Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Digital Cemetery Platforms and the Breakdown of Data Governance Chains
Acquired Record: garanteprivacy.it

Digital Cemetery Platforms and the Breakdown of Data Governance Chains

garanteprivacy.itItalia2026public
#privacy#gdpr#comune di ancona#garante privacy#servizi cimiteriali#protezione dati

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Executive Lead

Municipal digitalization initiatives increasingly delegate public registry management to commercial mobile applications without maintaining strict regulatory oversight. When digital cemetery registries and memorialization services blur the lines between administrative record-keeping and commercial user tracking, the statutory protections governing citizens and deceased individuals collapse into jurisdictional ambiguity.

A critical investigation into outsourced municipal digital platforms demonstrates how administrative chain-of-custody failures leave sensitive registry information vulnerable to commercial misallocation. The intersection of local authority delegation, multi-tiered subcontracting, and posthumous privacy rights reveals a systemic enforcement gap across public sector software deployments.

Historical and Institutional Context

The transformation of public cemetery administration from physical ledgers to cloud-based management platforms began as a municipal efficiency drive across European local authorities. Under the framework of Italian Legislative Decree no. 196/2003, local administrations initially structured vendor agreements around localized service provisions, such as physical votive lighting management and basic registry indexing.

As digital platforms evolved, municipal authorities sought comprehensive digital solutions capable of mapping grave plots, managing memorial tributes, and offering remote interaction for relatives. However, the contractual foundations governing these relationships frequently failed to adapt to modernized data protection requirements introduced by the European General Data Protection Regulation (Regulation EU 2016/679).

Historical records show that formal designations dating back to municipal mayoral decrees established legacy frameworks that persisted without adequate updates. In many jurisdictions, public service agreements originally drafted exclusively for mechanical or electrical upkeep were casually repurposed to cover comprehensive cloud application suites, creating substantial regulatory discrepancies.

The administrative shift accelerated with the integration of specialized applications designed to aggregate deceased records, geolocation data, and registered user profiles. This technological expansion created a fragmented operational architecture where municipal entities, in-house public utilities, and private software intermediaries operated across conflicting legal definitions of data control.

Key Entities and Structural Actors

The institutional ecosystem surrounding municipal cemetery app deployments involves public territorial authorities, intermediary operational bodies, and multi-layered software development vendors operating under distinct contractual mandates.

Public and Institutional Bodies

The Municipality of Ancona served as the original statutory data controller, maintaining legal ownership of municipal civil status and cemetery registry records while delegating administrative operations to external entities through historical executive decrees, including Mayoral Decree no. 139/2008.

The public utility company AnconAmbiente operated as an intermediate institutional entity tasked with local operational management. Under municipal delegation, this body executed direct procurement procedures for technological solutions and entered into downstream agreements with external software service providers.

The Italian Data Protection Authority acted as the national supervisory authority responsible for enforcing compliance under the framework of the General Data Protection Regulation and national legislative provisions governing administrative transparency and civil data rights.

Commercial and Technical Intermediaries

The corporate entity ISSAM Consultancy LTD entered into contractual arrangements as a designated data processor under Article 28 of the GDPR, holding structural responsibility for technical service provision and system-level data management operations.

The software development enterprise STUP 1 S.r.l.s. operated as a sub-processor designated by ISSAM Consultancy LTD to process user registry data for the Aldilapp platform, while simultaneously engaging in direct software provision contracts with the local public utility.

Critical Analysis of Evidence and Governance Failures

A rigorous examination of public records, contractual instruments, and supervisory notices uncovers profound structural disconnects within the administrative processing chain. Rather than a unified data management workflow, the architecture presents significant regulatory fragmentation.

Contractual Ambiguity and Scope Repurposing

Contractual documentation reveals that formal processor designation instruments suffered from severe title and scope discrepancies. Agreements formally designated under specific operational headings were retroactively treated as catch-all authorizations for unrelated digital processing activities.

“The subsequent deed of designation, pursuant to art. 28 of Regulation EU 2016/679, for the sake of brevity alone, bears as its title the wording of the ‘votive lamp service’, but in reality this agreement authorizes the processor to process the entire list of services carried out by the operator.”

This contractual conflation demonstrates a fundamental breakdown in the principle of purpose specification. When a legal agreement titled for simple utility lighting is leveraged to govern mobile application databases, geolocation tracking, and biometric or familial registries, the legal basis of processing becomes inherently compromised.

