The right to respect for private life and the requirement of transparency of Public Administration in the Italian legal system

Premessa: tale scritto, a cura di Aniello Formisano, fa parte del Legal Research Group di ELSA Napoli intitolato “Right to private life: challenges and perspectives” organizzato da ELSA Napoli e curato da Francesco De Santis (professore di diritto processuale civile e procedure di tutela internazionale dei diritti umani presso il Dipartimento di Giurisprudenza dell’Università di Napoli “Federico II”).

Summary: 1. Legal evolution of transparency in the Italian legal system ‒ 1.1. From transparency as a publication requirement to transparency as freedom of access to data and documents: the generalized civic access ‒ 2. Privacy and transparency: a difficult coexistence ‒ 2.1.Risks and consequences of the uncontrolled dissemination of data on constitutional rights: data mining and algorithmic governance ‒ 3. The role of Italian Regulatory Authorities in the balance of privacy and transparency: the relevance of its guidelines.

  1. Legal evolution of transparency in the Italian legal system

Before analysing the relationship between transparency and privacy, we need to bring attention on the evolution of transparency regulation in the Italian legal system[1]. The evolution of transparency involves a series of difficulties in defining its boundaries and providing an univocal definition of the same boundaries. Transparency is often linked to publicity, which is essential to disseminate acts, documents and information to citizens, that is now possible and easier through Internet. Nevertheless, as it has been opportunely noted[2], this is not the only element that characterizes transparency. The Administration must, in fact, guarantee citizens access to information through tools for access to administrative documentation or through direct publication of data on websites that should be inserted in website section not hidden and easily accessible. In addition to these characteristics, transparency is linked to clarity and comprehensibility of information. If these requirements are not met, the citizens’ legitimate expectation would be harmed by access to incomprehensible and “equivocal” information which would generate an erroneous conviction regarding the behaviours to be kept[3].

Based on what has been just mentioned, the analysis of transparency cannot be separated from the analysis of its evolution. Before the reforms of the ‘90s on the administrative procedure, the administrative activity was characterized by secrecy[4]. Public authorities were bound by the official secret and administration had a very wide discretionary space to decide arbitrarily what documentation was covered by such secret[5]. Therefore, the previously transparency regulation was not able to achieve the aims set forth in our Constitution.

The evolution of transparency regulation has implemented constitutional principles to prevent corruption and maladministration, and also tends to achieve the effective participation of citizens in decision-making control over public powers: it aims at becoming a real instrument of democratic participation. In this scenario, citizens do not assume a position of mere expectation, but acquire awareness and actively participate in the public decision-making processes[6].

In light of this, a non-static notion of transparency emerges in the Italian legal system: it is a dynamic one that evolves and changes over time. In fact, there is a change from an originally vertical interpretation of transparency[7], founded within a ministerial pyramid, to a horizontal vision of Administration, as elaborated by Filippo Turati. This paradigm shift is confirmed by the possibility for all citizens to access information except for the limits fixed by the public law[8], «whose legitimacy ultimately lies precisely in the vote expressed by the same administered as voters».

The 1948 Italian Constitution does not expressly provide the notion of transparency, but it shares Turati’s reconstruction, hence constitutionalizing the aspects that characterize it: advertising and accessibility. These can be derived from the interpretation of the general principle of good administration, enshrined in Article 97 of Constitution. This gives rise to a notion of transparency in which advertising and accessibility are strictly inter-linked. A different interpretation would undermine one of the aims pursued by transparency ‒ e.g., the repression of corruption phenomena. For example, we can consider the publication of a call for tenders on the notice board or on a website, in a holiday period, which has been cleverly concealed becoming «equivocal, obscure and therefore non understandable to the citizens»[9].

It seems appropriate to outline the legal regime that has been introduced in the Italian legal system.

The epochal turning point is represented by Law no. 241 of 1990, which introduced in the institution of administrative procedure as a general rule of public action and the right to access to public administration documents. It has been observed that with this law «the wall of impenetrability towards the outside has begun to gradually crumble»[10]. The foundations have been laid for creating a notion of transparency that tends to approach the glass house, theorized by Filippo Turati.

