TL;DR for the DPO
The Italian DPA fined Lepida (EUR 100,000, decision of 29 April 2026): in the LepidaID service over 7,000 operators could access, in a substantially indiscriminate way, data and documents of 1.5 million citizens. The DPA found an overly permissive access model, lack of privacy by design/by default (Art. 25), copies of ID documents kept on operators' workstations after identification, and a joint-controllership arrangement not matching the real allocation of responsibilities.
The three points that matter
- Need to know, not 'everyone sees everything': being an authorised operator does not justify access to any record. You need differentiated profiles, access tied to the case being handled, and alerts on anomalous access.
- Privacy by design (Art. 25) is engineering, not paperwork: if the system STRUCTURALLY allows indiscriminate access, the breach exists even without abuse. 'Curiosity' accesses are the symptom, not the cause.
- Leftover files are a forgotten risk: document copies remaining on workstations after the case = storage without necessity. Automatic deletion at the end of the process is needed.
What to do now, in practice
For every client whose operators access third-party data (counters, tax-assistance centres, agencies, healthcare, public sector): 1) map WHO can see WHAT and check that access is tied to operational need; 2) ask the software vendor for differentiated profiles and access logs with alerts; 3) check that uploaded/scanned documents do not remain on local PCs after the case. The 'moderate' fine (100k) reflects the mitigating factors - cooperation and immediate fixes - not the seriousness of the design flaw.
Why it matters for your clients
The case matters because Lepida is no improvised player: it is the Emilia-Romagna in-house company that trains public bodies on digital services. If it happens there, it can happen wherever a system has too many eyes inside. For a DPO it is the perfect argument to bring access governance to the client's table: appointing authorised staff is not enough - the system must make unnecessary access impossible.
Official source:Italian Data Protection Authority - decision of 29 April 2026 (Lepida S.c.p.A.)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free