Operational notes Regulation

The system administrator of your company’s AI: is the 2008 measure still in force?

8 min read

Fibre-optic patch panel with rows of connectors and tangled cables, in black and white
Every cable in that cabinet has, by law, an individual person answerable for it. The designation must be written before the fact, not reconstructed after an incident.

A typical scenario, not the case of a real company. A company installs a dedicated AI assistant: it reads technical manuals, tender specifications, supply contracts, the payroll of the quality department. The server is administered by whoever set it up — an in-house technician, often an outside supplier — through a single “admin” account that everyone in the IT department knows by heart. It works, nobody complains, until someone asks who opened what, and when. In many companies the answer is that nobody knows for certain, because nobody has ever had to prove it.

The 2008 measure, with the references

The Italian data protection authority’s general measure of 27 November 2008 — “Measures and arrangements required of data controllers processing personal data by electronic means, concerning the assignment of system administrator functions” (doc. web no. 1577499, Official Gazette no. 300 of 24 December 2008), amended on 25 June 2009 (doc. web no. 1626595) — sets out five requirements, all of them operational, not statements of principle:

  1. a prior assessment of the “subjective characteristics” of whoever will be designated — experience, capability, reliability;
  2. an individual designation, never a collective one, with “an analytical list of the areas of operation permitted under the authorisation profile assigned”: the administrator gets access to what the job needs, not to everything;
  3. an up-to-date list of system administrators, with identifying details and the functions assigned, made known or knowable to workers — through the privacy notice, the technical policy or an internal communication — whenever the processing concerns their data;
  4. the recording of logical access: complete, unalterable, with verifiable integrity, time references and a description of the event, retained for a “period of not less than six months”;
  5. a review of the administrator’s work “at least once a year” by the controller or processor.

The 2009 amendment removed only one paper-based duty — the note in the security policy document, itself later abolished — and allowed retention and review to be delegated to an external processor by contract. The substance of the five requirements has not changed.

The trap: “the GDPR has superseded it”

It is the most common objection, and it is not baseless: the measure was written under the old Privacy Code, does not mention the GDPR, and has never heard of AI. Checking it at the root means reading a single provision, article 22(4) of Legislative Decree 101 of 10 August 2018: “As from 25 May 2018, the measures of the Data Protection Authority continue to apply, in so far as they are compatible with the above-mentioned Regulation and with the provisions of this Decree.” That is not a blank confirmation: it is a conditional survival, to be checked provision by provision — which is exactly why legal commentators disagree. Some write that incompatibility with the GDPR is “a non-issue”; others argue that still requiring the names of administrators is today “a pointless practice”. Neither of them is the Garante.

The answer that counts is not in an FAQ but in an enforcement decision. On 16 January 2025 (register of measures no. 11/2025, doc. web no. 10110241) the Authority fined Realmaps S.r.l. €100,000, and among the violations found was precisely the handling of system administrators: “generic accounts used, and usable, by system operators” — the Garante writes — “amount, in fact, to system-level credentials shared among several users”, raising difficulties “as to the actual possibility of tracing accesses back to the individual formally authorised to process the data”. The processing turned out to have been carried out “in the absence of a formal ‘assignment of functions and tasks to designated persons’” under article 2-quaterdecies of the Privacy Code. And to justify this the Authority invokes “the measures set out in the Garante’s provision of 27 November 2008 on system administrators, still to be regarded as valid, with the value of a guideline”.

Here is the outcome, with the precision it deserves: not “in force” as a stand-alone body of rules with its original binding weight — that framework has been absorbed into GDPR accountability — and not “lapsed” either. Valid, with the value of a guideline, kept alive by article 22(4) of Legislative Decree 101/2018 and made operational today through article 2-quaterdecies of the Privacy Code and articles 5(2), 24 and 32 of the GDPR, cited together in the same decision. What remains undefined, and we say so because it is more useful than an invented certainty, is which individual requirements of the 2008 measure the Garante would treat as “compatible” in a case unlike Realmaps. The point that is settled — and settled by a recent enforcement decision, not by a rule eighteen years old — is the substance: individual designation, credentials that are not shared, traceable access.

Who, under the GDPR, is the person administering the system

The system administrator is not a category the GDPR itself uses: the Regulation knows the controller and the processor — article 4(8): “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller” — and anyone who, under either one, has access to the data. Article 29 puts it in one line: anyone acting under the authority of the controller or the processor who has access to personal data “shall not process those data except on instructions from the controller”; article 32(4) places the same duty on both. Article 2-quaterdecies of the Privacy Code — introduced by the very same Legislative Decree 101/2018 that also holds the survival clause — is the hinge: it lets the controller assign “specific tasks and functions connected with the processing of personal data” to “natural persons, expressly designated”, through “whatever arrangements it considers most appropriate”. It is the legal basis on which what was called, in 2008, the designation of the system administrator is written today: the same underlying duty, an updated foundation.

Where the administrator is an outside party — an IT supplier, a service centre, a technology partner — article 28 of the GDPR also applies: the controller “shall use only processors providing sufficient guarantees”, under a contract that sets out the subject-matter, duration, nature and purpose of the processing, the duty to process data “only on documented instructions from the controller”, and the security measures of article 32; where that outside processor in turn engages a sub-processor, the same obligations pass on by contract (article 28(4)). It is not a form signed once: it is the document where scope, logs, periodic review and audit rights get written down.

A boundary, for anyone who read this week’s piece on AI assistant logs: the administrator’s access log is itself one of the “instruments from which the possibility of remote monitoring of workers’ activity also follows”, under article 4 of the Italian Workers’ Statute — we have already written about that with regard to the prompt register. Here the question comes first, and it is a different one: who has the right to open that log, under what written designation, and who checks that it is opened only for the reasons it was switched on for.

What to do now

Six things, each verifiable on its own. A written, up-to-date list of who administers the AI system, with the assessment of subjective characteristics and the exact scope of each person — an individual, not a generic role. Individual credentials, never a shared “admin” account: precisely the point that cost Realmaps €100,000. The logical access log, retained for at least six months, complete and with verifiable integrity. A review of the administrator’s work at least once a year, minuted — not merely turning logging on. Where the administrator is external, the article 28 contract with the clauses set out above, not a supplier’s verbal assurances. Where the processing concerns workers’ data, the administrator’s identity made known or knowable in the privacy notice: the same principle that underpins protection of trade secrets — measures count if they can be produced, not merely declared.

How we solve it

We say it on our home page in plain terms: on-premise machines stay autonomous, are not deeply integrated into the client’s network, and we manage them jointly with the client — because almost no enterprise, not even in healthcare or defence, already has someone in-house who administers AI models. That is precisely the case in which the figure of the system administrator has to be named, bounded and traced in writing, not left to a shared account used by whoever picks up the phone that day.

That is why we work in two modes, always both available. On-premise, in the client’s own environment: the client’s IT lead and our own engineer are each designated individually, with distinct, written scopes — we hold no access beyond the maintenance we have been designated for. CSIDIA dedicated cloud — an environment reserved for the single client, accessed over a dedicated VPN, with the data centre resident in Italy and premises we staff ourselves: here we are, by construction, the administrator of the infrastructure, and the article 28 contract, the access log and the periodic review are not optional extras — they are the very perimeter we sell. In both cases the designation is signed before the system is switched on, not reconstructed after an incident.

Do you know today who holds the administration credentials for your AI system, under what written designation, and with what access log? Half an hour with one of our experts is enough for a first map.

Sources