Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
State Museum Video Surveillance Ruled Unlawful Over Worker Safeguards and Public Street Filming
Acquired Record: garanteprivacy.it

State Museum Video Surveillance Ruled Unlawful Over Worker Safeguards and Public Street Filming

garanteprivacy.itItalia2025public
#videosorveglianza#ministero della cultura#statuto dei lavoratori#campobasso#protezione dati#musei statali

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Oversight of Institutional Video Surveillance

The boundary between safeguarding cultural heritage and protecting citizen privacy remains one of the most contentious battlegrounds in public administration. When public cultural institutions deploy digital monitoring systems without procedural safeguards, security measures rapidly transform into unlawful employee surveillance and unchecked public tracking. The regulatory intervention into the National Archaeological Museum of Campobasso demonstrates that administrative mandates for security cannot override statutory workplace protections and data protection frameworks.

Surveillance systems operating across public pathways and administrative workspaces require rigorous adherence to legal standards before activation, rather than post-facto regularizations. In this case, monitoring devices captured both the internal workspace and an adjacent municipal alleyway, raising immediate concerns over systematic data processing without mandatory workplace agreements or statutory impact assessments. The enforcement action against the competent regional museum authority establishes an essential legal benchmark for public sector accountability.

The administrative case reveals how administrative bodies frequently misinterpret statutory security obligations as an exemption from privacy compliance. By examining the evidentiary record, procedural timelines, and institutional defenses, this dossier unpacks the systemic compliance failures that led to formal sanctions against the Ministry of Culture’s regional administration.

Context, Chronology, and Institutional Precedents

Under Italian and European jurisprudence, the deployment of audiovisual recording equipment in locations where staff perform their duties is governed by strict, dual-layered legal constraints. While Article 6(1)(e) of the General Data Protection Regulation (GDPR) allows processing necessary for the performance of a task carried out in the public interest, Article 88(2) and Article 6(2) explicitly preserve national provisions offering enhanced workplace protections. Specifically, Article 4 of Law No. 300/1970 (the Workers’ Statute) mandates that any monitoring device capable of remote employee oversight must be preceded by a formal collective agreement with trade union representatives or an authorization from the territorial labor inspectorate.

For state-run cultural sites, a statutory tension has long persisted between workplace privacy and patrimonial asset protection. Decree-Law No. 433 of November 14, 1992, mandates the adoption of audiovisual security systems to prevent theft and damage in national museums. However, administrative bodies frequently make the erroneous assumption that this security mandate supersedes the procedural obligations outlined in labor and privacy legislation.

The timeline in Campobasso began when an active staff member assigned to the National Archaeological Museum of Campobasso lodged a formal complaint under Article 77 of Regulation (EU) 2016/679. The employee reported that video recording devices had been operational without providing the required statutory notices or establishing the mandatory prior agreements with workplace trade union representatives.

Upon formal inquiry by the regulatory authority pursuant to Article 157 of the Italian Personal Data Protection Code, the regional administration attempted to cure the procedural omission. The data controller entered into an agreement with workplace trade union representatives on June 25, 2025—months after the surveillance system had already been actively processing data and only following the commencement of the regulatory investigation. This retrospective agreement exposed a fundamental flaw in the institutional deployment strategy, confirming that the system had operated outside the bounds of legality during its initial deployment phase.

Institutional and Administrative Entities Involved

The enforcement dossier involves several primary institutional actors and administrative bodies operating within the Italian cultural and regulatory landscape:

The Data Controller

The processing entity held accountable in this matter is the Ministero della Cultura through its territorial branches: the Parco Archeologico di Sepino and the Direzione Regionale Musei Nazionali Molise. As the state administration managing the National Archaeological Museum of Campobasso, this entity bore direct legal responsibility for defining the purposes, technical specifications, and legal grounds of the video monitoring infrastructure.

