Cass.Civ. - 15625/2026
| Cass.Civ. - 15625/2026 | |
|---|---|
| Court: | Cass.Civ. (Italy) |
| Jurisdiction: | Italy |
| Relevant Law: | Article 5(1)(c) GDPR Article 5(1)(d) GDPR Article 5(1)(a) GDPR Article 5(2) GDPR Article 6(1)(e) GDPR Article 6(3) GDPR Article 24 GDPR Article 25 GDPR Article 35 GDPR |
| Decided: | 21.05.2026 |
| Published: | |
| Parties: | Istituto nazionale della previdenza sociale (INPS) |
| National Case Number/Name: | 15625/2026 |
| European Case Law Identifier: | |
| Appeal from: | Tribunale di Roma 4735/2022 |
| Appeal to: | Unknown |
| Original Language(s): | Italian |
| Original Source: | Corte di cassazione (in Italian) |
| Initial Contributor: | ap |
The Supreme Court revoked a €300,000 fine against the National Institute for Social Security and held that the institute lawfully performed eligibility checks in relation to a subsidy given during the pandemic. According to the court, these checks did not violate the principles of data accuracy and minimisation.
English Summary
Facts
Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities.
The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed.
The DPA appealed this decision to the court.
Holding
The court dismissed the appeal.
The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior.
The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake.[1] The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR.
In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process.
Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.
JUDGMENT
on the appeal registered under No. 20692/2022 R.G. filed by:
Personal Data Protection Authority, represented and defended
by the State Attorney General
-appellant-
against
INPS – National Institute for Social Security, represented and defended
by attorneys Gaetano De Ruvo, Paolo Aquilone, and Mauro Sferrazza
-counterappellant-
against the judgment of the Court of Rome No. 4735/2022 filed on
March 24, 2022.
Having heard the report of the case presented at the public hearing on January 22, 2026
by Councilor Davide De Giorgio;
Having heard the Public Prosecutor represented by Deputy Attorney General
Michele Di Mauro, who concluded that the appeal be granted;
Court of Cassation - unofficial copy
Civil Sentence, Section 2 No. 15625 Year 2026
President: MILENA FALASCHI
Rapporteur: DAVIDE DE GIORGIO
Publication date: 05/21/2026
2
Having heard Marina Russo of the State Attorney's Office,
counsel for the appellant, who referred to the defense;
Having heard Gaetano De Ruvo and Paolo Aquilone, counsel for the
counter-appellant, who referred to the defense briefs.
FACTS OF THE CASE
INPS – National Institute for Social Security filed an appeal before the
Court of Rome pursuant to Articles 152 of Legislative Decree No. 196/2003 and 10
of Legislative Decree No. 150/2011 against Order No. 87/2021 of the Italian Data Protection Authority, with which the latter, having declared the unlawfulness of the processing carried out by the institution in violation of EU Regulation no.
679/2016 on the protection of personal data, had ordered the
institution to pay a fine of €300,000.00,
in addition to the deletion of all personal data processed up to that point in violation of the data minimization principle and the performance of a
data protection impact assessment pursuant to Article 35 of the Regulation with reference to the processing, before restarting any
processing operation, including as part of a comprehensive
impact assessment relating to all processing carried out by the Institute for
this purpose.
As emerges from the contested ruling, the disputed issue revolved
around the methods by which INPS had performed some of the second-level
checks following the disbursement of the so-called "Covid bonus" during
the pandemic emergency. Given the need to proceed with the immediate payment
of the benefit, a complete verification of the requirements for obtaining it was reserved for a later phase. On the assumption that
parliamentarians and regional and local administrators fell under
a social security regime incompatible with receiving the benefit in question,
the institute conducted a verification by acquiring the personal data
of elected office holders from the databases of the Chamber of Deputies, the Ministry
of the Interior, and, later, the Senate. It extracted their
Court of Cassation - unofficial copy
3
tax codes using the criteria set out in the Ministerial Decree of March 12, 1974, and, by cross-referencing
the data thus obtained with the tax codes of those who had submitted
an application for the bonus, it identified the holders of political office who
had submitted the request.
With the provision in question, the Italian Data Protection Authority found the following to have been violated:
1) the principle of lawfulness, fairness, and transparency of processing pursuant to
Article 5, paragraph 1, letter a), of the Regulation; 2) the principle of
data minimization pursuant to Article 5, paragraph 1, letter c), of the Regulation;
3) the principle of accuracy pursuant to Article 5, paragraph 1, letter d), of the
Regulation; 4) the protection of personal data by design and
by default pursuant to Article 25 of the Regulation; 5)
the obligation to conduct a data protection impact assessment pursuant to
Article 35 of the Regulation; 6) the principle of accountability pursuant to
Articles 5, paragraph 2, and 24 of the Regulation.
The opponent argued that the Guarantor's findings were unfounded and
requested the annulment of the decision, or, alternatively, a reduction
of the imposed fine.
The respondent appeared in court, requesting that the
opposition be dismissed.
With ruling no. 4735/2022, published on March 24, 2022, the Court of Rome,
upholding the appeal, annulled the contested decision and
ordered the respondent to reimburse the opponent for the legal costs.
