Trento Ran Facial Recognition on Its Own Citizens, Then Lost Control of the Data
What happened
The Municipality of Trento, Italy ran AI-powered street surveillance on its own residents for years before a regulator looked closely at what it was actually doing with the data. When Italy's data protection authority, the Garante, examined the city's two flagship projects in January 2024, it found systematic violations of EU privacy law and handed down a fine that made Trento the first local administration in Italy to be sanctioned over its use of AI.
The two EU-funded programs, Marvel and Protector, were designed around public safety. Cameras and microphones deployed across the city fed footage and audio into systems capable of anomaly detection, object tracking, facial recognition, and computer vision analysis. The city had partnered with two developers, the Foundation for Research and Technology Hellas (FORTH) and Saher Europe, to operate the infrastructure. The data sources extended beyond physical hardware: social media networks were also monitored as part of the collection pipeline.
The Garante identified two distinct failures. The data gathered through both projects was not sufficiently anonymized, meaning individuals captured on camera or microphone could be identified from the records Trento held. The city had also shared that data with third parties without the legal basis the regulation required. Together, the violations put the privacy of every resident who passed through a monitored area at real and documented risk, not as a theoretical exposure but as one the regulator confirmed had already occurred.
The watchdog fined Trento EUR 50,000 (approximately USD 54,225) and ordered all data gathered through Marvel and Protector to be deleted. The city said it would appeal. The distinction of being the first Italian municipality sanctioned for AI data use marks less a unique failure than the first time the regulator turned its attention to deployments of this kind at the local government level.
The gap the Trento case reveals is not technical. The surveillance infrastructure functioned as designed. The failure was in governance: no verified process existed to confirm that data stayed within required anonymization thresholds, no documented checkpoint governed when or with whom it could be shared, and no trail showed who had approved each transfer to a third party. A system that maintained a provable record of what was collected, how it was transformed, and where it went would have made these violations visible before a regulator had to find them. Instead, accountability arrived only after the data was already out.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.