Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Automated Traffic Enforcement and Municipal Surveillance Governance
Acquired Record: garanteprivacy.it

Automated Traffic Enforcement and Municipal Surveillance Governance

garanteprivacy.itItalia2026public
#videosorveglianza#codice della strada#protezione dati#valutazione impatto#garante privacy#pubblica amministrazione

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and the Expanding Municipal Surveillance Apparatus

Municipal administrations across Europe are increasingly automating civic enforcement through optical surveillance and algorithmic traffic monitoring. The widespread installation of optical recording devices capable of cross-referencing vehicle movements with administrative registries alters the fundamental balance between public oversight and individual privacy. When public authorities deploy systemic monitoring tools without meeting basic regulatory safeguards, automated governance shifts from legitimate law enforcement into unmonitored mass surveillance.

This investigation scrutinises the operational breakdown that occurs when local entities enforce road regulations through automated digital systems while failing to conduct mandatory risk assessments or provide lawful public notices. The systemic reliance on digital video hardware to process civic data places an affirmative duty on public bodies to ensure strict compliance with legal baselines before deploying invasive monitoring technologies against citizens.

The findings demonstrate how administrative automation, when decoupled from data governance frameworks, exposes municipal institutions to regulatory injunctions and financial penalties. The public interest demands absolute transparency regarding how municipal sensory devices collect, retain, and process spatial and vehicular movements across local transport networks.

Historical and Geopolitical Context: The Rush to Algorithmic Code Enforcement

Over the past two decades, local administrative bodies have undergone an accelerated transition toward digital policing. The primary catalyst has been the modernisation of municipal police workflows, driven by statutory frameworks such as Legislative Decree no. 285 of 30 April 1992, commonly known as the New Highway Code (Codice della Strada). Under provisions such as Article 80, local authorities hold statutory authority to verify vehicle roadworthiness and compliance through automated administrative checks.

However, the rapid adoption of high-resolution digital cameras and optical character recognition hardware outpaced institutional preparedness regarding fundamental data protection doctrines. While public safety and traffic regulation constitute recognized public interests, European supervisory frameworks strictly constrain how statutory bodies handle identifying imagery. The legal intersection between the Highway Code and the General Data Protection Regulation (GDPR) mandates that statutory power does not grant blanket exemptions from fundamental privacy protections.

Urban surveillance systems throughout Southern Europe have expanded rapidly, frequently financed through public safety modernisations and infrastructure renewal programs. Local councils often acquire sophisticated digital video suites without establishing the administrative architecture required to conduct privacy impact evaluations or maintain updated transparency registers, creating structural vulnerabilities across municipal networks.

The operational tension between local road enforcement and European privacy jurisprudence culminated in targeted enforcement actions against municipal entities. As supervisory authorities unified fine calculation standards through the European Data Protection Board (EDPB) Guidelines 04/2022, local councils found that informal compliance or retrospective adjustments could no longer shield administrative operations from formal sanction proceedings.

Key Entities and Institutional Actors

The primary administrative body central to this regulatory review is the Municipality of Mazara del Vallo, a local public administration located in the Province of Trapani, Sicily. Acting as a data controller under European law, the municipal body holds legal responsibility for all automated video processing and traffic monitoring apparatus deployed within its territorial jurisdiction.

The supervisory authority directing the investigation is the Italian Data Protection Authority (Garante per la protezione dei dati personali), an independent administrative body established under national and European law to supervise data processing operations, enforce statutory compliance, and issue binding injunctions against public and private controllers.

The dispute originated from an individual complaint filed pursuant to Article 77 of the GDPR and Article 141 of the Italian Personal Data Protection Code (Legislative Decree no. 196/2003). The citizen challenged the lawfulness of a formal violation notice issued under Article 80, paragraph 14 of the Highway Code, which had been generated directly through automated municipal video recording infrastructure.

The institutional dialogue also involved municipal technical departments and administrative enforcement units, operating under the regulatory parameters of Law no. 689 of 24 November 1981, which governs administrative sanctions, alongside the procedural mechanisms defined in Article 157 and Article 166 of the national Privacy Code.

Critical Analysis of the Evidence and Administrative Findings

The regulatory inquiry centered on whether a valid legal mandate under sector-specific traffic legislation absolves a municipal controller from the core transparency and preventive risk requirements codified in data protection law. The evidence reveals a structural failure across multiple operational levels of municipal surveillance deployment.

The Illusion of Sectoral Exemption

During the administrative defense proceedings initiated under Article 166 of the Privacy Code, the municipal controller contended that its video surveillance hardware was positioned exclusively to document statutory infractions under Article 80, paragraph 14 of the Highway Code. The municipality maintained that the visual frame captured only the essential technical data elements required for drafting the official citation, citing previous administrative guidance and institutional notes.

“Pur in presenza di una condizione di liceità del trattamento, il titolare è tenuto, in ogni caso, a rispettare i principi in materia di protezione dei dati, fra i quali quelli di liceità, correttezza e trasparenza.”

