TL;DR for the DPO
An electronic document register is a document management system like any other: if every user sees everything that passes through it, the configuration is already unlawful. Documents concerning the employment relationship require separate, confidential procedures. The fine is low, the principle is not.
What happened
The proceeding started from two converging fronts: a data breach notification filed by the body itself and a complaint from a data subject. The investigation established that the electronic document register of the Metropolitan City of Sassari had been configured so that documents containing personal data were accessible to staff who, given their role and duties, were not authorised to process them.
There was no external intrusion and no attack. There was a configuration: the system showed unauthorised staff documents it should have restricted. It is the most frequent category of breach in the public sector and the least reported, because there is nothing spectacular about it.
The principles breached
The authority found breaches of the principles of integrity and confidentiality, accountability, and data protection by design and by default. The last is the core point: privacy by default means the initial configuration of a system must be the most restrictive, not the most convenient. A register that starts with total visibility and is restricted only on request is precisely the opposite.
Recalling its own earlier decisions, the authority restated that processing carried out through document management systems also requires technical and organisational measures ensuring selective access to the documentation held in the register, so that unauthorised staff cannot consult it.
The most important passage: documents concerning employees
The authority is explicit: filing documents containing employees' personal data and relating to the specific employment relationship requires differentiated and confidential procedures. A generic folder permission is not enough: those documents need a separate route. This is the part that does not exist in most public bodies and companies.
Why the fine is nevertheless low, and why that is not good news
In setting the fine at 12,000 euro the authority took into account, among other things, three elements: that it has been giving public and private employers guidance on the correct processing of data in the employment context since 2007; that the breach affected all personal data passing through the register; and that the processing also involved sensitive material relevant to disciplinary proceedings.
It is worth reading these as written: they are aggravating circumstances, not mitigating ones. The fine stays modest for reasons connected to the nature of the body, but the reasoning behind it is strict, and in a private setting with the same facts the financial outcome would differ. The reference to 2007 is an elegant way of saying that on this subject there are no interpretive excuses left.
The check you can run in half an hour
1) Ask the client to log into the document register with the lowest-privilege profile and look at what it shows: it is the quickest and most revealing test. 2) Check whether a separate route exists for documents relating to the employment relationship, in particular disciplinary and health records. 3) Check whether authorisation profiles have been reviewed since the last reorganisation: people almost always change role while permissions stay. 4) Check that the records of processing include document management as a processing activity of its own, with its recipients and its measures: if it is missing, nobody has ever assessed that configuration.
The point for the external DPO
This is a fine that an hour of work and a list of profiles would have prevented. The reason it happens anyway is that nobody treats it as a data protection matter: the register is an administrative topic, permissions are an IT topic, and the DPO gets consulted on privacy notices. The way to catch it is to add a review of access profiles for document systems to the client's periodic checks, with a deadline of its own, just like the records of processing. It is exactly the kind of control that slips when deadlines live in the consultant's head instead of in a calendar.
Official source:Italian Data Protection Authority - Newsletter no. 550 of 29 July 2026; decision of 11 June 2026 [doc-web 10266034]Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free