The case, explained
Data Protection Authority Sanction on PA: The Case of the CIE Agenda Portal Vulnerability
5 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa
The security of public digital infrastructure is back at the center of legal debate following the recent sanctioning measure issued by the Data Protection Authority. According to national press reports, including La Notizia and Pagella Politica, a technical error occurring between June 8 and 10, 2023, exposed the personal data of numerous citizens during Electronic Identity Card booking procedures, leading to administrative fines for the Ministry of the Interior and its technological partner Sogei S.p.A. The incident highlights the critical issues of in-house management of strategic IT services and the rigor required by the Authority in supervising security systems. In this article, we analyze the liability profiles between Controller and Processor, reconstructing the event through applicable provisions and offering a didactic twin case to illustrate potential legal developments.
In brief
The Data Protection Authority sanctioned the Ministry of the Interior (45,000 euros) and Sogei (30,000 euros) for a data breach on the CIE Agenda portal. The error, caused by a software update, permitted unauthorized viewing of personal data. The analysis focuses on the Controller's duty of supervision (culpa in vigilando), the obligation of preventive testing (privacy by design), and the timely notification of violations to the supervisory authority.
The fact
According to reports by news outlets such as La Notizia and Pagella Politica, in June 2023, the Agenda CIE portal suffered a serious personal data breach. Due to a bug introduced during a software update, logged-in users were able to view the personal data of other citizens.
From an administrative standpoint, the matter concluded with a definitive sanctioning order issued by the Data Protection Authority in June 2024. The Authority established that, despite discovering the issue on June 10, the official notification was submitted beyond the mandatory 72-hour deadline. Furthermore, deficiencies in pre-release vulnerability testing were identified.
The rules at play
The governing legal provisions are set out in Regulation (EU) 2016/679 (GDPR). Article 24 outlines the general responsibility of the controller, while Article 25 establishes the principle of privacy by design, requiring appropriate security measures from the initial design phase.
Article 32 mandates adequate technical and organizational measures, including regular vulnerability testing. Finally, Article 33 imposes the duty to notify the breach within 72 hours of becoming aware of it. For public authorities, Article 166 of the Italian Privacy Code governs the imposition of administrative fines.
What case law says
Case law and guidance from the Data Protection Authority clarify that the Controller's liability for the Processor's actions constitutes culpa in vigilando. Delegating technical operations is insufficient: the Controller remains obligated to continuously verify the adequacy of security measures.
Furthermore, it is established that a technical error resulting from a software update does not qualify as a fortuitous event, as conducting pre-release testing falls within the ordinary diligence required under the principle of accountability.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
Lessons for professionals
- Contractual review: verify that service contracts and Data Processing Agreements explicitly mandate mandatory security testing and pre-release procedures.
- Incident management: implement internal protocols to detect breaches promptly and guarantee notification within 72 hours.
- Documentation: maintain logs and reports of vulnerability assessments as evidence of accountability in the event of an inspection by the competent authorities.
References: Regolamento UE 2016/679 (GDPR) Artt. 5, 24, 25, 32, 33, 83D.Lgs. 196/2003 (Codice Privacy) Art. 166Provvedimenti del Garante per la protezione dei dati personali
Related cases

Frequently asked questions
What are the maximum sanctions for a data breach in the PA?
In Italy, Article 166 of the Privacy Code applies the statutory fines under the GDPR to public authorities, which can reach up to 10 million euros. For private companies, administrative fines can reach up to 2% or 4% of total annual worldwide turnover, depending on the severity of the violation.
When does a Privacy Authority sanction expire?
The right to collect amounts due for administrative sanctions expires five years from the day the violation was committed, pursuant to Article 28 of Law no. 689/1981.
What should a citizen do if they discover their data has been exposed online?
A citizen may lodge a complaint with the Data Protection Authority or bring an action directly before the ordinary judicial authority to claim compensation for material and non-material damage suffered, after gathering evidence of the breach.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free