The regulatory authority rejected the defense that a lawful statutory purpose under Article 6 of the GDPR nullifies baseline compliance obligations. The evidentiary record established that while the municipality possessed institutional authority to monitor road safety, the operational execution directly violated Article 5, paragraph 1, letter (a), Article 6, paragraphs 1–3, and Article 2-ter of the national Privacy Code due to comprehensive transparency failures.

Systemic Breakdown of the Multi-Level Information Architecture

European regulatory doctrine establishes a mandatory two-tier information architecture for video surveillance operations. First-level notices consist of visible, standardized physical signage situated before entering camera coverage zones to warn individuals immediately. Second-level notices require exhaustive, readily accessible public documentation detailing data retention schedules, controller contact information, data subject rights, and the exact legal basis for processing.

The evidentiary investigation documented that the municipal authority completely failed to deliver compliant first-level signage to motorists. Furthermore, the administration failed to provide any second-level transparency policy prior to 30 January 2026. Even after that date, the revised documentation furnished by the administration remained legally deficient, violating Articles 12 and 13 of the GDPR.

“Risulta accertato che il Comune ha omesso di fornire agli interessati un’idonea informativa di primo livello, ha omesso di fornire agli stessi un’informativa di secondo livello fino al 30 gennaio 2026 nonché, dopo tale data, ha fornito agli stessi un’inidonea informativa di secondo livello.”

The Critical Absence of a Data Protection Impact Assessment

A pivotal finding in the regulatory assessment involves Article 35 of the GDPR, which mandates a prior Data Protection Impact Assessment (DPIA) whenever processing operations, particularly those involving systematic monitoring of public areas on a large scale, present significant risks to the rights and freedoms of natural persons. The municipality failed to conduct or document any DPIA prior to activating its automated video enforcement network.

The supervisory body explicitly rejected the notion that informational notices could substitute for an impact assessment. A DPIA functions as an indispensable preventive instrument designed to evaluate proportionality, assess technological risks, define camera focal limits, and restrict data retention periods before real-world deployment begins.

Remedial Procurement versus Verifiable Territorial Implementation

To mitigate potential sanctions, the municipal administration submitted documentation demonstrating the emergency procurement of 50 standardized physical warning signs bearing the label area videosorvegliata for progressive installation across its territorial jurisdiction. However, the regulatory analysis underscored that purchasing hardware or signage does not constitute verified operational compliance.

The supervisory authority observed that the municipality failed to provide conclusive factual evidence showing that the newly acquired signage had been fully and properly erected across all monitoring nodes. Consequently, corrective injunctions under Article 58, paragraph 2, letter (d) were imposed, compelling the controller to conform all active video processing operations to European standards within strict deadlines.

Sanction Determination and European Harmonisation Standards

In establishing the administrative pecuniary fine under Article 83, paragraphs 2, 4, and 5 of the GDPR, the regulator applied the harmonised framework outlined in the European Data Protection Board Guidelines 04/2022. Several mitigating and aggravating factors were formally weighed on the administrative record:

  • Subjective Element: The infringement was classified as negligent (colposo) rather than intentional, reflecting organizational oversight rather than malicious intent under Article 83(2)(b).
  • Nature of Data: The automated optical processing did not involve special categories of personal data under Article 9, falling under Article 83(2)(g).
  • Corrective Responsiveness: The administration initiated corrective signage acquisitions, although proof of comprehensive territorial deployment remained incomplete.

Transparency, Archival Provenance, and Legal Framework

This investigative dossier is constructed upon the formal administrative decision issued by the Italian Data Protection Authority under reference Provvedimento del 12 febbraio 2026 [10227910]. The source document represents a public administrative enforcement decree issued pursuant to supervisory powers codified in European and national statutes.

Under Law no. 633 of 22 April 1941, Article 5, official texts of state acts and public administrative decisions belong to the public domain and are exempt from copyright restrictions. The publication and analytical review of these enforcement instruments uphold fundamental democratic transparency principles regarding the exercise of state power and administrative accountability.

