BOOK NOW • BOOK NOW • BOOK NOW •
eng
ita

Important notice on personal data security

What happened
On 14 August 2025, our hotel was informed — following a technical alert — that certain scanned copies of customers’ identity documents (passports) had been published and offered for sale on a forum hosted on the so-called “dark web”. The images come from the computer system dedicated to managing the identity documents of guests staying at accommodation facilities, which by law must be transmitted to the Italian police authorities. This computer system is owned by a company outside our group, which was subject to unauthorized access by third parties using extremely insidious software (so-called "malware"). This particular malicious software infiltrated the computer archive managed by this company outside our group and extracted several tens of thousands of identity documents stored digitally by it. Of these, approximately 3,600 identity documents were acquired by our facility between July 2023 and August 2025. The image copies include both the front and back of the identity document, containing identifying data such as name, surname, date and place of birth, nationality, document number, and photograph.

What this means under the law
According to the General Data Protection Regulation (GDPR – EU Regulation 2016/679), this incident, for which our company is not responsible, constitutes a personal data breach, i.e., an event that involves the unauthorized disclosure of information relating to natural persons.
Article 34 of the GDPR requires data controllers to inform affected individuals promptly whenever a breach is likely to result in a high risk to the rights and freedoms of natural persons.

Possible risks for customers
• EN: Identity theft, financial fraud, unlawful use of data to obtain services or forged documents, targeted phishing attacks.

Measures taken by the Hotel
1. Notification of the incident to the Data Protection Authority.
2. In-depth technical investigation with the service provider.
3. Strengthening security measures (multi-factor authentication, network segmentation, password change).
4. Communication to interested parties with self-protection instructions via this web page on the Hotel website.

What you can do
• Monitor bank accounts and payment instruments.
• Report any suspicious use of your data to the authorities.
• Be cautious of unsolicited emails or phone calls.
• Consider replacing the compromised identity document.
• Use credit monitoring or identity theft alert services.

FAQ
1. Is my passport definitely affected?
We cannot confirm each case individually here. Contact us directly and we will reply as soon as possible.

2. Is it safe to keep staying at the hotel?
Yes.The security systems adopted by the third-party company are also extremely strict, and personal data is managed with highly effective security measures.

3. What should I do right now?
Follow the self-protection measures above and keep copies of any reports made to the authorities.

Contact for assistance,
Email: fom@borghesecontemporaryhotel.com





Tailored for you

Special Offers

Long Stay - 4 nights - flexible rate
stay for 4 nights and take advantage of our special offer!