The Complainant and Cultural Heritage Facility

The complainant is an employee on active duty at the Museo Archeologico Nazionale di Campobasso, situated within the historical district of the municipality of Campobasso. The operational context encompasses both the public exhibition rooms and the historic pedestrian stairway directly outside the building entrance.

The Supervisory Authority and Trade Union Representatives

The regulatory review was conducted by the Italian Data Protection Authority (Garante per la protezione dei dati personali) pursuant to powers granted under Articles 58 and 83 of the GDPR and Article 166 of Legislative Decree No. 196/2003. The labor representatives involved in the subsequent union accord include the internal workplace union structures operating within the regional museum directorate.

Critical Analysis of the Evidentiary Record

An exhaustive analysis of the technical and documentary evidence highlights three primary vectors of non-compliance: the spatial overreach of the optical sensors, the complete absence of a prior Data Protection Impact Assessment (DPIA), and deficiencies in public and employee transparency notices.

Spatial Configuration and Excessive Public Alleyway Monitoring

The technical configuration of the exterior camera presented significant disproportionality. According to the technical records, the camera mounted at the museum entrance was configured with a wide-angle lens directed toward a public pedestrian alleyway in the historic center of Campobasso. This alleyway, characterized by a pedestrian stairway, measures approximately 3.90 meters in width in the affected sector.

«L’angolo di visuale della telecamera posizionata all’ingresso del Museo stesso e ritraente la pubblica via era impostata in modalità grandangolo […] trattasi di vicolo pedonale sito nel centro storico del Comune di Campobasso con scalinata, della sezione di circa 3,90 metri nel tratto interessato.»

By capturing a public thoroughfare spanning the full 3.90-meter width, the system processed personal data of pedestrians, residents, and visitors who had no intention of entering the museum facility. European Guidelines 3/2019 on processing personal data through video devices strictly require that monitoring be restricted to the immediate perimeter of the protected building, unless exceptional and documented security threats justify broader coverage. The museum administration failed to provide objective evidence demonstrating why a narrow entranceway required wide-angle capture of a public urban passage.

The Failure to Conduct a Prior Impact Assessment

Because the video system conducted continuous visual monitoring over an accessible municipal space and an exhibition area, a mandatory Data Protection Impact Assessment under Article 35(3)(c) of the GDPR was required prior to turning on the devices. The statutory framework explicitly mandates a DPIA when an entity undertakes systematic, large-scale monitoring of a publicly accessible area.

«Stante l’attivazione del sistema di videosorveglianza in un’area museale, la valutazione di impatto sulla protezione dei dati personali era, in ogni caso, dovuta anche sulla base di quanto previsto dall’art. 35, par. 3, lett. c), del Regolamento, essendo stata posta in essere una “sorveglianza sistematica su larga scala di una zona accessibile al pubblico”.»

A prior impact assessment would have forced the data controller to systematically calibrate camera angles, assess optical depth, and mitigate risks to passersby and employees. The omission of the DPIA eliminated the preliminary proportionality check mandated by Article 35(7)(b) of the Regulation.

Transparency Deficits and Informational Misclassifications

The investigation established that prior to May 12, 2025, the data controller failed to prove that adequate first-level warning signs were displayed at the monitored locations. While historical signage had been installed in November 2023 and subsequently replaced, the controller could not demonstrate that the earlier notices met the necessary transparency criteria established by European guidelines.

Furthermore, an examination of the updated first-level signage revealed notable compliance errors. The physical sign contained a structural misclassification, designating the internal contact as the “responsabile trattamento dati” (data processor) rather than the statutory “responsabile della protezione dei dati” (Data Protection Officer). Additionally, while second-level information was accessible via an integrated QR code, the administration had failed to provide its employees with the specific labor-related disclosures required by Article 4(3) of Law No. 300/1970 regarding the modalities of use and inspection.

The Invalidation of the Cultural Heritage Defense

The core institutional defense presented by the regional museum directorate relied heavily on Article 1(1) of Decree-Law No. 433/1992, which mandates audiovisual systems for state museums. The administration argued that this statutory security obligation exempted it from negotiating union agreements or adhering strictly to ordinary procedural sequencing.

