• Passa alla navigazione primaria
  • Passa al contenuto principale
  • Formati
    • Serie
    • Inchieste
    • Feature
    • Editoriali
  • Speciali
    • Inchiestage
    • Fotoreportage
    • Video
    • Podcast
  • Archivi
    • Archivio generale
  • IrpiMedia
    • Membership
    • SHOP
    • Newsletter
    • IrpiLeaks
    • Editoria
    • Redazione
  • Irpi
    • APS
    • SLAPP
    • Dona
  • In English
    • Investigations
    • Donate
  • Social
    • Facebook
    • Instagram
    • LinkedIn
    • Telegram
    • YouTube
IrpiMedia

IrpiMedia

Periodico indipendente di giornalismo d'inchiesta

  • Home
  • Menu
  • MyIrpi
  • Login
irpi media

Privacy watchdog halted facial recognition at Rome’s Olympic Stadium. A law could bring it back

The system was being used without an adequate legal basis, in violation of privacy rules. Unpublished documents show that in May 2025, Italy’s Data Protection Authority asked the Interior Ministry to suspend it

09.09.26

Rosita Rijtano

Argomenti correlati

Cybersecurity
Sorveglianza

An IrpiMedia investigation reveals that the facial recognition system operating at Rome’s Olympic Stadium since 2021 was being used in violation of privacy rules. In May 2025, Italy’s Data Protection Authority secured the suspension of the technology, managed by the Interior Ministry. But now, a new legislative decree could bring it back.

The technology can create a digital map of millions of spectators’ faces. Without a law regulating its use, it should not have been put into operation.

Yet the system was used for four years, from 2021 to 2025. Whenever it was activated, cameras at the stadium entrances took seven photos of each person entering, reveals IrpiMedia. The result was a potentially vast archive built through what attorney Francesco Paolo Micozzi, an expert in digital rights, describes as «unlawful data processing».

L’inchiesta in breve

  • From 2021 to 2025, a facial recognition system at Rome’s Olympic Stadium took seven photos of every spectator entering the venue. In May 2025, Italy’s Data Protection Authority called for its suspension because it lacked an adequate legal basis
  • Documents obtained by IrpiMedia show that the images were stored for seven days alongside ticket data. If a crime occurred, the software could compare the face of a person to be identified with those of all spectators present
  • The Olimpico had already been used as a testing ground for such technology. In 2014, Sind reportedly tested a system on 22,000 fans to identify five people of interest. Hower, Italian Data Protection Authority says that it never reviewed the facial recognition system developed by the company
  • In March 2025, Interior Minister Matteo Piantedosi told the Senate that the system complied with privacy rules. Just over two months later, the Data Protection Authority challenged its use and the Interior Ministry suspended it
  • A legislative decree approved by the government on August 4, 2026, could now provide the legal basis that has so far been missing. The final text has not yet been published in Italy’s Official Gazette, meaning it is not yet in force. It therefore remains unclear whether, and under what safeguards, the facial recognition system could resume operating

IrpiMedia first discovered and reported the surveillance operation in 2023. Two years later, the Data Protection Authority stated that the “smart” cameras at the Olympic Stadium had been used «in the continued absence of an adequate legal basis». The words appear in a previously unpublished email marked «extremely urgent» sent to the Interior Ministry’s Department of Public Security on May 28, 2025.

The authority demanded that use of the technology be suspended «before having to, if necessary, take the necessary measures». The Interior Ministry complied the next day.

Just over a year later, on August 4, 2026, Giorgia Meloni’s government gave final approval to a legislative decree regulating law-enforcement use of facial recognition in public places. The measure could pave the way for broader use of technologies like the one already tested at the Olympic Stadium.

The decree has not yet been published in Italy’s Official Gazette, meaning it is not yet in force and its final text is not publicly available. But whatever its final wording, it cannot erase what happened before.

From the 2014 test to the Data Protection Authority’s first approval

«European law does not allow fundamental rights to be restricted indiscriminately in order to identify a single person suspected of a serious crime», Micozzi says.

«This is why what happened at the Olimpico matters to everyone: the same logic of indiscriminately monitoring anyone attending an event with no inherent connection to criminal activity could also be applied to LGBTQIA+ events, religious gatherings or union meetings. Identifying the people who attend such events could reveal their sexual orientation, religious beliefs or union membership. Simply knowing they might be under surveillance could deter many people from attending an event or entering a venue for fear of discrimination or persecution», he warns.