In its reasoning, the Court noted the following:
With reference to the violation of the principle of lawfulness, fairness, and
transparency of processing, it should be noted that the same legislative
provision as set out in Legislative Decree no. 18/2020 to exclude the right to the Covid bonus
for those who were enrolled, at the time of submitting the
application, in other mandatory social security schemes, nor did the request to the Ministry of Labor for
Court of Cassation - unofficial copy
4
for an opinion, the content of which was found to be in accordance with the decisions
adopted by the institution, lead to any
conclusions to the contrary.
The Court also found the respondent's conduct to be compliant with the
principle of minimization in light of the following considerations: - it
guaranteed faster checks and was the only one capable of
also including applications still under investigation, which
could have been accepted at a later time because they were still
pending, or by virtue of the subsequent extension of the deadlines for
submitting applications; - limiting the benefit to only
successfully resolved applications would have entailed, in the event of a review or
appeals, the need to implement new benefits; - the data processed had
been limited to the minimum necessary to verify entitlement to the bonus,
or for the specific (and dutiful, as well as legitimate) purpose pursued
by INPS.
As for the violation of the principle of accuracy, the complaint had to
be considered raised in the abstract, given that no case of so-called homocody
appeared to have occurred in practice. Furthermore, given that Article 5 of the
Regulation, in recommending "taking all reasonable measures
to promptly erase or rectify inaccurate data with respect to the
purposes for which they are processed," provides for the possibility of a post-processing accuracy check, provided that it is collected on the basis of
sufficiently reliable elements, it should have been noted that the tax codes had been
calculated based on a procedure established by a regulatory
law and on personal data extracted from official databases and open to
free consultation.
A violation of the principle of personal data protection by design and by default was ruled out on the basis of the general nature of the complaint, in the absence of any concrete suggestion of a lawful alternative course of action, and also given the fact that the procedural processing of the compensation application did not
Court of Cassation - unofficial copy
5
include the performance of subsequent checks, and, finally,
taking into account the foreseeability of the processing for the control purposes
in question; as for the risks to the rights and freedoms of the data subjects, they
had to be deemed nonexistent, given the failure
to disclose the names of the politicians who had requested the payment
of the bonus and the absence of any concrete interference of such risks with the
specific violations contested.
Regarding the violation of the obligation to conduct a data protection impact assessment, the Court, despite noting that the processing was carried out on a large scale, ruled out the existence of the conditions for such an assessment, since the only concrete risk of the cross-referencing of data was the loss of an unduly paid economic benefit, a risk not contemplated in Recital 75 of the Regulation, while the risk of disclosure of the data was not causally related to the processing itself. Finally, once the existence of other violations had been ruled out, the violation of the principle of accountability had also been deemed nonexistent. It was also noted that INPS had sent a communication to the
Garante in which, in addition to indicating the role of the
data protection officer, identified as the Central Anti-Fraud Directorate, it also specified that the press reports
relating to the matter had been disseminated through sources outside
the institute, as the press outlets involved had reported,
and that the measures adopted appeared entirely adequate, given that the
processing did not present any high risk, given that
it consisted of cross-referencing non-sensitive information, taken from an
open data system, with information provided by the data subjects, within the
specific purposes for which it had been collected.
The Italian Data Protection Authority appealed the ruling in question on eight grounds.
Court of Cassation - unofficial copy
6
The INPS – National Institute for Social Security (INPS) opposed the appeal with a
counterappeal.
After a public hearing was scheduled, the Public Prosecutor, represented
by Deputy Prosecutor General Dr. Michele Di Mauro, presented
written conclusions, and the INPS filed an explanatory memorandum.
REASONS FOR THE DECISION
1. The objection of inadmissibility of the appeal
for lack of specificity, raised by the counterappellant, must be dismissed, noting,
in general, that the appellant has fully identified the provisions of law
allegedly violated, examined their content, and recalled the
statements contained in the contested judgment deemed to be in conflict
with the provisions in question, stating the reasons therefor.
2. The first ground is listed as follows: violation and/or misapplication
of the law in relation to Article 5, paragraph 1, letter a) of
Regulation (EU) No. 679/2016 of the European Parliament and of the Council of 17 December 2016 on the
protection of natural persons with regard to the processing of personal data
and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation), also
in conjunction with Articles 27 to 31 and 38 of Legislative Decree 18/2020 – Article
360, paragraph 1, no. 3 of the Italian Code of Civil Procedure.
In particular, according to the appellant, given that the INPS had not been accused of lacking a legal basis for the benefit, it was noted that the institution had carried out its assessments on the existence of the conditions legitimizing the payment of the bonus for specific categories of individuals, and not in relation to the individual beneficiary. This was evident from the fact that the Ministry of Labor's opinion had been requested after the benefits had begun, in relation to parliamentarians and the representative bodies of local authorities, and not in general terms with respect to the requirements established by law (existence, or otherwise, of other
significant social security schemes). According to the appellant, any interpretative doubts regarding the scope of the provision should have been resolved in relation to the individual applicants in the abstract, and in any case before carrying out the second-level assessment regarding whether the individual belonged to one or the other category. Specifically,
while the method chosen by INPS had involved checks on
categories of individuals (members of parliament and local administrators) who
could have (along with many other categories) applied for
the benefit, the law instead allowed checks on all
individuals who had actually requested and obtained the benefit,
to verify the existence of the legal requirements to obtain it. For the purposes
of these checks, the tax codes declared when submitting the
application could have been cross-referenced with those in the
available databases (INPS and Tax Registry).