As already mentioned, the internet’s future brings a change of transparency that is no longer seen in the one-to-one or peer-to-peer relationship between citizen and administration, because administration expresses the interest that actions become visible to all, through an open data dissemination[11]. Thus, the transparency paradigm changes. The ultimate aim is to ensure freedom of access to information in order to pursue a number of different interests, all aimed at achieving the good performance of Public Administration (e.g., the prevention of corruption phenomena; the repression of abusive practices; the resolution of interest conflicts; an immediately access guarantee to those who are in a difficult situations to the data of their interest). All these interests have an ultimate common purpose, namely to guarantee the principle of good administration through a citizen participation in policy-making

  • From transparency as a publication requirement to transparency as freedom of access to data and documents: the generalized civic access

 The legislator’s goal is to create a freedom of access to information was pursued with the Madia Reform, announced as the “Italian Foia[12]. The legislator limited himself to introduce a series of publication requirement for the Public Administration. On this point, it has been observed that this reform is far from giving citizens full access to information, being compared to an embryonic version of the American FOIA[13] and not to the recent developments that have taken place[14].

 The main innovation of Legislative Decree No. 97 of 25 May 2016 is represented by the introduction of a third form of access ‒ the generalized civic access. This the two already existing were the access to the simple acts ‒ governed by the already mentioned Law no. 241 of 1990 ‒ and the simple civic access, introduced by Article 5 of Legislative Decree No. 33 of 2013[15]. The latter, in particular, assumes a sanctioning nature by guaranteeing to those who request it acts, documents and information subject to the obligation of publication.

The generalized civic access is a new type of access that becomes autonomous and disconnected from a publication requirement, placing on the citizen the obligation to request access to closed data, i.e. those data on which there is no obligation to publish by the public administration. Therefore, the Madia Reform has undoubtedly represented an improvement on the active side of transparency because it has introduced the so-called reactive disclosure, that is the possibility for everyone to request any kind of information to public administration[16]. Such possibility goes beyond the so-called proactive disclosure ‒ i.e. the Administration’s requirement to publish a series of public information considered relevant by the Legislator.

 However, authoritative scholars have highlighted the various obscure points of the Madia Reform, especially the lack of widespread access to information. In this regard, the private accessibility to the so-called closed data requires an access request that the citizen must submit from time to time (i.e. a qualified interest). Therefore, the Administration will not make ex-officio data available to citizens, since there is no general administrative requirement to make data available to citizens. This means that this reform moves away from an administration model aimed to create an Open Data Policy, expression of the highest form of democracy.

For the reasons analysed above, it emerges that the regulatory evolution of transparency appears unable to guarantee the citizens right to be adequately informed. However, the question that underlies all the reasoning so far carried out is the following: does our Constitution recognize a «right to administrative information[17].

On this point, some scholars have observed[18] how the right to information is recognized under the active aspect ‒ i.e. the freedom of expression ‒ but not for the passive aspect ‒ i.e. being informed or anxious to inform oneself. The latter is not set forth in the Italian Constitution. Article 21 of the Italian Constitution only provides that “everyone has the right to freely express their thoughts by speech, in writing and by any other means of communication“. With reference to the passive aspect, the Constitutional Court with judgment No. 105/1972 has highlighted the link between freedom of expression and freedom of enterprise and democratic state form.

The approach adopted by our Constitution cannot allow the notion of transparency to be one-dimensional, since it would be very limited and would clash with the Universal Declaration of Human Rights. Hence, the passive aspect of the right to information deserves protection as strong as the active one[19]

The absence of an explicit recognition of the right to be informed does not concern other legal systems. For example, the Spanish Constitutional Charter of 1978, much more “recent” and modern than the Italian Constitution, not only states the right “to freely communicate or receive truthful information by any means of communication” (Article 20), but explicitly recognizes the “right of citizens to access the archives and administrative registers, except in matters concerning the security and defence of the State, investigation into crimes and the privacy of persons” (article 105).

A notion of transparency emerges from the Madia Reform. Such notion is un-linked to the right to be informed, which does not encourage the formation of a critical awareness of citizens as they will not have a full access to administration data. Making the glass house, of which Turati spoke, means that the Administration should provide as much information as possible to the citizens without placing conditions or constraints to access it. Nevertheless, even an unconditional access to news poses a series of risks, especially the right to respect for private life, such as the possibility of providing the authorities with great opportunities for surveillance does not produce a more democratic system without an adequate explanation regarding the content of specify[20].

