Italian Data protection Authority: The "Exodus” Trojan Case –

12 april 2019

The "Exodus” Trojan Case – "Appalling”, said Antonello Soro'
(Ansa, 30 march 2019)

"What happened is appalling. The fact that hundreds of people having no connections whatsoever with criminal investigations have been intercepted because of a flaw in a Trojan used for those investigations is quite worrisome. More in-depth inquiries are necessary into this incident, and the Garante will also step in as appropriate.

The exact circumstances of the case have yet to be clarified and the chain of events must be brought to light. Nevertheless, what is unquestionable is that tools like these Trojans are quite dangerous: they can help investigations, but are also liable to give rise to unacceptable breaches of citizens' freedoms if they are deployed without the barest technical safeguards. We had drawn the Government's attention to these issues when we gave our opinion both on the draft legislative decree amending the interception laws – which also introduced regulations on the use of Trojans – and on the draft implementing decree that was supposed to lay down the appropriate safeguards in selecting the software for those purposes.

There is a lesson to be drawn from this case: we must be resolute in preventing similar breaches from occurring in future,  being aware that no mistakes may be allowed for in such a sensitive area – where investigational powers go hand in hand with no less strong technological applications. Investigational tools such as those at issue must be kept at the disposal of law enforcement bodies, as provided for by the law, but only if they are coupled with robust safeguards to protect citizens' freedom."

 

Retrieved from https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9101790

News archive

 

Firm news

apr21

21/04/2026

Trasporti aerei – Regolamento (CE) n. 261/2004 – Articolo 8, paragrafo 1 – Rimborso del prezzo di un biglietto in caso di cancellazione del volo

la Corte di Giustizia dell' UE, con sentenza del 16 gennaio 2026 (Quarta Sezione), nella causa C-45/24, avente ad oggetto la domanda di pronuncia pregiudiziale proposta alla Corte, ai sensi

apr21

21/04/2026

Diritto ad accesso proprie email dopo fine rapporto lavoro Sanzione di 50mila euro ad una compagnia assicurativa

lL Garante per la protezione dei dati personali ha affermato che il lavoratore può accedere ai messaggi del proprio account email aziendale e ai documenti presenti nel pc dopo la fine del rapporto

apr21

21/04/2026

Il Garante privacy sanziona Poste Italiane e Postepay per oltre 12,5 milioni di euro

Il Garante privacy ha comunicato in data 20 aprile 2026 di aver irrogato una sanzione di 6.624.000 euro a Poste Italiane S.p.A. e una di 5.877.000 euro a Postepay S.p.A., per aver trattato

Lawyer News

apr22

22/04/2026

Deposito Penale Telematico: la mind map

Scarica gratuitamente la mappa concettuale

apr22

22/04/2026

La Conferenza Unificata si pronuncia sull’autonomia differenziata

Il via libera alle intese preliminari per