Garante per la protezione dei dati personali (Italy) - 419/2026
| Garante per la protezione dei dati personali - 419/2026
Internal number (from the DPA): 10259701 | |
|---|---|
| Authority: | Garante per la protezione dei dati personali (Italy) |
| Jurisdiction: | Italy |
| Relevant Law: | Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(2) GDPR Article 12 GDPR Article 14 GDPR Article 25 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | |
| Decided: | 28.05.2026 |
| Published: | |
| Fine: | 55,000 EUR |
| Parties: | AgID |
| National Case Number/Name: | 419/2026
Internal number (from the DPA): 10259701 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Italian |
| Original Source: | GPDP (in IT) |
| Initial Contributor: | carloc |
The DPA fined the government agency for digitalization €55,000 for failing to inform data subjects about the inclusion of their certified email addresses in a public index of registered addresses.
English Summary
Facts
The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act.
The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law[1] and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address.
Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index.
Some data subjects complained[2] that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion.
Holding
The investigation
On the duty of information
First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index).
With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams[3].
The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index.
On the controller’s identity
The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index.
During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay.
The DPA's conclusion
The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000.
With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.
Comment
The DPA’s Opinion on the processing
Before the creation of INAD, the DPA had specifically provided the controller with an opinion[4] on the relative processing of personal data. In particular, the DPA’s guidance noted that the controller had not planned sufficient measures to inform the data subjects, which could practically undermine their option to opt out of the processing. In the decision, the controller noted that this guidance was entirely ignored.
No injunction in the decision
Notably, the decision does not contain an injunction to properly inform the data subjects. This implies that in the DPA’s eyes, the controller had remedied the violation with its broader 2025 information campaign.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.
[web doc. no. 10259701] Measure of May 28, 2026 Register of Measures No. 419 of May 28, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, General Data Protection Regulation (hereinafter, the Regulation); HAVING REGARD to Legislative Decree no. 196 of June 30, 2003 196 of 30 June 2003, containing the Personal Data Protection Code (hereinafter, the Code); CONSIDERING Regulation No. 1/2019 concerning internal procedures of external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Journal No. 106 of May 8, 2019 and on www.garanteprivacy.it, web doc. No. 9107633 (hereinafter "Regulation No. 1/2019"); CONSIDERING the documentation in the file; CONSIDERING the observations made by the Secretary General pursuant to Article 15 of Regulation No. 1/2000 on the organization and functioning of the Office of the Italian Data Protection Authority (web doc. No. 1098801); Speaker: Dr. Agostino Ghiglia; WHEREAS 1. Introduction Beginning June 6, 2023, any adult citizen with a certified email address has been allowed to elect their "digital domicile" in the National Index of Digital Addresses of Natural Persons, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register (hereinafter, INAD). From the same date, all certified email addresses of professionals listed in INI-PEC have also been automatically elected in INAD as digital domiciles of natural persons, without prejudice to the possibility for these professionals to change their address in INAD to one other than that listed in the National Index of Certified Email Addresses of Businesses and Professionals (hereinafter, INI-PEC). Subsequently, starting July 6, 2023, all domiciles thus elected were published on the INAD and made available for consultation (see the dedicated website at https://domiciliodigitale.gov.it/dgit/home/public/#!/home). As is known, the INAD was introduced by Legislative Decree No. 82 of March 7, 2005 (see specifically Articles 3-bis, 6-quater, and 6-quinquies; hereinafter, CAD) and regulated by specific Guidelines—adopted by the Agency for Digital Italy (hereinafter, AgID) with Directorial Resolution No. 529/2021 of September 15, 2021, and on which the Guarantor had expressed its opinion with Provision No. 288 of July 22, 2021 (available on the institutional website www.garanteprivacy.it, web doc. no. 9690742) – which also assumes the role of manager and, therefore, controller with respect to the processing of personal data carried out within its scope. Also following several appeals filed by professionals before the administrative court, with Directorial Decision no. 188 of August 8, 2023, the Agency adopted some amendments to the aforementioned Guidelines, specifically concerning the "limitation of the right to cease domicile for natural persons who are simultaneously registered in INI-PEC," as it created "unequal treatment between natural persons who are non-professionals and professionals not registered in registers or lists, on the one hand, and natural persons who are professionals registered in INI-PEC, on the other." Therefore, with a view to "reassessing the