All news
Enforcement July 1, 2026 4 min

SPID under scrutiny: Lepida fined, data of 1.5 million citizens viewable 'out of mere curiosity'

Over 7,000 counter operators could download ID documents and health cards with no operational need. The lesson: access governance is privacy by design

TL;DR for the DPO

The Italian DPA fined Lepida (EUR 100,000, decision of 29 April 2026): in the LepidaID service over 7,000 operators could access, in a substantially indiscriminate way, data and documents of 1.5 million citizens. The DPA found an overly permissive access model, lack of privacy by design/by default (Art. 25), copies of ID documents kept on operators' workstations after identification, and a joint-controllership arrangement not matching the real allocation of responsibilities.

The three points that matter

  • Need to know, not 'everyone sees everything': being an authorised operator does not justify access to any record. You need differentiated profiles, access tied to the case being handled, and alerts on anomalous access.
  • Privacy by design (Art. 25) is engineering, not paperwork: if the system STRUCTURALLY allows indiscriminate access, the breach exists even without abuse. 'Curiosity' accesses are the symptom, not the cause.
  • Leftover files are a forgotten risk: document copies remaining on workstations after the case = storage without necessity. Automatic deletion at the end of the process is needed.

What to do now, in practice

For every client whose operators access third-party data (counters, tax-assistance centres, agencies, healthcare, public sector): 1) map WHO can see WHAT and check that access is tied to operational need; 2) ask the software vendor for differentiated profiles and access logs with alerts; 3) check that uploaded/scanned documents do not remain on local PCs after the case. The 'moderate' fine (100k) reflects the mitigating factors - cooperation and immediate fixes - not the seriousness of the design flaw.

Why it matters for your clients

The case matters because Lepida is no improvised player: it is the Emilia-Romagna in-house company that trains public bodies on digital services. If it happens there, it can happen wherever a system has too many eyes inside. For a DPO it is the perfect argument to bring access governance to the client's table: appointing authorised staff is not enough - the system must make unnecessary access impossible.

Official source:Italian Data Protection Authority - decision of 29 April 2026 (Lepida S.c.p.A.)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min