Multi-Tiered Delegation and Sub-Processor Friction

The operational chain between public authority and technical provider involved an opaque distribution of responsibilities. While AnconAmbiente enacted a direct award to STUP 1 S.r.l.s. for software supply, parallel agreements designated ISSAM Consultancy LTD as the external processor, which subsequently re-designated STUP 1 S.r.l.s. as a sub-processor for handling user registries.

This fragmented delegation model generated conflicting data ownership claims. The platform deployed two distinct privacy notices (designated Information Notices A1 and A2) to end users, simultaneously asserting separate data controller roles and confusing platform visitors regarding who held legal authority over their processed data.

“The concept of data controller should not be confused with other concepts, sometimes conflicting or coinciding, typical of other fields of law, such as that of author or holder of intellectual property rights or competition law.”

The supervisory record firmly rejects the argument that technical vendors can independently alter processing parameters to claim autonomous data control. When administrative clarity is missing in the foundational Article 28 instrument, processing ambiguity directly stems from institutional failure rather than unilateral vendor action.

The Post-Mortem Data Boundary and Civil Rights

A central vulnerability exposed by this architecture involves the legal treatment of deceased individuals’ records. While Recital 27 of the GDPR provides a safeguard clause allowing European Union Member States to regulate posthumous data processing, the Italian legal framework establishes explicit mechanisms under Article 2-terdecies of the Privacy Code.

“The rights referred to in Articles 15 to 22 of the Regulation relating to personal data concerning deceased persons may be exercised by those who have an interest of their own, or act to protect the interested party, as their agent, or for family reasons deserving protection.”

The operational evidence shows that while vendors claimed to process exclusively deceased records—theoretically attempting to bypass general GDPR provisions—the integration of user profiles, self-declarations, and administrative delegation inevitably captured living personal data. The failure of public entities to receive or properly route statutory requests under Article 2-terdecies underscores a total absence of functional rights-management workflows within the app interface.

Unresolved Questions in Public Tech Procurement

The documentary evidence leaves critical operational questions unanswered. It remains undetermined how local public authorities evaluate technical and organizational safeguards when granting direct commercial awards for public records management platforms.

Furthermore, the persistent reliance on legacy decrees pre-dating modern European privacy frameworks highlights widespread administrative inertia. Local administrations frequently transfer operational risk to private micro-enterprises without maintaining ongoing oversight mechanisms or verifying whether sub-processor chains maintain active, compliant data separation.

Transparency and Legal Framework

This investigation is established on primary public administrative records and formal supervisory findings issued under Italian Law no. 689/1981 and Article 166 of the Italian Personal Data Protection Code. These instruments document official regulatory compliance inquiries regarding municipal administration and third-party software procurement.

