Back to Feed
PolicySep 14, 2026

Garante per la protezione dei dati personali (Italy) - 10286417

Italy's Garante fines Municipality of Rieti €6,000 for personal data leak.

Summary

The Garante per la protezione dei dati personali (Italy) has fined the Municipality of Rieti €6,000 due to a data breach where personal information of 31,000 individuals was inadvertently published online. The leak occurred when a document containing names, tax codes, and property details of taxpayers was published alongside administrative acts, remaining accessible for eleven days and viewed by external users.

Full text

Help Garante per la protezione dei dati personali (Italy) - 10286417: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 17:16, 14 September 2026 view source Ligialagev (talk | contribs)42 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 17:16, 14 September 2026 Garante per la protezione dei dati personali - 10286417 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 5(1)(c) GDPR Article 5(1)(f) GDPR Article 5(2) GDPR Article 12(1) GDPR Article 24 GDPR Article 25 GDPR Article 32 GDPR Article 34 GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 14.07.2026 Fine: 6000.0 EUR Parties: Municipality of Rieti National Case Number/Name: 10286417 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: ligialagev The DPA fined the Municipality of Rieti €6,000 after a publication resulted in the leak of 31,000 individuals' personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A document was published by an employee, but other act was published at the same time, and it contained the names of 50 employees of that company and the waste tax roll (TARI) of around 31,000 taxpayers, both natural and legal persons. The roll listed names, tax codes, addresses of residence, cadastral data, the address and surface area of the taxed properties, and the tax category assigned to each taxpayer. The documents remained online for eleven days. They were viewed 57 times, 44 times by external users, and downloaded 31 times, always by external users. The controller notified the breach to the DPA under Article 33 GDPR. It did not inform the data subjects, arguing that the breach was unlikely to result in a high risk because the published data did not fall under Articles 9 or 10 GDPR, and it left that decision to the DPA. A local newspaper then reported the publication. The controller replied with a press release on its website, it stated that the controller had acted promptly and followed its protocols, and that the published document contained personal data which was neither sensitive nor judicial, as well as data of legal persons which, in the controller's view, fell outside data protection law. A third party reported the publication to the DPA under Article 144 of the Italian Data Protection Code. During the investigation, the controller asked its supplier to change the default setting, disabled the automatic publication of attachments and carried out a DPIA on the publication software, which the DPO approved. The DPIA concluded that human error was unlikely because staff had been made aware of data protection issues. Holding First, the DPA held that the software allowed the operator only to exclude a document from publication (opt-out) instead of selecting the documents to be published (opt-in). This default setting made the disclosure of personal data dependent on a single manual step and therefore increased the risk of loss of confidentiality through human error or system faults. The controller could not show that it had followed up on its request to the supplier, since the ticket it produced was merely a suggestion to change the default. The DPA therefore found a violation of Articles 5(1)(a), 5(1)(c), 5(1)(f), 25 and 32 GDPR. Second, the DPA held that a legal publication duty does not create an automatism. Before disclosing personal data online, the controller had to verify which data and documents the applicable rules actually required it to publish. Third, the DPA rejected the argument that the cadastral data was in any event available through the tax administration's online platform. The publication made a large volume of data on a large number of data subjects immediately accessible to anyone, which differs from selective searches on separate systems that require specific queries and concern one previously identified data subject at a time. Fourth, the DPA held that the controller discovered the publication late, therefore had no measure in place to detect anomalies in the uploads to its website, in breach of Articles 5(1)(f), 5(2), 24, 25 and 32 GDPR. The DPA added that the controller kept overall responsibility for the processing even where a processor carried it out on its behalf. Fifth, the DPA held that the controller could not limit its risk assessment to whether the breach involved data under Articles 9 and 10 GDPR. It should also have considered the number of data subjects, the identification data and home addresses involved, and the fact that the TARI category revealed highly personal information, namely the standard of living that can be inferred from the type of dwelling. On that basis the breach was likely to result in a high risk, for instance of theft or discrimination. Sixth, the DPA held that the press release did not amount to a communication under Article 34 GDPR. It did not state the categories of personal data affected or identify the categories of data subjects, and it incorrectly stated that data of legal persons fell outside data protection law, while the controller had admitted during the investigation that the business name of a sole trader may identify a natural person. The press release also suggested that the controller was still waiting for the DPA to tell it whether to inform the data subjects, although that assessment was its own. Finally, the data subjects could not easily find it, since it carried a misleading title and was only available in the press section of the website. The DPA therefore found a violation of Articles 5(1)(a), 5(2), 12(1), 24 and 34 GDPR. The DPA classified the gravity of the violation as medium and the conduct as negligent. It took into account as mitigating factors the small size of the municipality, the absence of previous relevant violations and the controller's cooperation, in particular the new procedure requiring an active step from the operator to upload attachments. On these grounds, the DPA fined the controller €6,000. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10286417] Decision of July 14, 2026 Register of Decisions No. 523 of July 14, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, “General Data Protection Regulation” (hereinafter, “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003, containing the “Code on Data Protection, setting forth provisions for the adaptation of national law to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at the performance of the tasks and the exercise of the powers entrusted to the Data Protection Authority, approved by

Entities

Garante per la protezione dei dati personali (vendor)Transparent Administration (product)