Public Interest and Workplace Surveillance
The unauthorized deployment of biometric tracking devices across public municipal facilities underscores a critical vulnerability in the governance of outsourced public services. When third-party service providers implement fingerprint scanners to monitor contracted custodial and maintenance personnel, fundamental questions emerge regarding proportionality, statutory lawfulness, and worker dignity under strict privacy frameworks.
This case demonstrates that technological surveillance cannot be unilaterally instituted as a casual substitute for administrative attendance verification. The direct involvement of law enforcement inspectors and national regulatory bodies highlights the ongoing systemic friction between digital contractor management tools and entrenched legal safeguards that categorically restrict the processing of sensitive biometric categories.
Institutional Framework and Chronology
The trajectory of this investigation originated within local administrative boundaries before escalating to national supervisory oversight. On December 18, 2024, the local police department of the Municipality of XX formally submitted a report to the national supervisory authority, signaling potential unlawful processing of employees’ biometric data by Depac Società Cooperativa Sociale a r.l., an entity contracted to provide municipal maintenance and cleaning operations.
Following this referral, the regulatory office initiated a preliminary inquiry on February 5, 2025, issuing a formal communication under Article 157 of the national Privacy Code requiring the cooperative to furnish comprehensive operational explanations. Despite statutory delivery, the company failed to provide any response, compelling the supervisory body to escalate the matter through judicial police channels.
To enforce compliance and establish the material facts on the ground, the authority delegated specialized inspection powers to the Nucleo Speciale Privacy e Frodi Tecnologiche of the Guardia di Finanza. On June 4 and 5, 2025, financial police units conducted on-site inspections at the company’s registered headquarters and subsequently at the operational municipal premises within the Province of Pavia.
During these inspections, law enforcement officers inspected both the municipal town hall and the local municipal warehouse and garage depot. Specialized officers discovered two distinct fingerprint recognition terminals actively deployed across these operational centers, extracting physical digital records that confirmed continuous biometric logging across sequential operational months for municipal service staff.
Entities and Institutional Actors
Depac Società Cooperativa Sociale a r.l.
The commercial entity under regulatory review is Depac Società Cooperativa Sociale a r.l., an operational social cooperative managing approximately 100 total employees across various territorial assignments. Within the municipal jurisdiction of the Municipality of XX, the enterprise executed outsourced municipal maintenance and cleaning contracts employing a dedicated unit of six workers stationed continuously since August 1, 2024.
The Municipality of XX and Local Police
The local municipal administration in the Province of Pavia served as the physical and contractual setting for the outsourced operations. The municipal police force functioned as the primary whistleblower, identifying the installation of electronic biometric hardware within public administrative spaces and transmitting formal notifications to national privacy regulators.
Guardia di Finanza (Nucleo Speciale Privacy e Frodi Tecnologiche)
The specialized technological investigations wing of the [[Guardia di Finanza|Q1142514]], Italy’s financial and economic law enforcement agency, operated under delegated regulatory authority. The unit executed official search, inspection, and forensic data acquisition measures across corporate and public premises pursuant to statutory investigative powers.
The National Supervisory Authority
The administrative authority responsible for safeguarding personal data evaluated the evidentiary record under domestic privacy statutes and European regulations. Acting under enforcement prerogatives, the body examined severe violations concerning special category data processing and administrative silence during statutory investigations.
Critical Analysis of the Evidentiary Record
The Legal Prohibition Against Biometric Time Tracking
The regulatory framework governing special category processing establishes a categorical baseline prohibition under Article 9(1) of Regulation (EU) 2016/679. While Article 9(2) outlines specific exceptions, national jurisprudence and Article 2-septies of the domestic Privacy Code strictly dictate that employee presence monitoring does not satisfy the threshold of legal necessity or statutory derogation required to harvest biometric identifiers.
“Tenuto anche conto di quanto previsto dall’art. 2-septies del Codice, l’ordinamento vigente non consente il trattamento di dati biometrici dei dipendenti per finalità di rilevazione della presenza in servizio.”
Prior regulatory precedents establish an unbroken doctrine confirming that fingerprint logging for staff attendance is inherently disproportionate. This regulatory position has been consistently affirmed through multiple formal injunctions, including decision no. 109 and no. 106 of February 22, 2024, decision no. 369 of November 10, 2022, and decision no. 16 of January 14, 2021, establishing absolute legal clarity on the impermissibility of such practices.
Forensic Findings and the Scope of Surveillance
Forensic data extraction conducted by the Guardia di Finanza documented the actual operational reach of the hardware. The technical extraction established that the terminal situated within the municipal maintenance garage recorded biometric entries for four manual workers from April 2025 through June 2025, while the device stationed at the town hall entrance captured data from two custodial workers dating back to September 2024.
The physical footprint of the equipment inside public administrative facilities directly contradicts foundational principles of data minimization and purpose limitation under Article 5(1)(c) of the General Data Protection Regulation. The records demonstrate continuous, automated biometric processing without identifiable safeguards, alternative clock-in mechanisms, or verifiable legal justifications.
Transparency Breaches and Total Regulatory Default
Beyond the primary illegality of biometric capture, the cooperative exhibited complete structural failure regarding administrative transparency. Under Article 13 and Article 5(1)(a) of the Regulation, employers must deliver unambiguous informational notices to personnel prior to initiating any specialized technical data treatments, an obligation that was entirely unfulfilled.
Furthermore, the entity’s complete failure to reply to the formal statutory demand issued on February 5, 2025, constituted an independent infraction under Article 157 of the Privacy Code. By ignoring official requests for information, the enterprise obstructed oversight, escalating an administrative verification procedure into an enforceable on-site search executed by technological police units.
Structural Questions Left Unresolved
The investigative records expose several unresolved operational questions regarding institutional oversight within public procurement. While the cooperative installed and operated the biometric terminals, the hardware resided directly inside municipal buildings and depots managed by public authorities, raising questions regarding the extent of municipal awareness prior to the police alert.
Additionally, the evidentiary record remains silent regarding whether biometric data was stored exclusively on local terminal memory boards or synchronized with remote corporate management servers. The technical architecture of data retention, encryption standards, and eventual data destruction protocols remained unclarified due to the initial absence of internal corporate processing records required under Article 30.
Transparency and Legal Foundation
The factual determinations and institutional findings analyzed in this dossier are derived from the official decision issued by the Italian Data Protection Authority (Garante per la protezione dei dati personali), formal Act of February 26, 2026, registered under document web reference 10233224.
This public document is accessible via the official institutional portal at garanteprivacy.it. Pursuant to Article 5 of Italian Law no. 633/1941, official texts of state acts, administrative decisions, and public enforcement records are excluded from copyright protection, ensuring unrestricted public access and transparent scrutiny of regulatory proceedings.