This legal argument was entirely rejected. Sector-specific security mandates cannot displace constitutional and European guarantees protecting workers from uncontrolled digital oversight. The supervisory authority confirmed that Article 4 of the Workers’ Statute operates as an indispensable national rule of greater protection under Article 88(2) of the GDPR. Consequently, the retroactive agreement signed on June 25, 2025, could not expunge the illegality of the prior operational period.

Transparency and Legal Framework

This investigation is based on the official administrative sanction order issued by the Italian Data Protection Authority on January 29, 2026 (Registry Number 10226639). The document represents a definitive public administrative act terminating the formal enforcement proceeding initiated against the territorial museum authority.

Under Article 5 of Italian Law No. 633 of April 22, 1941, official texts of legislative, administrative, and judicial acts of the State and public administrations are entirely exempt from copyright restrictions and belong to the public domain. The complete source text and related administrative records are publicly accessible via the institutional registry of the Garante per la protezione dei dati personali.

The supervisory authority imposed an administrative pecuniary fine pursuant to Articles 58(2)(i), 83(2), 83(3), and 83(5) of the GDPR, coupled with Article 166(7) of the Italian Privacy Code. By holding a state cultural institution accountable for surveillance overreach, this ruling reaffirms that public interest missions cannot serve as a pretext for bypassing fundamental privacy guarantees.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Con reclamo presentato ai sensi dell’art. 77 del Regolamento, il Sig. , lavoratore in servizio presso il Museo Archeologico Nazionale di Campobasso (di seguito, il “Museo”), ha lamentato una presunta violazione della disciplina in materia di protezione dei dati personali.
  2. Nel corso dell’attività istruttoria, l’Autorità ha rivolto al Ministero della Cultura - Parco Archeologico di Sepino - Direzione Regionale Musei Nazionali Molise (di seguito, il “Titolare”) una richiesta d’informazioni ai sensi dell’art. 157 del Codice (v. nota del XX, prot. n.
  3. XX), il Titolare ha poi provveduto produrre in atti copia dell’accordo stipulato in data XX con le organizzazioni sindacali, ai sensi dell’art. 4, comma 1, della l. n. 300/1970, in relazione al sistema di videosorveglianza in questione, dunque solo successivamente all’avvio dell’attività istruttoria.
  4. Con la medesima nota, il predetto titolare è stato invitato a produrre al Garante scritti difensivi o documenti ovvero a chiedere di essere sentito dall’Autorità (art. 166, commi 6 e 7, del Codice, nonché art. 18, comma 1, della l. 24 novembre 1981, n. 689).
  5. La base giuridica del trattamento è individuabile nell’articolo 6, paragrafo 1, lettera e) del Regolamento […]”; - “l’angolo di visuale della telecamera posizionata all’ingresso del Museo stesso e ritraente la pubblica via era impostata in modalità grandangolo […] trattasi di vicolo pedonale sito nel centro storico del Comune di Campobasso con scalinata, della sezione di circa 3,90 metri nel tratto interessato.
  6. In tale quadro, il datore di lavoro deve rispettare le norme nazionali di maggior tutela che regolano i trattamenti di dati personali nel contesto lavorativo (88, par. 2, del Regolamento, a cui fa rinvio l’art. 6, par. 2, del Regolamento).
  7. Come costantemente ribadito nei provvedimenti del Garante, i trattamenti conseguenti all’impiego degli strumenti tecnologici nei luoghi ove si svolge anche l’attività lavorativa, trovano la propria base giuridica nella disciplina di settore di cui all’art. 4 della l. n. 300/1970.