The reason is unfounded.
The processing at issue appears to have been carried out by INPS
for the performance of a task carried out in the public interest or connected
to the exercise of public authority vested in the data controller.
In this regard, the Guarantor has framed the aforementioned public interest within the
provision of art. 2-sexies, paragraph 2, letters l) and m) of Legislative Decree No.
196/2003, concerning, respectively, "control and
inspection activities" and "granting, liquidation, modification, and revocation of
economic benefits, incentives, donations, other emoluments, and
authorizations."
The acquisition aimed at carrying out second-level controls
concerned the personal data of regional and local deputies and administrators
and was carried out from open databases made available
to anyone, via the dedicated web pages made available by the
Chambers of Parliament and the Department for Internal and
Territorial Affairs of the Ministry of the Interior.
Court of Cassation - unofficial copy
8
In this regard, it is undisputed that the sensitive data referred to in
art. 9 of Regulation (EU) 2016/679 of the European Parliament, namely
personal data revealing racial or ethnic origin, political
opinions, religious or philosophical beliefs, or trade union membership,
as well as genetic data, biometric data intended to uniquely identify
a natural person, data concerning health or data concerning a natural person's sex life or
sexual orientation: both parties denied
that the data processed fell within the aforementioned provision, and the
Court also expressly noted that they were not sensitive data.
Therefore, the processing itself falls legally within the scope of
Article 6, paragraph 3, letter b) of the Regulation, referred to in Article 2-ter of Legislative Decree
No. 196/2003, in the text in force at the time the incident occurred
that led to the imposition of the sanction, i.e., before the
amendment introduced by Legislative Decree No. October 8, 2021, No. 139, converted with
amendments by Law No. 205 of December 3, 2021.
In particular, the applicability of Article 2-sexies of Legislative Decree No.
196/2003, which specifically concerns the processing of the
special categories of personal data referred to in Article 9, paragraph 1, of the Regulation, must be excluded.
Moving on to examine the appellant's complaints, the first provision
which the appellant claims has been violated is Article 5, paragraph 1, letter a) of
Regulation (EU) No. 679/2016 of the European Parliament, which provides that
personal data shall be "processed lawfully, fairly and in a transparent manner in relation to the data subject (lawfulness, fairness and transparency)".
In turn, Article Article 6 of the Regulation governs the lawfulness of
the processing itself, providing, among other things, in paragraph 3, that in the event that
it occurs, without the data subject's consent, for the performance
of a task carried out in the public interest or connected to the exercise of official
authorities vested in the data controller, the data processing must be based on
an adequate regulatory basis.
Court of Cassation - unofficial copy
9
With the contested ruling, INPS was accused of
processing data for the purpose of second-level checks regarding
the disbursement of the bonus under the relevant aspect, solely because
it occurred before the entitlement to it had been established
in the cases in question.
In this regard, recital 41 of the Regulation contains the following
indications: "Where this Regulation refers to a
legal basis or legislative measure, this does not necessarily require
the adoption of a legislative act by a parliament, without prejudice to the
requirements of the constitutional order of the Member State concerned. However, such a legal basis or legislative measure should
be clear and precise, and its application foreseeable, for the persons
subject to it, in accordance with the case law of the Court of Justice of the European Union (the "Court of Justice") and the European Court of Human Rights."
For its part, the Court of Rome, in relation to the above, essentially
deemed the legal basis
consisting of the emergency legislation referred to in Legislative Decree no. 101/2001 to be sufficiently clear and precise. 18/2020, with the consequent finding of irrelevance of the subsequent request for a ministerial opinion,
which had confirmed the institution's decisions.
The assessment in question is based on the merits and is therefore unquestionable in this case,
except for any flaw in the reasoning, which is not alleged in this case.
In any case, it should be noted that: - the condition for the benefit, consisting
in the applicants' failure to enroll in other mandatory social security schemes,
was directly provided for by Legislative Decree no. 18/2020; - any
interpretative doubts on the part of INPS at the time of the
treatment did not in itself affect the clarity and precision of the
rules; - the ministerial opinion, subsequently acquired, did not constitute a
secondary source of detailed legislation compared to the primary one
mentioned above, so it was only to the latter that it was necessary
Court of Cassation - unofficial copy
10
to refer in order to verify whether, at the time of the processing, the relevant
legal basis was sufficiently clear and precise; - the same
paragraph 1 of Article 2-ter of Legislative Decree No. 196/2003, in the text currently in force
ratine temporis, provides, in relation to the processing of personal data carried out
for the performance of a task carried out in the public interest or connected
to the exercise of official authority, that the legal basis provided for in Article 6,
paragraph 3, letter b), of the Regulation is constituted exclusively by
a provision of law or, in the cases provided for by law, by a regulation, sources
both different from the ministerial opinion.
