The case, explained
Striano-Laudati Dossiering Case: Unauthorized Access and Supervision Duties
8 min read · Updated August 2026 · Editorial oversight: Avv. Federico Papa
Recent developments in August 2024 regarding the so-called dossiering investigation, involving Lieutenant Pasquale Striano and Magistrate Antonio Laudati, have reignited the debate on the boundaries of legitimate access to institutional databases. According to national press reports, the investigation led by the Perugia Prosecutor's Office now focuses on the systematic querying of sensitive archives between 2019 and 2022, raising crucial questions about the internal control systems of the National Anti-Mafia Prosecutor's Office (PNA). While previous articles in this column examined device seizures and the use of computer interceptors, this contribution analyzes the conduct of individuals who, despite holding valid credentials, use the system for purposes unrelated to their official duties. The case is not merely a matter of judicial news, but serves as a testing ground for interpreting Article 615-ter of the Italian Criminal Code in high-profile public contexts. Through our recurring twin case, we will explore how case law distinguishes between formal authorization to access a system and the abuse of conferred powers, outlining the responsibilities of administrative leaders for so-called culpa in vigilando.

In brief
The article analyzes the Striano-Laudati investigation, focusing on unauthorized access to computer systems (Art. 615-ter of the Italian Criminal Code) by authorized users. It examines the orientation of the United Sections of the Supreme Court regarding the purpose of access and the potential liability of institutional leaders for lack of supervision. Through the twin case of Gaio Sventura in the Municipality of Roccamesta, it illustrates the criminal consequences of using public databases for private or political purposes, distinguishing formal legitimacy from the substantive illegality of the conduct.
The facts
The investigation, coordinated by Prosecutor Raffaele Cantone, is currently in the preliminary investigation phase and concerns over 33,000 accesses deemed anomalous to the SIVA, Serpico, and SDI databases. According to reports from outlets such as La Repubblica and Il Giornale, Finance Police Lieutenant Pasquale Striano, assigned to the National Anti-Mafia Prosecutor's Office, allegedly conducted massive queries of data regarding politicians, entrepreneurs, and public figures without investigative mandates or criminal proceedings to justify them. The investigative trigger followed a complaint filed by Defense Minister Guido Crosetto after news leaks in the press regarding his professional fees.
Magistrate Antonio Laudati's position is under scrutiny regarding the hypothesis that he coordinated or endorsed these activities by creating pre-investigative dossiers lacking real foundation. A central aspect of the investigation, highlighted by outlets like La Verità and Domani, concerns the structural vulnerability of the PNA's control systems, which allegedly allowed such conduct to persist for years. The defense of the suspects maintains the proactive and legitimate nature of the analyses within anti-mafia functions, denying any political dossiering purposes. At present, no judgments have been rendered, and the presumption of innocence applies to all individuals involved.

The legal framework
The core legal framework revolves around Art. 615-ter of the Italian Criminal Code, which penalizes unauthorized access to a computer system. The provision does not only sanction those who breach digital protections, but also those who, despite holding valid credentials, enter or remain in a system against the express or implied will of the system owner.
- The basic statutory penalty provides for imprisonment from one to five years.
- The aggravating circumstance for public officials or systems of public interest can increase the penalty up to ten years.
- Art. 326 of the Italian Criminal Code on the disclosure of official secrets also applies, punishing the dissemination of information required to remain confidential for justice purposes.
- Where documents are manipulated to justify searches, crimes of material or ideological forgery (Arts. 476 and 479 of the Italian Criminal Code) may be configured.
From an administrative and disciplinary liability perspective, personal data protection legislation and internal police regulations are key. Violating access protocols entails not only criminal sanctions, but also liability for lack of supervision on the part of managers if appropriate logging and monitoring systems were not established to prevent the improper use of databases. This aspect is governed mainly by disciplinary procedure rules and accounting liability for damage to the image of the Public Administration.
Case law trends
Supreme Court case law has established that access is deemed unauthorized not only when performed by an unauthorized third party, but also when a credentialed user acts for purposes unrelated to official duties. According to settled principles of the United Sections of the Supreme Court, what matters is the violation of objective limits arising from assigned tasks and instructions provided by the system owner.
- Merely subjective motivation is irrelevant, whereas the absence of an institutional justifying reason is decisive.
- Access performed for personal goals, sheer curiosity, or to favor third parties always constitutes unauthorized conduct, even if executed using valid personal credentials.
Regarding the liability of top management, case law clarifies that the duty of supervision must be measured against the concreteness of the organizational measures adopted. While strict criminal liability does not exist for the actions of subordinates, managers may be held liable in civil and disciplinary forums if the lack of systematic controls facilitated the illicit act. Administrative case law emphasizes that the Public Administration is subject to a heightened obligation to protect sensitive data, making judicial scrutiny of culpa in vigilando particularly strict in the case of national databases.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
Lessons for professionals
- Constantly monitor the compliance of internal database access policies, ensuring every login is traceable and linked to a specific case file or professional assignment.
- In criminal defense concerning Art. 615-ter of the Italian Criminal Code, focus the evidentiary strategy on proving the existence of an official service purpose, even if not formalized in a written order.
- Implement automated alert systems for anomalous or massive queries, as their absence underpins liability claims against top management.
- Train personnel on the boundary between proactive analysis powers and unauthorized consultation for private or journalistic purposes.
References: Articolo 615-ter Codice PenaleArticolo 326 Codice PenaleDecreto Legislativo 159/2011 (Codice Antimafia)Regolamento UE 2016/679 (GDPR)
Related cases

Frequently asked questions
What are the risks for someone entering a database with their own passwords for private reasons?
They risk a conviction for unauthorized access to a computer system (Art. 615-ter of the Italian Criminal Code), with penalties that can exceed five years of imprisonment if the individual is a public official.
Are the leaders of an entity always responsible for employees' unauthorized accesses?
In criminal law, liability arises only in cases of complicity or incitement to the crime; however, leaders may be held liable in civil, administrative, and disciplinary proceedings for failure to supervise or organizational deficiencies.
What can someone do if they discover they have been subject to dossiering?
They can file a criminal complaint and join the criminal proceedings as a civil party to claim compensation for material and non-material damages resulting from the violation of their privacy.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free