No external actor: a configuration breach, established by Italy's data protection authoritymedium
Nobody broke in: the confidential file was already visible to thirty people
On 29 July 2026 Italy's data protection authority disclosed a EUR 12,000 fine against the Metropolitan City of Sassari. There was no attack: the authority's document register was configured so that a pool of around thirty users with elevated privileges could see the register and the attachments of every entry. Among those documents, a confidential note about possible disciplinary proceedings against a senior manager. The alert did not come from a monitoring system: it came from the person concerned, warned by two colleagues who told her they had been able to open and download the file. The authority found breaches of integrity and confidentiality, accountability, and data protection by design and by default.
A breach with no attacker
Almost everything we cover starts with someone getting in where they should not. This story starts with someone who was already inside and could see more than their role warranted.
On 1 April 2025 the Province of Sassari — later the Metropolitan City — notifies the authority of a personal data breach under Article 33 GDPR. In the notification the body describes a "possible unauthorised access arising from organisational causes" affecting the document register and records management system hosted on its own servers: a pool of around thirty users with IT privileges could view both the register and the documents attached to each individual entry, thereby reaching personal data of employees and consultants.
The declared breach window runs from 25 to 29 March 2025. Data subjects affected, per the notification: one. The document in question was a communication from the then Commissioner to the Secretary, requesting the possible opening of disciplinary proceedings against a senior manager, with potential harm to her reputation.
- 25-29 March 2025The window
The confidential document is visible to anyone with an elevated profile.
- 26 March 2025The discovery
The body learns of the possible unauthorised access.
- 28 March 2025The fix
The data protection officer issues instructions on privileges.
- 1 April 2025The notification
Reported to the authority under Article 33 GDPR.
- 11 June 2026The decision
Register of decisions no. 426: a EUR 12,000 fine.
Who noticed what
The most instructive detail in the whole affair is not technical. The manager concerned files a complaint under Article 77 of the Regulation and describes how she found out: two staff in the department she leads told her they had been able to view and download the note, filed with a visibility level that made it accessible to every user holding that profile.
No alert. No log review. No system flagging anomalous access — because nothing was anomalous: these were perfectly authorised accesses to a document that should not have been in that category. The control that worked was one person telling another: you should know I can see this.
- 01The documenta confidential note, filed without the required confidentiality settings
- 02The permissionvisibility extended to all elevated authorisation profiles, around thirty users
- 03The discoverytwo colleagues flag it to the person concerned, who files a complaint
The body's response is fast. On 28 March 2025 the data protection officer issues technical and organisational instructions to restrict privileges: the highest consultation level is reserved to senior figures, with a reorganisation of accounts and privileges by role, and a requirement that all other accounts drop to a lower level. On 22 April 2025 the breach is communicated to the data subject.
What the authority found
Decision no. 426 of 11 June 2026, published with the newsletter of 29 July, sets the fine at EUR 12,000 and locates the violation in the principles of integrity and confidentiality, accountability, and data protection by design and by default.
The authority's reasoning, recalling its own earlier decisions, is that processing carried out through records management systems also requires technical and organisational measures adequate to ensure selective access to documentation held in the register, so that documents are not consultable by unauthorised staff. In particular, for the filing of documents containing employees' personal data relating to the employment relationship, the authority indicates the need for differentiated and confidential procedures.
Three declared elements weigh in the quantification: that the authority has provided guidance to public and private employers on the correct handling of data in the employment relationship since 2007; that the violation concerned all personal data passing through the register, not just the single document; and that the processing also involved sensitive material relevant to disciplinary matters.
That last point is worth pausing on. The notification says one data subject, and that is correct: only one person suffered concrete harm. But the misconfiguration was not about one document, it was about the way the register worked. The difference between "a case" and "a structural defect" is exactly what the authority puts at the centre.
What to take away, if you run a document register
Confidentiality level is data, not a label. Marking a document confidential achieves something only if the system translates that mark into an effective permission. If the authorisation profile overrides the document classification, the label is decorative.
"Technical" privileges are not neutral. Thirty users with IT privileges are not thirty system administrators: they are thirty people who, to perform an operational task, received a visibility level designed for a different task. It is the most common way a permission widens: not by decision, by accumulation.
Personnel documents want a separate track. It is the most concrete prescription in the decision: records concerning the employment relationship — and all the more so disciplinary proceedings — need differentiated and confidential filing procedures, not the same flow as any routine resolution.
Run a test, not a paperwork review. The useful question is not "what permissions did I assign", it is "what does someone with profile X actually see". Those two answers diverge with remarkable ease, and this case shows who notices first: the person with the document in front of them.
A note on sourcing: the facts and quotations come from the decision published by the authority and the accompanying newsletter. In the published text, names, internal dates and file numbers are partly redacted by the authority itself, and we have not reconstructed them.