Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Italian DPA July 29, 2026 6 min

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

A small fine on a very large problem: in document management systems selective access is not optional, and disciplinary records must be filed through confidential procedures

TL;DR for the DPO

An electronic document register is a document management system like any other: if every user sees everything that passes through it, the configuration is already unlawful. Documents concerning the employment relationship require separate, confidential procedures. The fine is low, the principle is not.

12,000
euro fine, for a configuration

What happened

The proceeding started from two converging fronts: a data breach notification filed by the body itself and a complaint from a data subject. The investigation established that the electronic document register of the Metropolitan City of Sassari had been configured so that documents containing personal data were accessible to staff who, given their role and duties, were not authorised to process them.

There was no external intrusion and no attack. There was a configuration: the system showed unauthorised staff documents it should have restricted. It is the most frequent category of breach in the public sector and the least reported, because there is nothing spectacular about it.

The principles breached

The authority found breaches of the principles of integrity and confidentiality, accountability, and data protection by design and by default. The last is the core point: privacy by default means the initial configuration of a system must be the most restrictive, not the most convenient. A register that starts with total visibility and is restricted only on request is precisely the opposite.

Recalling its own earlier decisions, the authority restated that processing carried out through document management systems also requires technical and organisational measures ensuring selective access to the documentation held in the register, so that unauthorised staff cannot consult it.

The most important passage: documents concerning employees

The authority is explicit: filing documents containing employees' personal data and relating to the specific employment relationship requires differentiated and confidential procedures. A generic folder permission is not enough: those documents need a separate route. This is the part that does not exist in most public bodies and companies.

Why the fine is nevertheless low, and why that is not good news

In setting the fine at 12,000 euro the authority took into account, among other things, three elements: that it has been giving public and private employers guidance on the correct processing of data in the employment context since 2007; that the breach affected all personal data passing through the register; and that the processing also involved sensitive material relevant to disciplinary proceedings.

It is worth reading these as written: they are aggravating circumstances, not mitigating ones. The fine stays modest for reasons connected to the nature of the body, but the reasoning behind it is strict, and in a private setting with the same facts the financial outcome would differ. The reference to 2007 is an elegant way of saying that on this subject there are no interpretive excuses left.

The check you can run in half an hour

1) Ask the client to log into the document register with the lowest-privilege profile and look at what it shows: it is the quickest and most revealing test. 2) Check whether a separate route exists for documents relating to the employment relationship, in particular disciplinary and health records. 3) Check whether authorisation profiles have been reviewed since the last reorganisation: people almost always change role while permissions stay. 4) Check that the records of processing include document management as a processing activity of its own, with its recipients and its measures: if it is missing, nobody has ever assessed that configuration.

The point for the external DPO

This is a fine that an hour of work and a list of profiles would have prevented. The reason it happens anyway is that nobody treats it as a data protection matter: the register is an administrative topic, permissions are an IT topic, and the DPO gets consulted on privacy notices. The way to catch it is to add a review of access profiles for document systems to the client's periodic checks, with a deadline of its own, just like the records of processing. It is exactly the kind of control that slips when deadlines live in the consultant's head instead of in a calendar.

Official source:Italian Data Protection Authority - Newsletter no. 550 of 29 July 2026; decision of 11 June 2026 [doc-web 10266034]

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

Jul 15, 2026 3 min
Italian DPA
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

Jul 14, 2026 3 min
Italian DPA
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

Jul 02, 2026 4 min