  • Privacy and transparency: a difficult coexistence

 The expansion of the right to transparency, also due to the new technological capabilities, raises the question of how this right can be reconciled with the right to a private life, since it is necessary to achieve a correct balance between such two interests.

The solution of this problem can be derived from the analysis of European Union law, especially Article 4 of EU Regulation No. 679/2016 which states that privacy “is not an absolute prerogative, but it must be considered in the light of its social function and must be reconciled with other fundamental rights, in compliance with the principle of proportionality”, while transparency must be ensured consistently with the personal data protection[21]. In particular, we move from a model based on the right to propriety to one based on right to privacy in the technological scenario, as proposed by Rodotà[22], where privacy is attracted in the area of ​​fundamental freedoms in which the development of technology unfolds and spreads outwards in an increasing quantity of data.

In the technological era, data dissemination requires the need to find the right tools to guarantee and protect the personal data held by citizens. The right to privacy has the status of individual fundamental right and it is protected by Articles 2, 3, 13, 14 15 of Italian Constitution and by Article 8 of the ECHR.

The internal framework for the processing of personal data derives from that of the European Union[23], substantially contained in the Regulation No. 679/2016 of the European Parliament[24], that from 2018 has taken the place of Directive No. 46/95/EC on personal data protection. In the Eu system, the right to private life is constructed as an “informational self-determination” in which citizens are given a full right to check their information tending not to forget them (i.e. the right to be forgotten)[25]The individual choice to make his/her data available takes place through a contract by which they decide to give a specific consent to the data processing, subject to informative without prejudice to the right of access to him/her information well as rectification and erasure right in case of errors and breaches.

The right to privacy evolves as an inviolable and essential right for the development of an individual personality, establishing a bilateral relationship between data subject and data controller. The relationship covers subjective legal situations where each individual is the owner of his/her data.

However, when a citizen makes a huge amount of data available, he or she does so without giving free and informed consent before sharing his or her data. In this way a situation of obscure uncertainty realises where consensus tends to turn into a “non-consensus[26], which, especially in economic relations, becomes and remains indispensable for access to the essential services of everyday life. In this way, the protection of privacy, originally based on consent and assisted by the guarantee of autonomy and awareness, can no longer be invoked.

On this point, a number of doubts have been highlighted about the purpose to use these data from those who collect them in massive form. As these data are anonymous, the data controller is not required to indicate the reasons to collect them and nothing would prevent their use for different reasons from the initial ones. Neither a similar risk is avoided by the rules of privacy that in Article 35 of Italian Data Protection Code guarantees the privacy protection through an ex ante assessment of the risks that would involve the aggregation of data “for the interests and freedoms of individuals“. On this aspect, some critically highlighted that such a well-conceived system could work in the case of data referable to a data controller, but not in the case of Big Data ‒ which are anonymous ‒, as in the latter case no one is able to sue the alleged perpetrators of the data breach due to the lack of legal bases for grievance and the impossibility of identifying the perpetrators, except through cross-checks[27]The same impact assessment would appear to be a completely inadequate remedy and would lead to unsuccessful results, as the approval of Privacy Guarantor entails a semi-legal immunity[28].

2.1. Risks and consequences of uncontrolled data dissemination on the Constitutional rights: data mining and algorithmic governance

The problem of balancing privacy and transparency is also intertwined with the methods concerning the use of data and the consequences that an uncontrolled dissemination of the same can entail.

Data could be used as a starting point for predictive analyses (i.e., all predictive activities carried out in order to anticipate the behaviour of entire categories of subjects that presumably will assume in according to the projections of algorithm models, so-called data mining[29]). In particular, this form of processing is made possible through the use of current technologies which have a computing power such as to allow not to work on samples but on a whole mass of information. This is precisely one of the aspects for which the need to provide adequate privacy protection arises: in order to avoid not only the right to privacy to be breached, but also discrimination and violation of other constitutional rights. 

The problem of algorithmic governance is linked to the danger of discrimination inherent in data mining which, if it occurs, can have repercussions on society as a whole, especially concerning the possible violation of fundamental rights[30]. For example, the predictive model has been applied during investigations on jihadist terrorism: if it turns out that the terrorists are mostly young men, coming from certain countries, anyone who presents these characteristics will be under special surveillance, automatically, on the base of what is revealed by the algorithm[31].