The administrative proceeding formally mandated the public dissemination of the injunction under Article 166, paragraph 7 of the Italian Privacy Code and Articles 16 and 17 of Garante Regulation no. 1/2019. The full official regulatory record remains accessible through the supervisory authority’s institutional repository at garanteprivacy.it/home/docweb/-/docweb-display/docweb/10227910.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Introduzione Con reclamo presentato in data XX ai sensi dell’art. 77 del Regolamento e dell’art. 141 del Codice, e successivamente regolarizzato in data XX, il Sig.
  2. XX ha lamentato una violazione della disciplina in materia di protezione dei dati personali da parte del Comune di Mazara del Vallo (di seguito, “Comune”), riguardante la ricezione di un verbale di contestazione dell’infrazione dell’art. 80 del D.Lgs. 30 aprile 1992, n. 285 (“Nuovo Codice della Strada”, o “C.d.S.”) accertata mediante sistema video.
  3. XX del XX), ai sensi dell’art. 157 del Codice, con note del XX e XX (rispettivamente, prot. nn.
  4. Il Comune, con l’atto sopra citato, è stato invitato a produrre al Garante scritti difensivi o documenti ovvero a chiedere di essere sentita dall’Autorità (art. 166, commi 6 e 7, del Codice, nonché art. 18, comma 1, dalla legge 24 novembre 1981, n. 689).
  5. II n. 12681 del 10 maggio 2023 e raccogliendo solo dati pertinenti e non eccedenti per il perseguimento delle finalità istituzionali del titolare, delimitando a tal fine la dislocazione e l’angolo visuale delle riprese in modo da non raccogliere immagini non pertinenti o inutilmente dettagliate.
  6. In particolare il fotogramma ha individuato unicamente gli elementi previsti dalla normativa di settore per la predisposizione del verbale di accertamento della violazione dell’art. 80 comma 14 […].
  7. Sulla liceità del trattamento All’esito dell’attività istruttoria, è emerso, in sintesi, che il Comune si è dotato di un sistema video anche per finalità di accertamento delle violazioni al C.d.S. e, con riferimento al caso di specie, in ossequio a tale finalità, ha notificato nei confronti del reclamante il verbale di accertamento per la violazione dell’art. 80, comma 14 del C.d.S.
  8. Pur in presenza di una condizione di liceità del trattamento, il titolare è tenuto, in ogni caso, a rispettare i principi in materia di protezione dei dati, fra i quali quelli di “liceità, correttezza e trasparenza”, in base ai quali i dati personali devono essere “trattati in modo lecito, corretto e trasparente nei confronti dell’interessato”, (art. 5, par. 1, lett. a), del Regolamento).
  9. Per le ragioni sopraesposte, risulta accertato che il Comune ha omesso di fornire agli interessati un’idonea informativa di primo livello, ha omesso di fornire agli stessi un’informativa di secondo livello fino al 30 gennaio 2026 nonché, dopo tale data, ha fornito agli stessi un’inidonea informativa di secondo livello, in violazione degli artt. 5, par. 1, lett. a), 12, par. 1, e 13 del Regolamento. 3.3.
  10. La predetta valutazione d’impatto, il cui adempimento è previsto dal citato art. 35 del Regolamento, si distingue, inoltre, dagli obblighi informativi (previsti, in particolare, dagli artt. 12, 13 e 14 del Regolamento, in ossequio al più generale principio di trasparenza di cui all’art. 5, par. 1, lett. a) del Regolamento).
  11. Alla luce delle considerazioni che precedono, non avendo redatto una valutazione d’impatto sulla protezione dei dati in relazione al sistema di videosorveglianza utilizzato, deve concludersi che il Comune ha agito in violazione dell’art. 35 del Regolamento. 4.
  12. Si confermano, pertanto, le valutazioni preliminari dell’Ufficio e si rileva l’illiceità del trattamento di dati personali effettuato dal Comune, per aver effettuato il trattamento di dati personali in violazione degli artt. 5, par. 1, lett. a), 6 parr. 1-3, 12, par. 1, 13 e 35 del Regolamento, nonché art. 2-ter, comma 1, del Codice.
  13. La violazione delle predette disposizioni rende applicabili le sanzioni amministrative previste dall’art. 83, parr. 4 e 5, del Regolamento, ai sensi degli artt. 58, par. 2, lett. i), e 83, par. 3, del Regolamento medesimo, come richiamato anche dall’art. 166, comma 2, del Codice. 5.
  14. Misure correttive (art. 58, par. 2, lett. d), del Regolamento) L’art. 58, par. 2, del Regolamento attribuisce al Garante il potere di “ingiungere al titolare del trattamento o al responsabile del trattamento di conformare i trattamenti alle disposizioni del presente regolamento, se del caso, in una determinata maniera ed entro un determinato termine” (lett. d).
  15. Si prende atto di quanto emerso in fase di istruttoria e si tiene conto di quanto dichiarato dal Comune circa l’aver “recepito l’invito all’adeguamento della cartellonistica di preavviso di “area videosorvegliata” e proceduto all’acquisto di n. 50 cartelli di “area videosorvegliata” e disposto la progressiva installazione sul territorio comunale” senza aver provveduto, tuttavia, a dare evidenza di tale aggiornamento.
  16. La predetta sanzione amministrativa pecuniaria inflitta, in funzione delle circostanze di ogni singolo caso, va determinata nell’ammontare tenendo in debito conto gli elementi previsti dall’art. 83, par. 2, del Regolamento.
  17. Deve, inoltre, considerarsi: - il carattere colposo della violazione (art. 83, par. 2, lett. b) del Regolamento); - che i trattamenti in questione non sono relativi a categorie particolari di dati (art. 83, par. 2, lett. g).
  18. Comitato europeo per la protezione dei dati, “Guidelines 04/2022 on the calculation of administrative fines under the GDPR” del 23 maggio 2023, punto 60).
  19. In tale quadro si ritiene, altresì, che, ai sensi dell’art. 166, comma 7, del Codice e dell’art. 16, comma 1, del Regolamento del Garante n. 1/2019, si debba procedere alla pubblicazione del presente capo contenente l'ordinanza ingiunzione sul sito Internet del Garante.
  20. Si rileva, infine, che ricorrono i presupposti di cui all’art. 17 del Regolamento n. 1/2019.
Click to switch theme:

Comments (0)