The case, explained
Supreme Court on Unauthorized Access and Dossiering: The Misuse of Digital Power
6 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
Recent jurisprudential developments have marked a turning point in the definition of so-called digital dossiering. According to press reports, the core of the debate no longer concerns the technical breach of digital barriers, but rather the functional legitimacy of access by those who, despite possessing credentials, use them for purposes unrelated to their office. This article analyzes the Supreme Court's interpretation of Article 615-ter of the Criminal Code, distinguishing between a mere credential breach and the misuse of digital power. Through the reconstruction of the facts and the aid of a twin case, we will see how exceeding the assigned operational perimeter constitutes a crime even in the absence of technical forcing, with severe consequences for public officials and individuals performing a public service.

In brief
The article analyzes the Supreme Court's interpretation of the crime of unauthorized access to a computer system (Art. 615-ter c.p.) applied to recent dossiering cases. The focus is on the misuse of digital power: access is deemed unauthorized if its purposes are unrelated to institutional tasks, even where the user holds legitimate credentials. It examines applicable legal frameworks, liability profiles for public officials, and operational implications for protecting data confidentiality in public databases.
The fact
National news outlets have given extensive coverage to investigations concerning the creation of confidential dossiers on political and business figures. According to «Il Dubbio» and «Diritto e Giustizia», investigations conducted by the Public Prosecutor's Offices of Perugia and Milan have revealed a system of massive queries to protected databases, such as the SDI and suspicious activity reports (SOS). The investigations, currently at the preliminary investigation stage, showed that individuals possessing regular access credentials queried thousands of records without any investigative mandate or official justification. The core of the prosecution's case lies in the nature of the accesses: not mere curiosity, but a systematic collection of information aimed at private or political ends. Although the suspects were technically authorized to access the system, the Prosecution alleges the crime of aggravated unauthorized access, arguing that technical authorization does not permit the arbitrary use of data. The case awaits trial, but it has already prompted clarifying guidance from the Supreme Court on the concept of functional unauthorized access.

The laws at play
The central legal provision is Art. 615-ter c.p., which penalizes unauthorized access to a computer or telecommunication system. The provision sanctions not only forced entry into the system, but also remaining in it against the express or implied will of the person entitled to exclude others.
- Aggravating factor for public officials: paragraph 2, no. 1, increases the penalty to imprisonment from one to five years if the offense is committed through abuse of powers or breach of duties inherent to the function or service.
- Breach of official secrecy: Art. 326 c.p. penalizes public officials or public service agents who disclose official information required to remain confidential.
- Data protection: EU Regulation 2016/679 (GDPR) imposes security obligations and purpose limitation principles, the violation of which entails substantial administrative fines for the entity operating the database.
What the case law says
Case law from the Supreme Court has progressively shifted away from the technical breach criterion, embracing a functional and purpose-based approach. The United Sections have clarified that access is unauthorized whenever a user, even if holding valid credentials, performs activities objectively incompatible with the reasons justifying credential issuance and use. The core principle is that system authorization is granted solely for institutional duties. Recent rulings have confirmed that querying a database for personal curiosity, to benefit third parties, or for dossiering constitutes a misuse of digital power. In such cases, exceeding the objective boundaries established by system rules or by the public function exercised renders the conduct criminally relevant. Thus, the formal validity of access credentials is irrelevant when there is a substantive breach of duties of loyalty and confidentiality.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Traceability and auditability: lawyers advising public entities and corporations should recommend adopting logging systems that record not only access, but also the explicit operational justification for each query.
- Defense strategy: in criminal proceedings, defense counsel must focus on the functional justification of queries, producing documentary evidence of relevance to official duties.
- Organizational risk management: organizations must train staff that using official credentials for personal purposes is not merely a disciplinary breach, but constitutes a criminal offense.
- Contract drafting: regarding external consultants, access scopes and data handling permissions must be defined with precision to avoid allegations of unauthorized access.
References: Articolo 615-ter Codice PenaleArticolo 326 Codice PenaleRegolamento UE 2016/679 (GDPR)
Related cases

Frequently asked questions
What are the risks for an employee who accesses acquaintance data out of curiosity?
The employee risks conviction for unauthorized access to a computer system, with penalties exceeding three years' imprisonment if the system is of public interest, alongside disciplinary dismissal for cause.
Does possessing employer-provided credentials exclude criminal liability?
No. According to established Supreme Court case law, access is unauthorized if carried out for purposes unrelated to work duties, constituting a misuse of digital power.
Can a person affected by unauthorized access claim damages?
Yes, the data subject may bring a civil action against both the individual perpetrator and the entity owning the database for breaches of data protection laws.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free