In accordance with Article 5 of Italian Law no. 633/1941, official texts of state acts and public administrative proceedings are exempt from copyright restrictions and belong fully to the public domain. The complete administrative documentation is accessible via the Italian Data Protection Authority register under official proceeding reference Provvedimento del 12 febbraio 2026, Docweb n. 10225650, accessible through garanteprivacy.it.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Comune e/o Gestore Cimiteriale) […] copia dell’autocertificazione rilasciata da parte dell’utente” nonché le richieste trasmesse “ex art. 2terdecies D.Lgs. 196/2003 co. 1 (n.d.r. amministratori del profilo)” tramite la piattaforma” (cfr. nota del XX, pp.
  2. Pertanto, la STUP è designata da ISSAM responsabile del trattamento ai sensi dell’art. 28 del Regolamento, per il trattamento di dati personali concernenti: “Anagrafiche degli utenti della piattaforma Aldilapp;
  3. XX in virtù di diverso antecedente atto di oggetto analogo, la designazione è stata effettuata con apposito decreto sindacale n. 139/2008.
  4. Infatti, già prima dell'entrata in vigore del Regolamento Europeo 2016/679, il Comune di Ancona, quale Titolare, ha nominato la società quale Responsabile sulla scorta del D.lgs. n. 196/2003, […e] Il successivo atto di designazione […], ai sensi dell'art. 28 Reg.
  5. UE 2016/679, solo per brevità, riporta come titolo la dicitura del “servizio di lampade votive”, ma in realtà tale accordo autorizza il responsabile al trattamento dell'intero elenco dei servizi svolti dal gestore […]” (cfr. nota del Comune del XX p.
  6. L’articolo 11 del medesimo (rubricato “Tutela della Privacy”) prevede in primis il ruolo di titolare del trattamento in capo al Comune di Ancona e quello di responsabile del trattamento in capo alla Società con esclusivo riferimento alle designazioni che verranno in seguito effettuate.
  7. Il ruolo di STUP 1 S.r.l.s., […] è quello di responsabile del trattamento, ai sensi dell’articolo 28 GDPR […].
  8. Al riguardo, in data XX, AnconAmbiente ha provveduto ad un affidamento diretto nei confronti di STUP 1 S.r.l.s. per la fornitura dell’App concernente i servizi cimiteriali […] In aggiunta, si sottolinea che AnconAmbiente ha sottoscritto un accordo, ai sensi dell’articolo 28 GDPR, con il responsabile del trattamento “ISSAM Consultancy LTD” […].
  9. Infatti, nei predetti accordi ex art. 28 GDPR gli unici dati personali oggetto del trattamento per conto della Società risultavano essere riferiti ai defunti medesimi. […] AnconAmbiente ad oggi, non ha mai ricevuto alcuna istanza di esercizio dei diritti ai sensi dell’articolo 2-terdecies Codice Privacy.
  10. Il Comune, con l’atto sopra citato, è stato invitato a produrre al Garante scritti difensivi o documenti ovvero a chiedere di essere sentita dall’Autorità (art. 166, commi 6 e 7, del Codice, nonché art. 18, comma 1, dalla legge 24 novembre 1981, n. 689).
  11. Inoltre, “si considera identificabile la persona fisica che può essere identificata, direttamente o indirettamente, con particolare riferimento a un identificativo come il nome, un numero di identificazione, dati relativi all’ubicazione, un identificativo online o a uno o più elementi caratteristici della sua identità fisica, fisiologica, genetica, psichica, economica, culturale o sociale” (art. 4, par. 1, n. 1).
  12. In ambito nazionale, l’art. 2-terdecies (Diritti riguardanti le persone decedute) del Codice prevede, tra l’altro, che “i diritti di cui agli articoli da 15 a 22 del Regolamento riferiti ai dati personali concernenti persone decedute possono essere esercitati da chi ha un interesse proprio, o agisce a tutela dell'interessato, in qualità di suo mandatario, o per ragioni familiari meritevoli di protezione”.
  13. Il titolare del trattamento è tenuto altresì, in ogni caso, a rispettare i principi in materia di protezione dei dati personali, di cui all’art. 5 del Regolamento, fra cui quello di “liceità, correttezza e trasparenza”, in base ai quali i dati personali devono essere “trattati in modo lecito, corretto e trasparente nei confronti dell’interessato” (art. 5, par. 1, lett. a), del Regolamento).
  14. In aggiunta, nelle Linee guida 07/2020 sui concetti di titolare del trattamento e di responsabile del trattamento ai sensi del Regolamento, adottate dal Comitato europeo per la protezione dei dati il 7 luglio 2021, si rappresenta che “L’obbligo di impiegare solo responsabili del trattamento «che presentano garanzie sufficienti», ai sensi dell’articolo 28, paragrafo 1, del […Regolamento] è un obbligo permanente.
  15. Linee guida 8/2020 sul targeting degli utenti di social media Versione 2.0 adottate dal CEPD il 13 aprile 2021, parr. 1 e 2).
  16. Con riguardo ai dati personali delle persone decedute, il Regolamento prevede la “clausola di salvaguardia” (considerando n. 27), riconoscendo la facoltà agli Stati membri di “prevedere norme riguardanti il trattamento dei dati personali delle persone decedute”.
  17. Inidonea regolamentazione dei rapporti tra i soggetti coinvolti nel trattamento ai sensi dell’art. 28 del Regolamento Nell’ambito dei servizi erogati in Applicazione, vengono fornite agli utenti due informative distinte (le citate informativa A1 e A2), in cui sono indicate distinte titolarità del trattamento.
  18. XX), atteso che “Il concetto di titolare del trattamento non dovrebbe essere confuso con altri concetti, talvolta contrastanti o coincidenti, propri di altri campi del diritto, come quello di autore o di titolare dei diritti in materia di proprietà intellettuale o di diritto della concorrenza” (cfr. delle citate Linee guida 7/2020, par. 13).
  19. Né si condivide l’affermazione che il gestore abbia disatteso le istruzioni fornite dal Comune per quanto concerne il trattamento dei dati personali, divenendo esso stesso titolare ai sensi dell’art. 28, par. 10 del Regolamento (cfr., da ultimo, memoria difensiva del XX, p.
  20. XX) per aver determinato mezzi e finalità del trattamento posto che la confusione in merito al ruolo svolto dal gestore è derivata, altresì, da una mancanza di chiarezza proprio nell’atto stipulato ai sensi dell’art. 28 del Regolamento.
Click to switch theme:

Comments (0)