Officially, the first plan to install facial recognition at the Olimpico was announced in 2016. Rome Police Headquarters unveiled a project to strengthen video surveillance at the stadium and make it easier to identify people involved in crimes.

The Data Protection Authority approved the project, but only for a clearly defined setup. If clashes broke out during a match, for example, police could compare footage recorded inside the stadium with images of spectators taken at the entries and automatically linked to the name on their ticket.

The Interior Ministry said the system went live on August 20, 2016, during Roma-Udinese, the first match of the Serie A season.

Scopri MyIrpi

Sostienici e partecipa a MyIrpi

Regala MyIrpi

Regala l’adesione a MyIrpi+
e ricevi in omaggio la nostra T-shirt IrpiMedia.

Segnala

Diventa una fonte.
Con IrpiLeaks puoi comunicare con noi in sicurezza.

But even that was not the first experiment at what might be called the “Olympic Surveillance Lab”.

An exclusive video obtained by IrpiMedia shows a presentation for law-enforcement and government officials held on June 3, 2026, at ISS World Europe in Prague, a closed-door trade show that connects surveillance companies with potential buyers.

The speaker is a manager from Sio, a company that supplies wiretapping systems to Italian prosecutors’ offices. Behind him is a photo of the stands at the Olimpico, showing the faces of Roma fans recognizable by their jerseys.

«These are 22,000 people, and we identified all of them to find five targets», the manager says. He adds that the technology was «adopted in collaboration with law enforcement» and developed by Sind, a partner company that has belonged to the same corporate group as Sio, the Zenita Group, since 2022.

Contacted by IrpiMedia, a Zenita spokesperson said the demonstration referred to «a 2014 test», and called «the claim that 22,000 people were identified» a misrepresentation. There was no «blanket identification», the spokesperson said. «The technology operates exclusively to compare individuals with those flagged by the relevant authorities».

In practice, the system analyzes each face against a pre-existing reference database until it finds a match with a wanted person.

The company does not explain why it used a 2014 example in a 2026 presentation. It stresses, however, that it is now «led by a completely renewed management team and uses different technology from that employed in the cited test».

At the time, Sind was controlled by Enrico Fincati and Nicola Franzoso, two entrepreneurs who stepped down from the company’s board in April 2026 while retaining an 11.25 percent stake.

Both men also made the news during that period, when Rome prosecutors issued search orders against them. They are under investigation over the alleged sale of software to the Prime Minister’s Office at an inflated price. Prosecutors say they secured the contract through their ties to Giuseppe Del Deo, former deputy director of the Department of Security Information, the body that coordinates Italy’s intelligence services.

At the time of the Olimpico test, Sind described its stadium product on its website as software capable of extracting faces from high-resolution images and searching them against a reference database.

At the time, testing such technology in a public place required prior review by the Italian Data Protection Authority. But the authority told IrpiMedia it had «never dealt with Sind’s facial recognition system». Contacted by email through their current company, Franzoso and Fincati did not respond to requests for comment.

What We (Don’t) Know About the Software Installed at the Olimpico

Seven years after the Sind test, in 2021, the facial recognition system at the center of this investigation was installed at the Olimpico. Sport e Salute, the company controlled by the Ministry of Economy and Finance that manages the stadium, awarded the contract directly to Reco 3.26, a company founded in 2018 in the province of Lecce.

The system’s technical specifications remain unknown, as does the number of times it was actually used to identify someone. The Interior Ministry blocked disclosure of this information, arguing that releasing it could cause «concrete harm to public order and security».

But Data Protection Authority inspection reports obtained by IrpiMedia show how spectators’ data were processed.

When the technology was active, seven photos were taken of each person entering the stadium. They were stored for seven days together with ticket data: first and last name, date and place of birth, seat number, row and section.

If a crime occurred, an operator could upload an image of the person to be identified. The software could then compare it with images of all spectators and return the closest matches.

The inspection reports leave two key questions unanswered.

The first concerns a contradiction. A 2021 public document describes the product installed at the Olimpico as a “real-time” system, meaning it could analyze faces in real time. During the Data Protection Authority’s inspection, however, a Sport e Salute representative said the version in use did not operate in real time.