Therefore, the violation of the law alleged by the appellant cannot be identified, given the objections raised in the contested decision.
The additional considerations formulated in the appeal for annulment, far from contradicting the reasoning adopted on this point by the trial judge,
concern different aspects that, with specific reference to the violation in question,
were not considered either in the contested decision or,
therefore, in the contested judgment.
In any case, the appeal does not specify whether and in what terms the
arguments in question were formulated during the trial on the merits,
and therefore they are inadmissible here.
3. The second ground is titled as follows: violation and/or false
application of the law in relation to Article 5, paragraph 1, letter c), of
Regulation (EU) 2016/679 of the European Parliament and of the Council of 17 December 2016 on the
protection of natural persons with regard to the processing of personal data
and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation), also
in conjunction with Articles 27 to 31 and 38 of Legislative Decree 18/2020 – Article
360, paragraph 1, no. 3 of the Italian Code of Civil Procedure.
In particular, according to the appellant, given that the processing of personal data
relating to parliamentarians and regional and local administrators
Court of Cassation - unofficial copy
11
had not been limited to the beneficiaries of the benefit, but had instead
involved all those who had applied for the Covid bonus, including
those whose applications, already at the first-level review,
had been examined and rejected, it should have been considered that, if the purpose
of the scheme was to recover the sums illegitimately received
by political office holders, the processing should have been
limited to those who had actually received the benefit. With regard
to those who, despite having submitted an application, had not
received the bonus, there was no reason to carry out a second-level
review and, therefore, no reason to process the data. Ultimately,
according to the appellant, it was not permissible to apply preventive and generalized treatment to any non-beneficiary applicant,
including those who had demonstrated acquiescence to the institution's
rejection decision.
The fourth ground is listed as follows: violation and/or misapplication
of the law in relation to Article 25 of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data, and
repealing Directive 95/46/EC (General Data Protection Regulation) – Article 360, paragraph 1, no. 3 of the Italian Code of Civil Procedure.
In particular, according to the appellant authority, the failure to adopt predetermined
criteria to limit the processing of personal data to that which is
strictly necessary was an undisputed fact and such as to constitute a
violation of Article 25 of the Regulation. The foreseeability of the
processing in the presence of a legitimate interest of the data controller did not affect
the need to implement the aforementioned provision, and this is without considering
that the processing at issue was carried out not for a legitimate interest of the data controller, but rather for the performance of a task in
the public interest, a hypothesis that is very different from the first.
Court of Cassation - unofficial copy
12
The two grounds in question appear closely connected, given that the
lack of adequate processing planning criticized
by the INPS by the Data Protection Authority resulted, in the latter's opinion,
in the omission of appropriate measures to ensure that, by default,
only the data necessary for each specific purpose of the processing was processed, thus violating the principle of data minimization.
These grounds are unfounded.
Art. 5, paragraph 1, letter Article 25(2) of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 provides that personal data shall be "adequate, relevant and
limited to what is necessary in relation to the purposes for which they are processed
("data minimization")."
Recital 39 of the Regulation also states that "personal data
should be processed only if the purpose of the processing cannot
reasonably be achieved by other means."
In turn, Article 25(2) of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 provides as follows: "The controller shall
implement appropriate technical and organizational measures to ensure that, by default, only personal data
which are necessary for each specific purpose of the processing are processed. This obligation applies to the amount of
personal data collected, the scope of the processing, the period of
retention, and accessibility. In particular, these measures ensure
that, by default, personal data are not made accessible
to an indefinite number of natural persons without the intervention of the
natural person."
In this regard, it has been observed that the principle of privacy by design aims
to ensure the existence of an appropriate level of privacy and protection
of personal data from the design phase of any
system, service, product, or process, as well as throughout their
lifecycle. In other words, it aims to ensure an appropriate level of
data protection in all processing activities and implementations
Court of Cassation - unofficial copy
13
carried out within an organization. To fulfill this
principle, data controllers and processors must be proactive and
preventative, evaluating and implementing suitable technical and organizational
measures to integrate data subject protection safeguards into the processing and to apply the fundamental data protection principles specified in Article 5 of EU Regulation no. 2016/679, such as
transparency, purpose limitation, and minimization (see: Cass. No.
28385/2023).
Specifically, it is undisputed that the cross-referencing of data did not only concern
political office holders who had actually received the allowance, but also extended to individuals whose
applications had already been rejected.
The counter-appellant, moreover, pointed out that, as deduced
in the original appeal filed before the Court, the processing of all
applications was still ongoing, and even those initially rejected were
subject to re-examination, because Legislative Decree No. 24/2020 had extended the deadline
for submission and removed some incompatibilities already foreseen with the
previous Legislative Decree No. 18/2020.
In this regard, it should be noted that, in general, recital 4 of the
Regulation states that "the right to the protection of personal data
is not an absolute prerogative, but must be considered in light of its
social function and must be balanced with other fundamental rights,
in accordance with the principle of proportionality."
