Italian Data Protection Authority: The "Exodus” Trojan Case –

12 aprile 2019

The "Exodus” Trojan Case – "Appalling”, said Antonello Soro'
(Ansa, 30 march 2019)

"What happened is appalling. The fact that hundreds of people having no connections whatsoever with criminal investigations have been intercepted because of a flaw in a Trojan used for those investigations is quite worrisome. More in-depth inquiries are necessary into this incident, and the Garante will also step in as appropriate.

The exact circumstances of the case have yet to be clarified and the chain of events must be brought to light. Nevertheless, what is unquestionable is that tools like these Trojans are quite dangerous: they can help investigations, but are also liable to give rise to unacceptable breaches of citizens' freedoms if they are deployed without the barest technical safeguards. We had drawn the Government's attention to these issues when we gave our opinion both on the draft legislative decree amending the interception laws – which also introduced regulations on the use of Trojans – and on the draft implementing decree that was supposed to lay down the appropriate safeguards in selecting the software for those purposes.

There is a lesson to be drawn from this case: we must be resolute in preventing similar breaches from occurring in future,  being aware that no mistakes may be allowed for in such a sensitive area – where investigational powers go hand in hand with no less strong technological applications. Investigational tools such as those at issue must be kept at the disposal of law enforcement bodies, as provided for by the law, but only if they are coupled with robust safeguards to protect citizens' freedom."

Retrieved from https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9101790

Archivio news

 

News dello studio

giu30

30/06/2026

Intelligenza Artificiale 2026:Rapporto sull'Intelligenza Artificiale 2026: le principali trasformazioni tecnologiche, economiche e giuridiche legate allo sviluppo dei modelli di IA e il ruolo di AGCOM nel nuovo ecosistema digitale europeo

Pubblicato il Rapporto sull’Intelligenza Artificiale dell’Autorità per le Garanzie nelle Comunicazioni, che offre una ricostruzione organica delle principali trasformazioni tecnologiche,

giu12

12/06/2026

The European Data Protection Board welcomes comments on the Template for personal data breach notification.

The template is subject to a public consultation, providing stakeholders with the opportunity to share their comments and feedback on the content of the template. Following the public consultation,

giu12

12/06/2026

Search engine delisting: When to act and what to do

Search engine providers play a crucial role in how personal data is disseminated online. Under the GDPR, individuals have the “right to be forgotten”—meaning they can request

News Giuridiche

giu30

30/06/2026

Terrazza a livello a cui si accede dall’appartamento: si presume comune se funge da copertura

L’assegnazione in proprietà o in uso esclusivo

giu30

30/06/2026

Il Massimario AGCM e AGCOM: maggio-giugno 2026

<p>Il Massimario del mese di maggio-giugno

giu30

30/06/2026

L'avvocato non è mai in pausa: il richiamo disciplinare che non si può ignorare

Dal richiamo verbale definitivo al principio