The case, explained
Privacy Authority Sanction in the Rome Fetus Cemetery Case
6 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
Recent developments concern the findings regarding the management of personal data at a cemetery in Rome, closing a legal chapter that began with the discovery of women's names exposed on wooden crosses. According to press reports, the case highlighted a bureaucratic practice that for years ignored the right to privacy concerning health and reproductive choices. The case involved a municipal company, a municipal entity, and a local health authority, called to account for a structural violation of the GDPR. Through the reconstruction of the facts and the analysis of Gaio Sventura's twin case, we will explore how the automatism of mortuary police regulations must now yield to the protection of hypersensitive data.

In brief
The article analyzes the Privacy Authority's measures against a municipal company, a municipal entity, and a local health authority for placing mothers' names on fetus burials without consent. The focus is the conflict between the Mortuary Police Regulation and the GDPR, highlighting how the publication of health data requires specific legal bases and compliance with the minimization principle. The liability of the Data Controller is examined, even in the presence of established administrative practices.
The fact
The case originated following the complaint of a citizen who discovered her identity publicly displayed at a cemetery in Rome corresponding to the burial of a fetus following a pregnancy termination. According to media reports, the practice of placing the woman's name on the crosses was systematic and occurred without any information notice or explicit consent.
The investigation established that the data lists, transmitted by health authorities to the cemetery management company, contained complete information (name, surname, tax code) which was then transcribed onto plaques visible to anyone visiting the area. The procedural framework led to appealable administrative measures by the Privacy Authority, which sanctioned a municipal company and a municipal entity, while only admonishing the involved local health authority, for the unlawful processing of special categories of data.

The rules at play
The regulatory focus is represented by the provisions of the GDPR establishing a general prohibition on processing special categories of data, including those relating to health and reproductive life, except for specific statutory exemptions. The principles of the regulation mandate compliance with data minimization, prescribing that processed information must be adequate, relevant, and limited to what is necessary in relation to the purposes.
The conflict arises with the Mortuary Police Regulation, specifically the provisions governing the burial of products of conception. However, this regulation does not mandate making the mother's identity public on the tombstone, merely requiring internal administrative traceability. The violation of security and transparency obligations completes the framework of the sanctions imposed.
What case law says
Administrative and high court case law has clarified that the right to privacy regarding data revealing health status is inviolable, even in the face of long-standing administrative practices. Established case law clearly distinguishes between internal identifiability (official registers accessible only to those with a legitimate interest) and external identifiability through public display.
The courts have reiterated that the manager of a public service cannot invoke the instructions of a health authority as a defense if such instructions are clearly in conflict with data protection law. The principle of data controller accountability requires every entity in the chain to independently verify the lawfulness of data disclosure, especially when concerning the intimate sphere of the individual.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Data Protection Impact Assessment (DPIA): conducting a prior risk analysis is mandatory when processing health data on a large scale in publicly accessible contexts.
- Hierarchy of sources: as European law, the GDPR overrides local regulations or administrative circulars that fail to guarantee equivalent protection standards.
- Liability of operating entities: legal counsel must advise clients that acting as an executing party does not release an entity from verifying treatment lawfulness whenever decision-making autonomy exists regarding technical display methods.
Update and rectification note (17 September 2026)
The previous version of this article incorrectly stated that the local health authority had been fined, whereas it only received an admonishment. Furthermore, it omitted the involvement of the municipal entity (which was fined) and described the Authority's measures as 'definitive' rather than appealable. In the absence of available primary sources, the text has been corrected and the real parties have been anonymized in accordance with editorial rules.
References: Regolamento Generale sulla Protezione dei DatiCodice in materia di protezione dei dati personaliRegolamento di Polizia Mortuaria
Related cases

Frequently asked questions
Is it possible to display the mother's name on the burial if she has given consent?
Yes, provided that explicit, free, and informed consent has been obtained. In the absence of such consent, strict protection of anonymity for special categories of data prevails.
What are the risks for public managers who issue measures contrary to the GDPR?
In addition to administrative fines levied against the entity, public managers may face proceedings for financial loss to the public treasury before the Court of Auditors, as well as disciplinary actions.
How can a data subject verify whether their health data has been unlawfully disclosed?
By exercising the right of access with the Data Controller, requesting confirmation of data processing and the specific methods of communication or disclosure used.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free