public interests involved, and in particular the right to equal treatment, in light of the provisions of Article 3 of the CAD and the general principles of equality and reasonableness enshrined in the Constitution," AgID introduced amendments aimed at "allowing natural persons simultaneously registered with INI-PEC to voluntarily cease their domicile with INAD." 2. The Investigation Over time, starting from the moment INAD was made available to the public, the Authority identified certain critical issues, including following the receipt of complaints and reports, regarding the processing of personal data carried out in this context. Therefore, it initiated an investigation that required AgID to submit several requests for information pursuant to Article 157 of Legislative Decree No. 196 of June 30, 2003 (Personal Data Protection Code – hereinafter, the Code). The main issue that emerged – and one that the Authority immediately highlighted – concerns the fact that interested parties with certified email addresses already registered with INI-PEC were not informed of this additional processing at the time of transferring their email addresses to INAD (pursuant to Article 6-quater, paragraph 2, of the CAD). In this regard, the Agency stated, in particular, that: - "The information regarding the transfer of addresses from INI-PEC to INAD was provided to professionals registered with INI-PEC through a communication forwarded to the professional associations and bodies prior to the publication of the data on INAD for sharing with local associations and members" (note dated October 30, 2023). In this regard, it provided a copy of the communication sent on June 21, 2023, to 16 professional associations and bodies, announcing the launch of INAD and attaching "an informational flyer on INAD that you can share with your members and provincial associations" (note dated March 27, 2024); - "has initiated direct discussions with the Ministry of Business and Made in Italy, where the INI-PEC is established, with a view to jointly drafting and subsequently disseminating a detailed statement on the functioning of the INAD and its interaction with the INI-PEC, with particular attention to the automatic import of the digital addresses of professionals registered with the INI-PEC into the INAD, pursuant to Article 6-quater, paragraph 2 of the CAD. The statement will be distributed to all professional associations and colleges required to communicate the digital addresses of their members to the INI-PEC, in order to ensure widespread and full awareness among all parties involved" (note dated November 20, 2024); - the "draft statement jointly signed by the Innovation and Digital Transition Directorate of the undersigned Agency and by Division VI, Chamber of Commerce System, of the aforementioned Ministry" was still "under review by the Ministry" (note dated March 18, 2025); - "As agreed, with Prot. No. 156298 of July 29, the MIMIt forwarded the joint press release to the professional associations, councils, or colleges required by law to communicate the digital address of their members to INI-PEC, requesting that the notice be forwarded to the professional's digital address or by any other means suitable for wider and more widespread dissemination. This press release and the detailed information contained therein are being adequately publicized both on the INAD portal and on the institutional websites of this Agency and the MIMIt," attaching a copy of the aforementioned joint press release (note dated August 11, 2025). Another issue—also highlighted by this Authority in its note dated September 26, 2023—concerns the circumstance whereby, upon authentication for the service, UnionCamere is indicated as the Service Provider. In this regard, AgID stated, in particular, that: - "In compliance with the provisions of Article 6-quater, paragraph 1 of the CAD, the creation and management of the INAD are entrusted to the undersigned Agency, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. In compliance with this regulatory provision, AgID, pursuant to Articles 4, no. 8) and 28 of Regulation (EU) 2016/679, will rely solely on Infocamere S.c.p.A. for the management of the index. Unioncamere has no role in this regard" (note dated October 30, 2023); - "It is confirmed that UnionCamere does not play and has never played any role in the processing of personal data with reference to INAD, using AgID solely and directly through InfoCamere S.c.p.A. as the IT structure of the Chambers of Commerce, pursuant to art. 6-quater, paragraph 1 of Legislative Decree 82/2005 and subsequent amendments (hereinafter CAD). The indication of UnionCamere as the service provider when authenticating the user via SPID is due to a material error in which the Agency, through InfoCamere, accidentally made. Indeed, InfoCamere, as a company of the Italian Chambers of Commerce for digital innovation, has always worked with UnionCamere. In the different context outlined by the aforementioned CAD provision, in the implementation of the SPID gateway on the INAD portal, the erroneous indication of UnionCamere was left instead of AgID. While thanking this Authority for highlighting this anomaly, we inform you that the undersigned Agency immediately took action to ask InfoCamere S.c.p.A. to change the name to avoid confusion among users" (note dated March 27, 2024); - "Thanks to the notification from this Authority, the Agency has asked InfoCamere S.c.p.A. to change the SPID service provider's name on the INAD portal to avoid confusion among users. As communicated by InfoCamere S.c.p.A., this change will be finalized shortly and the Authority will be notified" (note dated