At this point it becomes necessary to guarantee the knowability of algorithm operation in order to evaluate the predictive investigations, since the algorithm may present errors that can have detrimental effects for the subjects involved[32]

Another case is represented by sensitive health data collected anonymously about a serious incapacitating disease spread in a specific area of the country. Therefore, persons may be are discriminated against due to the error of the algorithms[33]. These technologies make possible to exploit the power of Big Data to increase the data base on which one performs his or her own analyses, profiling the habits, preferences, trends of the insured in order to determine the relative insurance risk. This could occur when the assessment is carried out not by a human, but by an algorithm, that is to say to a fully automated procedure, which, in a more efficient and faster way, will assess: the insurance risk relating to a specific person; the convenience or otherwise the assumption of the risk; the amount of insurance premium; other elements of the insurance contract. Therefore, it becomes necessary that the algorithm operations are knowable, at least the source code of the algorithm, in order to check on its functioning. In this regard, the need to reveal how algorithms work becomes instrumental to its justice. Administrative jurisprudence regarding the use of authoritative acts based on algorithms has deemed it appropriate to accept the use of administrative acts for algorithmic errors[34]

  1. The role of the Italian Regulatory Authorities in balancing privacy and transparency: the relevance of the guidelines

After analysing the difficulty of guaranteeing an effective balance between transparency and privacy, and the risks deriving from an uncontrolled dissemination of data, it is necessary to analyse how to bring together two regulatory systems: the first is the national regulatory discipline of privacy and the new EU regulation, characterized by the presence of a sector Authority (Privacy Guarantor) and various organizational models; the second is a transparency system that presents its own rules[35]in which the role of the National Anti-corruption Authority (ANAC) tends to build up a model aimed to prevent and reduce the risk of maladministration.

But is it possible to create a coexistence between these two systems?

This balance must be achieved by the legislator, who should define the methods for achieving this objective. Therefore, the legislator enjoys a great discretion which should, however, be assessed in accordance with EU rules[36]. Especially, it is necessary that the privacy restriction represents “a necessary and proportionate measure” considering the other public interests[37].

A violation of citizens’ right to privacy is one of the risks stemming from the publication of an enormous amount of data on the public administration websites, according to modalities that allow indexing and traceability through search engines.  Indeed, it will be enough to type on Google the name and surname of the interested party to find all the published data of the Administration that can be linked with them[38].

 The danger of the various models of transparency would therefore result in emptying the concept of privacy, which will also undermine the right to be forgotten. Therefore, it will be necessary to identify the various strategies that can be adopted by legislators to achieve an adequate balance between these two constitutional values[39]. Several proposals have been made on this issue[40]

In order to achieve this balance, the guidelines of Privacy Regulatory Authority in the transparency field assumes primary importance. Through such guidelines, the Guarantor tends to achieve the principles of minimization, relevance, and not excess[41]The Privacy Code specifies the task entrusted to the Guarantor, namely: “to take care of the knowledge among the relevant public discipline concerning the processing of personal data and related purposes as well as data security measures[42]”. However, this provision indicates the aim to be pursued but not the means to achieve it.

The Guarantor’s guidelines, however, establish a first unitary framework regarding the devices that public subjects must employ in the activity of spreading personal data in order to maintain balance between privacy and transparency[43]First, it is established that the administrations must only make available the exact personal data that are updated and contextually evaluating the purpose envisaged by the sector discipline for which there is a requirement to publish.

Therefore, even if the legislator is required to publish a series of data, he must assess, case by case, which data may be published, and which ones must be obscured. The identification work of the legislator must be inspired by an interaction of a series of principles including the necessity and relevance established by the Code, the indispensability to prohibit the data publication which reveals the state of health[44].

As regards the realization of this balance, an important role is also played by the ANAC, which is called to monitor compliance with the publication requirement. The competence of the ANAC is automatically intertwined with that of the Privacy Guarantor, as it plays a fundamental role in the implementation of a good coordination between the two Authorities. This coordination can be appreciated by Article 3, paragraph 1-bis that recognizes the possibility for ANAC, after having “heard the Privacy Guarantor about the events that personal data are involved”, even “for the exclusive purpose to reduce charges“, to “identify the data, information and documents subject to mandatory publication pursuant to the regulations in force for which publication in its entirety is replaced by that of summary information, processed by aggregation“.