Even the principle of data minimization, by its very formulation,
cannot be considered absolute, as it requires carrying out,
on a case-by-case basis, a comparison between the protection of the right to
the confidentiality of personal data and the needs justifying its
processing.
Furthermore, this comparison cannot fail to take into account the
type of data being processed, since it is clear that, for this purpose,
Supreme Court - unofficial copy
14
sensitive data as referred to in Article 9 of the
Regulation cannot be placed on the same level as data that are not sensitive.
In this case, as seen above, the INPS's needs were institutional ones
related to the performance of second-level checks on
applications for access to the so-called Covid bonus, in order to verify actual
entitlement to the benefit and avoid undue payments or fraud.
In general, the interpretation of case law has
found that the right to demand proper management of one's personal
data, although falling within the fundamental rights set forth in Article 2 of the Constitution,
is not a "tyrant" or a "totem" to which other
rights that are equally constitutionally relevant must always be sacrificed. On the contrary, the
rules on the protection of sensitive data must be coordinated and balanced with the
constitutional provisions that protect other, overriding rights, as far as
the public interest in the speed, transparency, and effectiveness of
administrative activity is concerned. Determining whether a data subject has violated the
legal rules governing the management of other people's data requires interpreting the latter,
balancing the interests they protect with other potentially conflicting
constitutionally protected interests (see: Cass. No. 10280/2015; Cass. No. 6177/2023).
The need to balance the various interests at stake with
reference to the principle of data minimization under Article 5,
paragraph 1, letter c), of the Regulation has also been affirmed by the
Court of Justice of the European Union (see: judgment of 02.03.2023 of the Third
Chamber of the Court in Case No. C-268/21, concerning the production of a
document containing personal data in civil proceedings).
The assessment of the adequacy, relevance, and necessity of the
processing with respect to its purposes, taking into account all the circumstances of the specific case, is the responsibility of the judge on the merits and is final in the legitimacy proceedings, where duly justified.
Court of Cassation - unofficial copy
15
In this case, the data extracted from the institutional databases and used for the purposes of the checks were clearly public registry data,
since they are freely accessible to anyone, and the additional data
with which they were cross-referenced were those provided to the institution by
those who had submitted the application for access to the bonus and whose
treatment constituted a mandatory step in assessing
whether or not they were entitled to the benefit.
Furthermore, the processing clearly took place in a
particular context, linked to the state of emergency, the high number of requests
submitted, and the need to ensure a prompt institutional response.
The Court, taking into account the Guarantor's observations and the defenses presented
by INPS, held that the treatment complied with the principle of
minimization, given that the procedure followed ensured greater
speed of checks and was the only one capable of also including
applications still under investigation, which could have been
accepted at a later time, either because they were still pending or
by virtue of the subsequent extension of the deadlines for submitting them.
In this case, considering the foregoing and taking into account the
prevalence of the public interest in a speedy conclusion of the
procedure, it must be considered that the reasoning of the judge of the merits
complied with the principles set out above.
For the rest, this is an assessment of the merits, adequately
motivated and not subject to review here since it is governed
by the determination of the indispensability of the treatment as carried out
(see: Cass. No. 9922/2022).
According to the Guarantor, the processing in question was not carried out in
compliance with the principles of personal data protection, from design
and by default, enshrined in Article 25 of the Regulation. This is due to the failure to predetermine the conditions
Court of Cassation - unofficial copy
16
preventing parliamentarians and regional and local administrators from being entitled to the bonus, the processing of data not necessary for
the performance of second-level controls, and the failure to
consider the risks that the processing posed to the rights and
freedoms of data subjects, including those arising from possible
inaccuracies in the methods used to calculate the data subjects' tax codes.
In this regard, the absence of objective grounds for uncertainty relevant to the identification of the regulatory basis for the processing and the lack of a violation of the principle of data minimization clearly demonstrate that the counter-appellant institution is not obliged to establish default data processing settings that are different
and additional to those commonly used in carrying out the institution's normal institutional activities. Therefore, on this point too, the contested decision appears to comply with Article 25 of the
Regulation.
4. The third ground is listed as follows: violation and/or misapplication
of the law in relation to Article 5, paragraph 1, letter d) of
Regulation (EU) No. 679/2016 of the European Parliament on the
protection of natural persons with regard to the processing of personal
data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation) – Article
360, paragraph 1, no. 3 of the Italian Code of Civil Procedure.
In particular, according to the appellant, the INPS's extraction of the tax codes of members of the
political class was incorrect, using personal data acquired by consulting the databases of the
Chambers of Parliament and the Ministry of the Interior, and the
use of the system referred to in Ministerial Decree No. 2227 of 12 March 1974, which did not
avoid the risk of so-called "unauthorized access." homocodie (i.e., identical tax code between
two or more people); in fact, according to the court, the potential harm resulting from the
risk in question would be significant in itself.
Court of Cassation - unofficial copy
17
The reason is unfounded.
Art. 5, paragraph 1, letter d) of the European Parliament Regulation
679/2016/EU provides that personal data must be "accurate and, where necessary,
kept up to date; every reasonable step must be taken to
erase or rectify without delay any data that are inaccurate, having regard to the purposes
for which they are processed ('accuracy')".
Recital 39 of the Regulation also states that "every reasonable step should be taken to
ensure that inaccurate personal data are
rectified or erased".
Since the topic of identifying data is concerned,
Recital 26 is also relevant. After stating that "it is desirable to apply the
principles of data protection to all information relating to an identified or identifiable
natural person," it states that "to establish
the identifiability of a natural person, account should be taken of all means, such as
single-handling, which the controller or a third party may reasonably
use to identify that natural person,
directly or indirectly." Furthermore, "to determine whether means are reasonably likely to be used to identify the natural person,
all objective factors should be taken into account, including the
costs and the time required for identification, taking into account both the
technologies available at the time of the processing and technological
developments."
In this regard, it is true that the accuracy of the data, although it can be
further verified after acquisition, constitutes a very specific
objective of the acquisition activity, to be pursued by adopting
the most suitable methods to achieve it.
It should be noted, however, that the personal data collected from the public databases
of the Chambers of Deputies and the Ministry of the Interior were to be presumed
accurate, given their institutional origin, and that the procedure
Court of Cassation - unofficial copy
18
used to extract the tax code from them was the official one
established by Ministerial Decree no. 2227 of March 12, 1974.
Regarding the risk of so-called homocodiality, Article 6 of the aforementioned Ministerial Decree provides that,
when the alphanumeric expression relating to the first fifteen characters of the
code is common to two or more subjects, it is differentiated for
each of the subjects following the first coded subject, which
means that none of the subjects involved is assigned the code thus
determined.
From the foregoing, it follows that, in the event that the alphanumeric expression relating to the first fifteen characters thus
calculated is common to multiple subjects, none of these subjects could have been identified
using the code thus obtained.
A further corollary of the foregoing is the absolute absence, in such a case,
of any risks to confidentiality, given the impossibility of associating any
subject with the possibly incorrect code.
Moreover, the legitimate possibility of error is permitted in light of the
legislative provision concerning the deletion or rectification of data
that may be inaccurate with respect to the purposes for which they are processed.
As noted by the trial judge and not questioned here,
in practice, no inaccuracy was found in the identification
of the individuals whose data were cross-referenced, so the
Garante's challenge is purely abstract.
The considerations formulated by the trial judge appear correct in light of the foregoing, and to them it must be added that the
alternative course of action proposed by the Garante, consisting in requesting tax
codes from the Tax Registry, would have caused, in addition to a delay
in the timing of second-level checks, also a wider
circulation of the personal data necessary for their performance.
5. The fifth ground is listed as follows: violation and/or false
application of the law in relation to art. 35 of the Rules of Procedure of the
Court of Cassation - unofficial copy
19
European Parliament 679/2016/EU on the protection of natural persons
with regard to the processing of personal data and on the free
movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Art. 360, paragraph 1, no. 3, Code of Civil Procedure.
In particular, according to the appellant authority, there was a risk to the
rights and freedoms of individuals, which was not constituted by the possibility of
losing, as a result of the controls, an unduly received economic benefit; on the contrary, it was the processing itself, if carried out without a prior
risk assessment, that could result (potentially
even unjustly) in the loss of the right.
The sixth ground is listed as follows: failure to provide reasons regarding a fact
that is decisive for the judgment and was the subject of discussion between the parties (Article
360, paragraph 1, no. 5, Code of Civil Procedure).
In particular, the appellant complains that, in examining
whether the conditions for the impact assessment were met,
the judge on the merits referred to a prerequisite
("a method that goes beyond the reasonable expectations of the interested party") not
mentioned in the contested decision, and instead completely
ignored the decisive criterion relating to the "creation of a
correspondence or combination of a set of data," expressly
indicated.
The grounds, which must be examined together given their connection,
are unfounded.
Article 35, paragraph Article 1 of Regulation (EU) No 679/2016 of the European Parliament and of the Council
provides that, "where a type of processing, in particular using new technologies, and taking into account the nature, scope, context, and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing on the protection of personal data."
Court of Cassation - unofficial copy
20
The risks to the rights and freedoms of natural persons that may justify
the need for an impact assessment are described as follows in
Recital 75: "Risks to the rights and freedoms of natural persons,
of varying likelihood and severity, may result from processing of
personal data that may result in physical, material or
non-material damage, in particular: if the processing may lead to
discrimination, identity theft or fraud, financial loss,
damage to reputation, loss of confidentiality of personal data
protected by professional secrecy, unauthorized reversal of
pseudonymisation, or any other significant economic or social
harm; if data subjects risk being deprived of their rights and
freedoms or prevented from exercising control over their personal
data; if personal data revealing
racial or ethnic origin, political opinions, religious or
philosophical beliefs, trade union membership, as well as genetic data, data concerning
health, or data concerning a person's sex life or criminal convictions or offences or related
security measures are processed; if personal aspects are evaluated,
in particular by analyzing or predicting aspects concerning
professional performance, economic situation, health, personal preferences
or interests, reliability or behavior, location or
movements, for the purpose of creating or using personal profiles; if personal data of vulnerable natural persons, in particular minors, are processed; if the
processing concerns a significant amount of personal data and a large
number of data subjects.