November 20, 2024); - "Regarding the incorrect SPID service provider's name on the INAD portal https://domiciliodigitale.gov.it, we inform you that discussions are underway with InfoCamere S.c.p.A. regarding the name change, which will be confirmed shortly" (note dated March 18, 2025); - "Following discussions with InfoCamere S.c.p.A., we hereby inform you that, as of August 5, 2020, when authenticating access to the digital domicile registration service on INAD, the indication of the undersigned Agency as the service provider is correct" (note dated August 11, 2025). In relation to the investigations carried out, based on the information acquired and the facts emerging from the investigation, as well as subsequent assessments, the Office, with a note dated December 5, 2025, notified AgID of the initiation of the procedure for the adoption of corrective measures and sanctions pursuant to Article 58, paragraph 1, of the Italian Civil Code. 2 of the Regulation, having ascertained, in the matter at hand, the existence of violations of the relevant regulations regarding the protection of personal data. Specifically, it was found that AgID: a) in relation to the activities carried out as manager of INAD, and therefore as controller of the related personal data processing, failed, by default, to implement measures aimed at adequately and in advance informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant Guidelines—as well as with reference to the indication of the data controller provided to users when authenticating to the relevant service, in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default pursuant to Article 5, paragraphs 1, letters a) and b), and 2, and Article 5, paragraphs 1, letters b), and c), and Article 5, paragraphs 2, and c), and d), and Article 5, paragraphs 2, and d), and e), and Article 5, paragraph 2, of the Regulation. 25 of the Regulation, as well as the transparency obligations set forth in Articles 12, 13, and 14 of the same Regulation; b) in taking action, following the initiation of the investigation, to address the identified critical issues, it initiated initiatives that were belated and not promptly implemented, resulting in the continuation of the same critical issues over time, impacting an ever-growing number of interested parties over the years, in violation of the principle of accountability set forth in Article 5, paragraph 2, of the Regulation and the obligations set forth in Article 31 of the same Regulation. With the same note, the aforementioned Institute was notified of the violations committed (pursuant to Article 166, paragraph 5, of the Code), inviting it to submit written defenses or documents and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). On December 31, 2025, AgID submitted its written defenses, and a hearing was held on January 26, 2026, which concluded on December 4, 2026. 3. The applicable regulatory framework 3.1. The legislation on the protection of personal data Pursuant to Article 5, paragraph 1, letter b), of the Italian Legislative Decree no. 1.1(a) and (b) of the Regulation, personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (principle of lawfulness, fairness, and transparency) and "collected for specified, explicit, and legitimate purposes, and not further processed in a manner that is incompatible with those purposes" (principle of purpose limitation). In this regard, it is added that the data controller shall take appropriate measures to provide the data subject with all the information referred to in Articles. 13 and 14 relating to the processing and, if the data have not been obtained from the data subject, provides the data subject with all the information required by the regulations on the processing within the established timeframes. This obligation does not apply if providing the required information proves impossible or would involve a disproportionate effort, or obtaining or communicating it is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the data subject's legitimate interests (Articles 12, 13, and 14 of the Regulation). In addition, Article 25 of the Regulation requires the data controller to comply with the principles of privacy by design and privacy by default. Furthermore, pursuant to Article 5, paragraph 2, of the Regulation, the data controller "shall be responsible for and able to demonstrate compliance with paragraph 1" (principle of accountability), and that, in this context, pursuant to Article 24, paragraph 1, of the Regulation, the controller shall be responsible for ensuring compliance with paragraph 1 (principle of accountability). 1, "shall implement appropriate technical and organizational measures to ensure and demonstrate that processing is performed in accordance with this Regulation." Finally, it is recalled that, pursuant to Article 31 of the Regulation, the data controller "[shall] cooperate, upon request, with the supervisory authority in the performance of its tasks." 3.2. Legislation regarding INAD With reference to INAD, Article 3-bis of the CAD specifically provides that professionals required to be registered in professional registers and lists are required to have a digital domicile registered in the INI-PEC (paragraph 1). However, in any case, "anyone has the right to elect or modify their digital domicile to be included in the list referred to in Article 6-quater" (paragraph 1-bis, first sentence); these digital domiciles are elected according to the procedures established in the Guidelines adopted by AgID (paragraph 1-ter, first sentence). In turn, art. Article 6-quater of the CAD establishes that: "1. A public list of digital domiciles of natural persons, professionals, and other private law entities not required to be registered in the index referred to in Article 6-bis is established, indicating the domiciles elected pursuant to Article 3-bis, paragraph 1-bis. The creation and management of this Index are entrusted to AgID, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. Professionals not registered in professional registers, lists, or directories referred to in Article 6-bis retain the right to elect a professional digital domicile and a personal digital domicile within this Index other than the first. 