Categories: Insights, Publications · News, Publications

Tag: Corte di Cassazione, Dismissal, GDPR


8 Jan 2025

Penalties may be imposed on the manager who accesses the computer system by using a subordinate’s credentials

Violates the employer’s directives (even if implicit, but clear) the employee who, although in a hierarchically superior position to the holder of the access credentials to a company’s IT system, has them revealed in order to gain access without specific authorization: the protection of data through access credentials alone is sufficient to make such directives clear”. This has been established by the Supreme Court of Italy, Criminal Section V, no. 40295/2024. 

The case 

An employee of a hotel in Chianciano Terme (Italy) had requested from another employee, directly subordinate to him, the access keys to the company’s IT system for the storage and promotional purposes of the customer database, which included about 90,000 individual records, accessing it for purposes unrelated to the mandate received. In the first two levels of judgment, was established the commission of the crime of «Unauthorized access to an IT or telematic system», under Article 615-ter, paragraph 1, of the Italian Penal Code. 

The employee appealed to the Italian Supreme Court, claiming that it was not an abuse access, both because he had the power «in his capacity as director and superior manager of the employee» from whom he had requested for the credentials, «also for the purpose of supervising her work» and because until shortly before, he had a personal and direct access to those data. 

The position of the Supreme Court 

The Supreme Court of Italy ruled that the offence of unauthorized access to IT systems (under Article 615-ter, paragraph 1, of the Italian Penal Code) also occurs in the case of a hierarchical superior using the access credentials provided by the employee. 

The judges of the Italian Supreme Court did not find convincing the appellant’s argument that relied on his power to access any company location in order to carry out checks on those hierarchically subordinate to him. In the case of an IT system protected by credentials, the Court pointed out that «each authorized person has his/her own ‘key’ (i.e., the access credentials)». «This is because it is data which, quite simply, the owner considers should be protected, both by limiting access to those who are provided with such credentials and, at the same time, by ensuring that a digital trace is left of the individual access and of who carries them out ». 

It is therefore incorrect to hold that the defendant «solely by virtue of his duties, automatically had the power to access data that, on the other hand, according to the employer’s discretionary assessment, were to remain available only to certain employees (even if subordinate to the appellant) » 

Moreover, by doing so, the appellant made it «falsely appear that the access had been made by the employee who, imprudently, had revealed her credentials to him». ​ 

Other related insights:   

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

6 Feb 2026

Pay equity and transparency: draft implementing decree presented

Italy is among the first Member States to have adopted the draft implementing legislative decree of EU Directive 2023/970, which yesterday received its initial approval from the Council…

30 Jan 2026

A conviction for stalking can justify dismissal for just cause

With Ordinance No. 32952 of 17 December 2025, the Italian Supreme Court, Labour Section, ruled that a final conviction for stalking and abuse can justify dismissal for just…

30 Jan 2026

We continue to be a Great Place to Work!

For the third consecutive year, De Luca & Partners has been awarded the prestigious Great Place to Work® certification, a significant recognition of the value we place on…

29 Jan 2026

Italian Supreme Court: Employer Monitoring and the Use of Corporate Chats for Disciplinary Purposes

Corporate chats “intended for work-related communications by employees accessing them through company accounts constitute work tools, pursuant to Article 4, paragraph 2, of Law No. 300 of 1970,…

28 Jan 2026

Anti-union conduct: the Supreme Court moves beyond formalism and focuses on substance

With order no. 789 of 14 January 2026, the Italian Supreme Court addressed the issue of anti-union conduct by employers in relation to information and consultation obligations on…

27 Jan 2026

DID YOU KNOW THAT… the use of artificial intelligence may justify a dismissal for objective justified reason?

With Judgment No. 9135 of November 19, 2025, the Labour Section of the Court of Rome held that the dismissal for objective justified reason (i.e. “giustificato motivo oggettivo”,…