It should be noted at the outset that neither party has referred to the use, for the purposes of the processing, of technologies that are new or different from those
usually employed by the respondent institution for its institutional
activities.
That said, it is noted that the "Guidelines on data protection impact assessment
and determining whether processing is likely to result in a high risk" for the purposes of Regulation (EU) 2016/679" of the Article 29 Data Protection Working Party
of 4 April 2017, as amended and last adopted on 4 October 2017
and endorsed by the European Data Protection Board on 25
May 2018 ("WP 248, rev. 01"), have identified nine criteria to be taken into account for the purpose of identifying processing operations that
may result in a "high risk": 1) assessment or assignment of
a score, including profiling and prediction, in particular taking into account "aspects concerning performance at work,
economic situation, health, personal preferences or interests,
reliability or behaviour, location or the movements
of the data subject”; 2) automated decision-making that produces legal
effects or similarly significantly affects individuals; 3)
systematic monitoring of data subjects; 4) sensitive data or data of a
highly personal nature; 5) large-scale data processing; 6)
matching or combining data sets; 7) data
relating to vulnerable data subjects; 8) innovative use or application of new
technological or organizational solutions; 9) when the processing itself
"prevents data subjects from exercising a right or from availing themselves of a
service or a contract"
In turn, the Garante, with provision no. 467 of 11 October 2018,
deemed that the presence of two or more of the aforementioned criteria indicates a
processing that presents a high risk to the rights and freedoms of
data subjects and for which a data protection impact assessment is therefore required.
It identified the list of types of
processing, subject to the consistency mechanism, to be subjected to an
impact assessment, reported in Annex 1, which is an integral part of the
provision in question.
In this case, the criteria indicated in the contested
provision of the Garante are the following: 1) the processing of
Court of Cassation - unofficial copy
22
data on a large scale; 2) the creation of correspondences or combinations of
data sets; 3) the fact that the processing itself prevents data subjects
from exercising a right or availing themselves of a service or contract.
Now, in the contested ruling, the
existence of the first condition is positively verified (with the clarification that it concerned
large-scale processing, but not involving the sensitive
data referred to in Article 9 of the Regulation), while the
existence of the third was excluded.
As for the second, contrary to what the
appellant complained about, it was taken into consideration in the ruling, in the part
where reference was made to the "manner that goes beyond the reasonable
expectations of the data subject."
It should be noted that the text of the WP29 guidelines, cited by both the
parties and the trial judge, on this point is as follows:
"creating correspondences or combining sets of data, for
example starting from data deriving from two or more processing operations
carried out for different purposes and/or by different data controllers in
a manner that goes beyond the reasonable expectations of the data subject."
It follows that the trial judge's reference to exceeding the
data subject's reasonable expectations refers precisely to the criterion in question, a criterion that the appellant authority erroneously believes - given
the above - to have been overlooked, and whose presence, however, was taken
into consideration and reasonedly excluded by the Court.
On this point, apart from complaining of a lack of consideration - non-existent in light of the above -
the appellant has made no submissions.
Furthermore, the element relating to exceeding the reasonable expectations of the data subject was deemed incompatible with the public nature of the identification data used by INPS.
The sixth ground of appeal therefore has been rejected.
From the foregoing, the fifth ground of appeal must also be rejected.
Court of Cassation - unofficial copy
23
Indeed, Article 35, paragraph 1, of Regulation (EU) No 679/2016 of the European Parliament and of the Council
679/2016/EU, in providing for the possibility of "a high risk to the rights and freedoms of natural persons" such as to require a prior
impact assessment, refers to the processing to be carried out in itself,
regardless of the manner in which it was subsequently carried out.
In fact, the impact assessment, which must be conducted before
the processing is carried out, presupposes an ex ante assessment of
the existence of any risks; the appellant also agrees with this,
as is evident from the appeal on page 16.
Now, the Guarantor, in addition to failing to mention the use of new
technologies, does not explain the potential risks of a large-scale
processing operation that would have justified, ex ante, and therefore
regardless of the violations currently attributed to INPS, an impact assessment. This is in contrast to the judge
on the merits, who instead noted that the processing itself did not
involve any publication or disclosure of personal data and that
the only potential risk for its recipients was the loss,
in the event of an unfavorable outcome of the checks, of an unduly received benefit.
Moreover, as the Court accurately stated, it was the
lack of requirements that led to the revocation of the benefit, and not the
treatment itself.
It follows that, given the lack of coexistence of multiple indicators of the
necessity of an impact assessment, the contested ruling is
legally correct.
6. The seventh ground of appeal is listed as follows: violation and/or misapplication of the law in relation to Articles 5, paragraph 2, and 24 of Regulation (EU) No 679/2016 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Court of Cassation - unofficial copy
24
(General Data Protection Regulation) - Article 360, paragraph 1, no. 3
CPC.
