The Italian authority publishes a decision against the municipality of Rieti

The Italian Data Protection Authority (GPDP) sanctioned a municipality for mistakenly publishing on its website the data of more than 31,000 taxpayers. The decision highlights the failings related to the default configuration of a publishing software and the absence of communication of the breach to the data subjects.

Facts and context

The Italian data protection authority (GPDP) today published a sanction decision against the municipality of Rieti for breaches related to the unauthorized disclosure of personal data on its website.

The case originated from a report, relayed by a press article, denouncing the online publication of a file containing the personal data of more than 31,000 taxpayers of the waste tax (TARI).

Grounds of the decision

The investigation revealed that an administrative determination had been published on XX on the public notice board and in the "Transparent Administration" section of the municipality's website, with attachments that should not have been public. These annexes notably contained the list of employees of a company (first and last names of 50 people) and the waste tax role, which listed about 31,000 users (natural and legal persons) with their first and last names, tax code, residence, as well as cadastral data and the area of their real estate properties. The publication, due to human error, remained online for 11 days before being removed on XX, after having been viewed 57 times and downloaded 31 times by third parties. The authority found several violations:

  • Obligation to respect processing principles (Article 5 of the GDPR): The authority considered that the online disclosure of the full list of taxpayers, including their names, tax codes, addresses, and cadastral data, was unlawful as no legal obligation justified such publicity. This publication also violated the principles of data minimization by disclosing far more information than necessary, and integrity and confidentiality by exposing data to unauthorized third parties.
  • Obligation of accountability of the controller (Articles 5, paragraph 2, and 24 of the GDPR): The municipality failed to demonstrate the implementation of appropriate technical and organizational measures to ensure and prove that processing was carried out in compliance with the GDPR, as evidenced by the publication error and its management.
  • Obligation of data protection by design and by default (Article 25 of the GDPR): The authority emphasized that the default configuration of the publishing software, which automatically uploaded attachments unless manually overridden by the operator, constituted a breach. The controller should have ensured that the most privacy-protective settings were applied by default to prevent such errors.
  • Obligation of security of processing (Article 32 of the GDPR): The accidental publication, resulting from human error combined with a software configuration not secure by default, was considered a failure of the technical and organizational measures aimed at ensuring a level of security appropriate to the risk.
  • Obligation to communicate a personal data breach (Article 34 of the GDPR): The municipality considered that the breach did not present a high risk to the rights and freedoms of individuals, arguing the absence of special categories of data or data relating to criminal convictions, and therefore did not individually inform the 31,050 data subjects concerned. The authority rejected this analysis, considering that the nature and volume of the data exposed (identity, tax code, domicile, real estate assets) created a high risk, notably of fraud or identity theft, making communication mandatory. This failure is accompanied by a violation of Article 12, paragraph 1, of the GDPR relating to transparency of communications.

Authority's decision

Consequently, the authority imposed a fine of €6000 on the municipality of Rieti.

Lessons learned

This decision reminds that:

  • The default configuration of a software tool must be the most privacy-protective; having to perform a manual action to *prevent* data publication constitutes a violation of the principle of data protection by default.
  • The risk assessment for the rights and freedoms of individuals, to determine whether communication of a breach is mandatory, must not be limited to the mere presence of special categories of data (Article 9) or criminal data (Article 10). The combination of identification, contact, and property data on a large scale can constitute a high risk.
  • Human error does not exempt the controller from responsibility when it is made possible by insufficient technical and organizational measures, such as inadequate staff training and the absence of technical safeguards.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire