The case, explained

Data Protection Authority Sanction Against Public Administration: The Case of the CIE Agenda Portal Vulnerability

5 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The security of public digital infrastructure is back at the center of legal debate following the sanctioning measure issued by the Data Protection Authority. According to reports in the national press, including La Notizia and Pagella Politica, a technical error occurring between June 8 and 10, 2023, exposed personal data of numerous citizens during Electronic Identity Card booking procedures, leading to financial penalties for the Ministry of the Interior and its technological partner Sogei S.p.A. The incident highlights critical issues in the in-house management of strategic IT services and the rigor required by the Authority in supervising security systems. In this article, we analyze the liability profiles between the Controller and the Processor, reconstructing the event through the study of applicable rules and proposing a didactic twin case to illustrate the potential legal developments of such a breach.

Data Protection Authority Sanction Against Public Administration: The Case of the CIE Agenda Portal Vulnerability

In brief

The Data Protection Authority sanctioned the Ministry of the Interior (45,000 euros) and Sogei (30,000 euros) for a data breach on the CIE Agenda portal. The error, resulting from a software update, allowed unauthorized viewing of personal data. The analysis focuses on the Controller's duty of supervision (culpa in vigilando), the obligation for preventive testing (Privacy by Design), and the promptness of notifying violations to the supervisory authority.

  1. The fact

    According to reports by outlets such as La Notizia and Pagella Politica, in June 2023, the CIE Agenda portal suffered a serious data breach. Due to a bug introduced during a software update, users logging in could view the personal data of other citizens.

    The matter concluded, from an administrative standpoint, with a definitive sanctioning measure from the Data Protection Authority in June 2024. The Authority found that, despite the discovery of the problem on June 10, the official notification occurred beyond the prescribed 72-hour deadline. Furthermore, a deficiency in pre-release vulnerability tests emerged.

  2. The rules at play

    The core rules are set out in the GDPR. Art. 24 outlines the Controller's responsibility, while Art. 25 introduces the principle of Privacy by Design, requiring systems to be configured securely from the design phase.

    Art. 32 mandates adequate technical and organizational measures, such as vulnerability testing. Finally, Art. 33 establishes the obligation to notify the breach within 72 hours of becoming aware of it. For Public Administrations, Art. 166 of the Privacy Code regulates the application of administrative fines.

  3. What case law says

    Case law and the Data Protection Authority's guidelines clarify that the Controller's liability for the Processor's actions constitutes culpa in vigilando. Technical delegation of the service is insufficient: the Controller must actively verify the adequacy of the implemented measures.

    Furthermore, it has been established that a technical error resulting from a software update does not constitute a fortuitous event, as conducting preventive tests falls within the ordinary diligence required by the principle of Accountability.

  4. Analysis drafted and verified with edit.legal

    To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.

    Try edit.legal AI
  5. Lessons for professionals

    1. Contractual review: ensure service contracts mandate required testing and security procedures.
    2. Incident management: implement internal protocols to guarantee notification within 72 hours.
    3. Documentation: retain vulnerability assessment reports as evidence of accountability during regulatory inspections.

References: Regolamento UE 2016/679 (GDPR) Artt. 5, 24, 25, 32, 33, 83D.Lgs. 196/2003 (Codice Privacy) Art. 166Provvedimenti del Garante per la protezione dei dati personali

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAMContent drafted with AI support and subject to editorial source checks. Despite these controls, inaccuracies may remain: reports and rectification requests are welcome. Report a correction

Frequently asked questions

What are the maximum sanctions for a data breach in the PA?

In Italy, Art. 166 of the Privacy Code limits administrative fines for Public Administrations up to 10 million euros or, for enterprises, up to 2% or 4% of total annual worldwide turnover, depending on the severity of the GDPR violation.

When does a Privacy Authority sanction expire?

The right to collect amounts due for administrative sanctions prescribes five years from the date the violation was committed.

What should a citizen do if they discover their data has been exposed online?

The citizen may lodge a complaint with the Data Protection Authority or bring an action before the ordinary court to seek damages, after securing evidence of the breach.

Verified legal research and drafting with edit.legal

Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.

Try edit.legal for free