Sport e Salute said it reserved the right to submit updated documents to the authority, but those documents were not provided to IrpiMedia.

The second, and more important, question is when biometric data were created. It is unclear whether they were generated as spectators entered or only after a possible crime, using the photographs already stored.

The difference is crucial. Biometric data are mathematical templates derived from facial features that make it possible to uniquely identify a person.

In the first scenario, the system would have created a temporary biometric database of every spectator, including people with no connection to any violent incident. On other occasions, the Data Protection Authority has objected to precisely this kind of practice, calling it ‘indiscriminate, mass surveillance.’

According to a source with knowledge of the matter, who spoke to IrpiMedia on condition of anonymity, this is precisely the difference between the system installed in 2021 and the setup approved by the Italian Data Protection Authority in 2016.

The 2016 system did not collect biometric data from everyone entering the stadium in advance, while the system used from 2021 may have allowed exactly that, according to the source.

First came the contracts and assurances. Then the shutdown

There was another key difference: in 2016, the Authority had issued its opinion under the law as it stood at the time. But the law later changed.

Yet the Data Protection Authority did not carry out its first inspection of Reco 3.26’s Olimpico system until August 8, 2024, three years after the technology had been installed and upgraded at a total cost of about 149,000 euros.

A second inspection, on January 27, 2025, found that the system was still active. It had stored facial images of all spectators at Lazio-Real Sociedad on January 23 and Lazio-Fiorentina on January 26.

Then came a revealing sequence of events. On March 20, 2025, Interior Minister Matteo Piantedosi, responding to a question from Senator Filippo Sensi, told the Senate that the technology used at the Olimpico complied with privacy rules.

On April 14, Reco 3.26 was awarded a 72,000-euro contract to maintain the “Safety & Security System installed at the Stadio Olimpico in Rome” through the end of the year.

Public documents contain no explicit reference to facial recognition. Based on the records available to IrpiMedia, however, this is the only service the company has provided at the stadium.

Seventy days after Piantedosi’s assurances in the Senate, and 45 days after Reco 3.26 secured its latest contract, the Interior Ministry suspended use of the software.

Contacted several times by IrpiMedia, the Interior Ministry, Sport e Salute and Reco 3.26 declined to comment. The Data Protection Authority, meanwhile, said it had opened an investigation to determine whether violations occurred and whether sanctions should follow. That investigation remains open.

«The people responsible for the decision either ignored the issues around personal data protection or assessed them incorrectly. This case shows how the right to privacy is often treated as secondary to the potential benefits of a tool: as an obstacle to innovation rather than a safeguard of fundamental rights», Micozzi says.

He is also concerned that there is no way to verify what happened to the data that were collected.

«Who can guarantee that they were actually deleted?» he adds. «The risks are twofold. The system itself could be breached, including by insiders. And data processed unlawfully may already have been shared with other European authorities, making it difficult to trace where they went and ensure their deletion», Micozzi concludes.

A Decree Tailored to the Olimpico?

For the Digital Human Rights Network  – a coalition comprising The Good Lobby, Privacy Network, StraLi, Amnesty International Italy, Hermes Center, Period Think Tank, Antigone, Sloweb, Italiani Senza Cittadinanza and Comunicazione Pubblica – the case uncovered by IrpiMedia confirms a broader concern. «For years, stadiums have been used as testing grounds for large-scale biometric surveillance, and now this technology will be taken outside, into public squares and the very places where democracy is practiced».

The coalition sees the 2014 test on 22,000 fans in the same light. «This is not just an incident that we consider serious in and of itself, a one-off event that requires clarification, but a glimpse into a future that is now very near», the organization says.

The legal basis that the Olimpico facial recognition system previously lacked could now come from the legislative decree given final approval by the government on August 4, 2026.

According to a source familiar with the matter, who requested anonymity, the decree is intended precisely to fill the gap identified by the Data Protection Authority and later acknowledged by the Interior Ministry itself.

The timing of biometric-data creation became a point of contention between the two institutions.

In its initial version, the decree allowed the faces of everyone present at locations or events deemed sensitive, including sports matches, concerts and demonstrations, to be automatically converted into biometric data. Those data would have remained available to law enforcement for seven days.