In particular, according to the appellant, the Court's finding
that there was no violation of the principle of accountability was erroneous when based on the non-existence of other violations.
The eighth ground is listed as follows: nullity of the judgment due to the mere
appearance of the reasoning (Article 360, paragraph 1, no. 4, Code of Civil Procedure).
In particular, according to the appellant, the arguments used by the
Court to affirm the non-existence of the violation in question were
eccentric with respect to what the Garante contested in the contested
order, as well as irrelevant to the principle of accountability,
so that the reasoning on this point was merely apparent.
The two grounds, which must be examined together because they are connected, are
unfounded.
Article 5, paragraph 2, of Regulation (EU) No 679/2016 of the European Parliament
provides that "the controller is responsible for compliance with
paragraph 1 and able to demonstrate it ('accountability')".
In turn, Article 24 of Regulation (EU) No 679/2016 of the European Parliament
provides the following: "1. Taking into account the nature,
scope, context, and purposes of processing,
as well as the risks of varying likelihood and severity for the rights and freedoms
of natural persons, the controller shall implement appropriate
technical and organizational measures to ensure and be able to
demonstrate that processing is performed in accordance with this
Regulation. Those measures shall be reviewed and updated where
necessary. 2. Where proportionate to the processing activities,
the measures referred to in paragraph 1 shall include the implementation of appropriate
data protection policies by the controller. 3.
Adherence to codes of conduct referred to in Article 40 or to a certification mechanism
Corte di Cassazione - unofficial copy
25
referred to in Article 42 may be used as an element to
demonstrate compliance with the controller's obligations.
Specifically, the Guarantor, in its challenged ruling, deemed it
to identify a specific violation of the above-mentioned provisions, noting
that, during the investigation conducted, INPS had not adequately
documented, from various perspectives, the circumstances surrounding the measures taken
and the related reasons.
For his part, the trial judge, in addition to ruling out the existence of the violation in question in light of the non-existence of the other violations, cited in his
reasoning , deeming it relevant, the communication sent by INPS
to the authority. In this communication, in addition to indicating the data protection officer, identified as the Central Anti-Fraud Directorate,
it was also specified that the press reports relating to the
incident had been disseminated through sources external to the institute, as the
media involved had themselves reported, and that the measures adopted
appeared entirely adequate, given that the processing did not
present any type of high risk, given that it consisted of
the cross-referencing of non-sensitive information, taken from an open
data system, with elements provided by the data subjects themselves, within the
specific purposes for which they had been collected.
Now, the reasoning in question cannot be considered merely
apparent.
In truth, the reasoning is only apparent, and the ruling is null and void because it is affected by error in procedendo, when, although graphically present, it does not make the basis of the decision perceptible, because it contains arguments that are objectively inappropriate to clarify the reasoning used by the judge to form his or her conviction. It is not possible to leave it to the interpreter to supplement it with the most varied hypothetical conjectures (see: Cass. No. 1986/2025).
Court of Cassation - unofficial copy
26
On the contrary, in the present case, the reasoning of the trial judge is clearly evident from an examination of the considerations set out in the reasoning, even if they are not shared by the appellant, who considers them eccentric with respect to the objections contained in the contested ruling.
In this case, the aforementioned lack of obligation on the counter-appellant institution to establish predefined data processing settings, different and additional to those commonly used in the performance of its normal institutional activity, the similar lack of the requirements for carrying out a preliminary impact assessment, and the type and origin of the data processed lead us to consider the reasoning of the trial judge to be legally correct, given that the institution had nothing concrete to prove other than the organization of its normal activity.
7. In light of the foregoing, the appeal must be dismissed.
Costs follow the unsuccessful party and must be awarded as per the order.
The procedural requirements exist, pursuant to art. 13, paragraph 1-quater, Presidential Decree no. 115/02, inserted by art. 1, paragraph 17, Law no. 228/12,
for the appellant to pay an additional amount as a
unified fee equal to that for the appeal, pursuant to paragraph 1-bis
of the same Article 13, if applicable.
P.Q.M.
The Court dismisses the appeal and orders the appellant to reimburse the
counter-appellant for the legal costs of the appeal, which it awards
at €200.00 for expenses and €12,000.00 for fees, plus 15% for
a lump sum reimbursement of general and incidental legal expenses, if and to the extent
due.
The procedural requirements are met, pursuant to Article 13, paragraph 1-
quater, of Presidential Decree No. 115/02, inserted by Article 1, paragraph 17, of Law No. 228/12,
Court of Cassation - unofficial copy
27
for the payment by the appellant of the additional amount as a
unified fee equal to that for the appeal, pursuant to paragraph 1-bis
of the same Article 13, if due.
Thus decided in Rome, in the chambers of the Second Civil Section
of the Court of Cassation, on January 22, 2026.
Councillor
Davide De Giorgio
President
Milena Falaschi
Court of Cassation - unofficial copy
- ↑ See also C-268/21, Norra Stockholm Bygg AB https://infocuria.curia.europa.eu/tabs/affair?lang=en&sort=AFF_NUM-DESC&searchTerm=%22C-268%2F21%22&publishedId=C-268%2F21