  8. Ciò comporta, pertanto, che il datore di lavoro deve rispettare le procedure di garanzia previste dall’art. 4, comma 1, della l. n. 300/1970 (accordo sindacale o, in alternativa, autorizzazione pubblica) allorquando ricorra a sistemi di videosorveglianza per il perseguimento delle finalità tassativamente ivi indicate.
  9. Nel caso di specie, il titolare non ha espletato le procedure di garanzia previste dall’art. 4 della l. n. 300/1970 prima di attivare il sistema di videosorveglianza in questione, essendosi provveduto a stipulare un accordo con le rappresentanze sindacali, ai sensi di tale disposizione, soltanto successivamente all’avvio dell’istruttoria, in data 25 giugno 2025.
  10. Non rileva, a tal riguardo, che, come anche sostenuto in sede di memoria difensiva, “l’attivazione e l’utilizzo del sistema di videosorveglianza, ai sensi dell’art. 1, comma 1, del d.l. 14 novembre 1992, n. 433, che impone nei musei statali l’adozione di strumenti audiovisivi di sicurezza”.
  11. Le informazioni di primo livello (cartello di avvertimento) “dovrebbero comunicare i dati più importanti, ad esempio le finalità del trattamento, l’identità del titolare del trattamento e l’esistenza dei diritti dell’interessato, unitamente alle informazioni sugli impatti più consistenti del trattamento” (“Linee guida 3/2019 sul trattamento dei dati personali attraverso dispositivi video”, cit., par. 114).
  12. Si precisa che la precedente cartellonistica era stata apposta dal novembre 2023 ed è stata di recente sostituita”; - “si allega [copia dell’informativa sul trattamento dei dati di secondo livello], precisando che l’informativa sul trattamento dei dati personali di secondo livello è raggiungibile tramite il QR-Code apposto sulla cartellonistica”.
  13. Non risulta, pertanto, comprovato che, nel periodo antecedente al 12 maggio 2025, fosse stata fornita agli interessati un’idonea informativa di primo livello relativa ai trattamenti di dati personali posti in essere nell’area museale mediante il sistema di videosorveglianza in questione.
  14. Deve, peraltro, farsi presente - per completezza - che l’attuale cartello informativo, fa erroneamente riferimento, probabilmente per un mero refuso, al “responsabile trattamento dati” in luogo del “responsabile della protezione dei dati” (riquadro n. 1).
  15. Ciò, inoltre, come detto, non avendo nemmeno il Titolare fornito ai lavoratori una specifica informativa sul trattamento dei dati personali mediante dispositivi video, anche a tutti i fini connessi al rapporto di lavoro (v. art. 4, comma 3, della l. n. 300/1970).
  16. Stante l’attivazione del sistema di videosorveglianza in un’area museale, la valutazione di impatto sulla protezione dei dati personali era, in ogni caso, dovuta anche sulla base di quanto previsto dall’art. 35, par. 3, lett. c), del Regolamento, essendo stata posta in essere una “sorveglianza sistematica su larga scala di una zona accessibile al pubblico”.
  17. Lo svolgimento di una valutazione di impatto sulla protezione dei dati, prima di dare avvio al trattamento, avrebbe consentito al titolare di effettuare le opportune valutazioni anche con riguardo a tale profilo, come elemento che concorre a definire la complessiva “necessità e proporzionalità dei trattamenti in relazione alle finalità” (art. 35, par. 7, lett. b), del Regolamento). 4.
  18. Adozione dell’ordinanza ingiunzione per l’applicazione della sanzione amministrativa pecuniaria e delle sanzioni accessorie (artt. 58, par. 2, lett. i e 83 del Regolamento; art. 166, comma 7, del Codice).
  19. Al riguardo, tenuto conto dell’art. 83, par. 3, del Regolamento, nel caso di specie la violazione delle disposizioni citate è soggetta all’applicazione della sanzione amministrativa pecuniaria prevista dall’art. 83, par. 5, del Regolamento.
  20. La predetta sanzione amministrativa pecuniaria inflitta, in funzione delle circostanze di ogni singolo caso, va determinata nell’ammontare tenendo in debito conto gli elementi previsti dall’art. 83, par. 2, del Regolamento.
Click to switch theme:

Comments (0)