«This does not comply» with the AI Act, the European Union’s regulation on artificial intelligence, the Data Protection Authority objected in its July 14 opinion.

After the criticism, the government changed the mechanism. According to reports by Ansa and Cybersecurity Italia, the law would allow systems to photograph and store the faces of everyone entering a venue for seven days without immediately converting those images into biometric data.

That conversion would take place only after a crime had been committed. In practice, the biometric database would no longer be created in advance. But the photographs from which those data could be derived would still be collected in advance.

The first draft was also broad about which authorities could approve the use of facial recognition, leaving considerable room for discretion. The government later changed this part as well.

A Palazzo Chigi press release says real-time identification will be allowed only «in exceptional cases, for limited periods, and subject to authorization by a judicial authority». It also says the decree clarifies deletion requirements and limits on the creation of databases for retrospective recognition.

But it does not specify who would authorize each individual use or how images would be collected. The decree has not yet been published. It is therefore impossible to know what safeguards have actually been adopted.

For now, the facial recognition system at the Olimpico remains switched off, but could soon be allowed to return.

Rosita Rijtano è Bertha Challenge Fellow 2026. Questa inchiesta è stata realizzata con il supporto della Bertha Challenge Fellowship.

Le inchieste e gli eventi di IrpiMedia sono anche su WhatsApp. Clicca qui per iscriverti e restare sempre aggiornat*. Ricordati di scegliere “Iscriviti” e di attivare le notifiche.

Crediti

Autori

Rosita Rijtano

Editing

Raffaele Angius

Visuals

Lorenzo Bodrero

In partnership con

Foto di copertina

A general view inside the stadium prior to the Serie A match between AS Roma and Cagliari at Stadio Olimpico on March 16, 2025 in Rome, Italy © Emmanuele Ciancaglini/Getty

Condividi su

Potresti leggere anche

#Sorveglianze
Feature

Il rischio di abboccare: come si è cercato di infettare il computer di un giornalista di IrpiMedia

27.03.26
Olivelli
#Sorveglianze
Inchiesta

Oppositori politici del Ruanda tra i target di Altamides, il software di First Wap

15.10.25
Coluccini, Black, Freudenthal, Geiger
#Sorveglianze
Inchiesta

Nel 2012 il giornalista che indagava sul pontificato di Ratzinger è stato spiato

14.10.25
Coluccini, Black, Freudenthal, Geiger
#Sorveglianze
Inchiesta

Paragon colpisce ancora: anche l’ad di Unicredit tra i bersagli

11.10.25
Angius

Logo IRPI media
Logo IRPI media

IrpiMedia è una testata registrata al Tribunale di Milano n. 13/2020.
IRPI | Investigative Reporting Project Italy | Associazione di promozione sociale | C.F. 94219220483
I contenuti di questo sito sono distribuiti con licenza Creative Commons Attribuzione – Non commerciale 4.0 Internazionale.

  • Serie
  • Inchieste
  • Feature
  • Editoriali
  • Inchiestage
  • Fotoreportage
  • Video
  • Podcast
  • Newsletter
  • IrpiLeaks
  • Irpi
  • Cookie Policy
WhatsApp Facebook X Instagram LinkedIn YouTube
Gestisci consenso Cookie
Per fornire le migliori esperienze, utilizziamo tecnologie come i cookie per memorizzare e/o accedere alle informazioni del dispositivo. Il consenso a queste tecnologie ci permetterà di elaborare dati come il comportamento di navigazione o ID unici su questo sito. Non acconsentire o ritirare il consenso può influire negativamente su alcune caratteristiche e funzioni.
Funzionale Sempre attivo
L'archiviazione tecnica o l'accesso sono strettamente necessari al fine legittimo di consentire l'uso di un servizio specifico esplicitamente richiesto dall'abbonato o dall'utente, o al solo scopo di effettuare la trasmissione di una comunicazione su una rete di comunicazione elettronica.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistiche
L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
L'archiviazione tecnica o l'accesso sono necessari per creare profili di utenti per inviare pubblicità, o per tracciare l'utente su un sito web o su diversi siti web per scopi di marketing simili.
  • Gestisci opzioni
  • Gestisci servizi
  • Gestisci {vendor_count} fornitori
  • Per saperne di più su questi scopi
Preferenze
  • {title}
  • {title}
  • {title}