ANAC guidelines regarding generalized civic access, approved on 29 December of 2016, seek to achieve this balance as well.

First, the Administration, before proving the existence of a prejudice to confidentiality, must demonstrate the existence of a specific causal link between access and damage. It must also provide that such prejudice has been caused by the dissemination of the requested information. The assessment, therefore, becomes a form of prognostic evaluation which brings the damage in a causal link, understood as a high probability of the prejudice deriving from the publication of the documents[45]In assessing the existence of such prejudice, which will have to be evaluated concretely, the role of the procedure in which the administration will have to involve the counterparts, whenever the data minimization and anonymization techniques will be ineffective, and so it will gain particular importance. In such a scenario, the dialogue with the other parties will be necessary, becoming an index from which to infer the existence or not of a concrete prejudice.

But what are the limits of the current system and how would it be possible to achieve a balance between the two rights?

It has been observed that the Italian legal system needs to strengthen the role of the regulatory authorities[46]It highlights that there are still serious doubts to assign regulatory powers to the independent Administrative Authorities, for the lack of a legal basis[47]On this point, we must mention the two main orientations: the first strictly applies the rule of law, and therefore denies the regulatory power of Administrative Authorities to the extent that these powers can only be granted by law; the second enhances, instead, the theory of implicit powers according to which although there are powers not contemplated by the law. These powers must however be conferred as long as they are instrumental to the achievement of the assigned institutional aims. In this way, a real blank cheque would be given to the Authorities[48].  

Administrative jurisprudence has shared the first orientation, rejecting a weak interpretation of the rule of law. In this regard, we quote the judgment of the Council of State No. 4874/2014 in the part where it states that:

«in the areas characterized by particular technicality […] the sector laws attribute to the individual independent administrative Authorities […], to ensure the pursuit of the legislative objectives set, not only individual administrative powers but also regulatory powers in the broad sense».

A corollary of the legal uncertainty framework is represented by the value to be assigned to the guidelines and, more in general, to the exercise of regulatory power – i.e, if they can be assimilated to soft law or hard law instruments[49]. From the framework outlined above, it emerges that the Italian legal system lacks a single control system, endowed with autonomy and independence, on civic access as well as powers of regulation and supervision. The Italian scenario differs from the other European realities where we find specific Authorities, also endowed with decision-making powers, in the matter to solve disputes regarding civic access. It is possible to mention the UK, where an Information Commissioner was established; Spain, which set up the Comisión de Transparencia y Buen Gobierno in 2013; Germany which, in 2006, chose to grant the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit supervisory powers on transparency.

Some indication in the perspective of an intervention by the Italian legislator is provided by the judgment of the Constitutional Court No. 20/2019 concerning the constitutional illegitimacy of Article 1-bis, paragraph 14 of Legislative Decree No. 33/2013, that provides Administration’s requirement to publish data indicated in Article 14, paragraph 1, letter f) for all holders of managerial positions[50]. The Constitutional Court observed that the publication of a such large quantity of data must pass a proportionality test, since it does not facilitate the implementation of anti-corruption purposes, but rather creates an “opacity due to confusion” which hinders an effective control by individual citizens on administrative action.

With reference to the implementation of a balance between privacy and transparency, the judges pointed out what might be the legislator’s solutions for compliance with the proportionality test: the predefinition of income thresholds (the exceeding of which is a necessary condition to trigger the requirement to publish); the dissemination of data covered by anonymity; publication in nominative form of information following predefined scales; the simple lodging of personal declarations with the competent supervisory authority. The Court emphasizes, however, that it is for the legislature, in view of its wide discretion, to choose the most appropriate remedy[51].

Another indication provided by the Constitutional Court in judgment No. 20/2019 is the need to ensure an adequate protection of personal data. So, it must be ensured by indexing or by easily retrieving through search engines[52]. Therefore, although the objective is to ensure a freedom of access to information we should consider the risk of a “crystallization” of information in the network. For this reason, we have a duty to find a valid balance between indexation of data and privacy[53].


