects explicit clauses and audit evidence. (EUR‑Lex — Art. 32)
  3. Evidence continuous oversight. The controller (or the “prime” processor towards its sub‑processors) must plan and document checks: due‑diligence questionnaires, proof of technical measures, relevant attestations/certifications, targeted tests, follow‑ups and orders to stop/limit processing when needed. The lack of sustained vigilance weighed against Velletri. (garanteprivacy.it)

Practical examples

  • Unplanned collection: a SaaS vendor adds an “ID verification” feature and starts collecting ID scans without written instruction → breach of Art. 28(3)(a) and of data minimisation/purpose limitation.
  • Unlisted cloud sub‑processor: a host hands off a feature to a new non‑EU CDN provider without contractual update or notice → break in the Art. 28(4) chain and potential Art. 44–49 transfer risk.
  • IT managed services: a framework agreement without a technical annex detailing data subjects (customers, prospects, applicants, staff) and data types → non‑compliance with Art. 28(3).

Common pitfalls seen in audits

  1. Generic “general authorisation” to sub‑process without written notification/approval and without flowing down the same obligations to the next sub‑processor. This is precisely what the Italian DPA criticised. (garanteprivacy.it)
  2. Generic DPA with unclear scope — makes it impossible to assess proportionality (Art. 5) or security (Art. 32). (EUR‑Lex — Art. 32)
  3. Unworkable audit rights — purely theoretical audit clauses (unrealistic notice, narrow windows, prohibitive costs). EDPB Guidelines require effective review/inspection options. (edpb.europa.eu)
  4. “Invisible” SaaS chains — add‑ons/marketplaces and edge services (CDN, logs, monitoring) not documented as sub‑processors; in Luxembourg, the CNPD expects you to “verify and evidence” vendor safeguards. (cnpd.public.lu)
  5. Uncontrolled app changes — features added by a sub‑processor without written instruction or contract update; a key finding in the Garante’s decision (extra ID documents collected). (garanteprivacy.it)

Official sources

In Luxembourg, this decision reinforces the need for contractual and operational control over the whole sub‑processing chain. To frame your DPO mandates and vendor oversight and align with the requirements of Art. 28 GDPR, rely on functional clauses and regular audits; where technical reviews are needed, a complementary cybersecurity audit supports due diligence.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →