Data protection as a criminal matter in Italy

Most people associate data protection with administrative fines. Italy also keeps criminal offences in the field: unlawful processing causing harm, unlawful disclosure of data on a large scale, fraudulent acquisition of personal data, false statements to the supervisory authority and failure to comply with its orders.
The offences
| Conduct | Position | Note |
|---|---|---|
| Unlawful processing causing harm | Criminal offence | Requires an intention to profit or to harm |
| Unlawful disclosure on a large scale | Criminal offence with a heavier bracket | Volume is the aggravating element |
| Fraudulent acquisition of personal data | Criminal offence | Obtaining data by deception |
| False statements to the authority | Criminal offence | In the course of proceedings before it |
| Failure to comply with an order | Criminal offence | Non-compliance with a measure |
| Administrative fines | Separate track | Under the European regime |
The element that limits the first offence is intention: processing carried out to make a profit or to cause harm. Sloppy processing, however serious the administrative consequences, is not the criminal offence — and drawing that line is the substance of most defences here.
The charge that usually comes with it
In practice these cases rarely arrive alone. They arrive with unauthorised access to a computer system, which in Italian law covers using credentials you were legitimately given for a purpose outside your authorisation.
That combination catches employees and former employees: taking a client list on departure, consulting records without a business reason, retaining access after leaving. The employer's complaint frames it as data protection; the prosecutor charges the access offence as well, and that is the more serious one. The framework is in cybercrime charges in Italy.
Where a company is involved
Three exposures run at once and they are frequently confused. Administrative proceedings before the supervisory authority; criminal proceedings against the individuals who processed the data; and, where the offences are among those listed, proceedings against the entity itself under the corporate liability regime.
- Establish immediately which track each communication belongs to: they have different deadlines and different rules on what can be used.
- Statements made to the supervisory authority are documents, and they end up in the criminal file.
- An internal investigation generates material that is discoverable and should be conducted on that assumption.
- Where devices are seized, the ordinary rules on forensic copying and on notice to the defence apply.
Internal investigations and monitoring
A recurring Italian problem for foreign companies: monitoring employees is restricted by employment law as well as by data protection, and evidence gathered in breach of those rules can be unusable — and the gathering itself can found a charge.
So an internal investigation that would be unremarkable in another jurisdiction can produce two adverse results here: the evidence is excluded, and the company is exposed. Checking the position before collecting is considerably cheaper than after.
If your data was taken
Where personal data has been unlawfully disclosed, taken or used, the criminal route exists alongside the complaint to the supervisory authority, and the two are not alternatives. The route for injured parties is in the guide for victims of crime in Italy.
Frequently asked questions
Can data protection breaches be criminal in Italy?
Yes. Unlawful processing causing harm, large-scale unlawful disclosure, fraudulent acquisition of data and non-compliance with the authority's orders are criminal offences.
Is every breach a crime?
No. The principal offence requires an intention to profit or to cause harm, so poor practice without that intention remains an administrative matter.
An employee took our client list.
That is usually charged as unauthorised access to a computer system as well, since using valid credentials for a purpose outside the authorisation is covered.
Can we investigate internally first?
With care. Monitoring is restricted by employment law as well as data protection, and material gathered in breach can be unusable and can itself found a charge.
If a matter has opened
Which track a communication belongs to determines what should be answered and when. First contact is free and covered by professional privilege.