2. For professionals registered in registers and directories, the digital domicile is the address included in the list referred to in Article 6-bis, without prejudice to the right to elect a different one pursuant to Article 3-bis, paragraph 1-bis. For the purposes of including the professional addresses in the aforementioned list, the Ministry of Economic Development shall make the relevant addresses already included in the list referred to in Article 6-bis available to AgID, through the IT services identified in the Guidelines […]. Finally, Article 6-quinquies, paragraph 1, of the CAD provides that "Online consultation of the lists referred to in Articles 6-bis, 6-ter, and 6-quater is permitted to anyone without authentication. The lists are created in open format." By Resolution of the Director General No. 529 of September 15, 2021, this Agency adopted the "Guidelines for the National Index of Digital Addresses of Individuals, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register," which, for the purposes of this document, provide that: - "The Ministry of Economic Development, using the INI-PEC Manager, makes the addresses and names of professionals listed in the INI-PEC available to the INAD Manager, through IT services whose technical specifications are defined during the INAD development phase. The inclusion of the electronic addresses in the INI-PEC in the INAD consists of the following steps: 1. Retrieval, through the aforementioned services, of the digital addresses and names of professionals listed in the INI-PEC, made available by the INI-PEC Manager to the INAD Manager; 2. Provisional inclusion in the INAD for 30 days, without publication, of the digital addresses and their names. In the case of professionals registered with multiple professional associations or colleges, the last digital address chronologically declared in the INI-PEC is entered in the INAD. The INAD Manager, possibly in agreement with the INI-PEC Manager, will provide professionals registered in the INI-PEC with the instructions needed to complete the INAD registration process, which is necessary to enable the management functions of their address, as set out in paragraph 2.3. The INAD Manager, using the same methods, will also provide information on the processing of personal data. If, within 30 days of the provisional entry referred to in point 2 above, the professional has not exercised his or her right to change the digital address transmitted by the INI-PEC, the INAD Manager will publish the information set out in point 2. If the professional has opted to change the digital address in order to elect a personal address in INAD different from the one present in the INI-PEC, the INAD Manager will proceed to cancel the digital address initially transmitted. by INI-PEC” (para. 3); - “the processing of personal data within INAD is carried out by the INAD Manager [(i.e., this Agency)], as the data controller, in fulfillment of the legal responsibilities identified in Articles 3-bis, 6, and 6-quater of the CAD, as well as in these Guidelines, which have the nature of a regulatory source with universal validity. […] The complete information on the processing of personal data pursuant to Articles 13-14 of the GDPR is disseminated through all channels available for the purpose of electing digital domicile” (para. 8). This specific measure was the subject of a condition in the aforementioned opinion of the Guarantor of 22 July 2021 (see paragraph 4.1 and condition a)), where it was noted that publishing the professional digital address of the professional in the INAD before the data subject can even exercise the right to elect a different digital address for personal use, increases "the risks – already high in themselves, due to the legislative provision – for the fundamental rights and freedoms of the data subjects. In fact, the dissemination operation makes immediately available to anyone information attributed to the data subject by default (i.e. the certified email address for professional use), in the absence of a voluntary choice regarding the certified email address to be made available to third parties, with the consequence of automatically making it the potential point of receipt of communications of a personal nature, with all the risks described above (see paragraph 3.1 of this provision). Moreover, this is in the absence of due transparency towards the data subjects, given that it is not clear when the professionals will be informed of the automatic registration of the professional address with the INAD. INAD, and in any case at a later time (though it is not known how long) after the start of the processing (dissemination) within INAD itself. Therefore, given the current regulatory framework, and pending legislative action to bring Article 6-quater, paragraph 2, of the CAD into compliance with the Regulation, it is necessary to identify measures to mitigate the negative impact of this provision on the rights and freedoms of data subjects, as well as to adequately inform data subjects. For example, it could be provided that the digital address of the professional registered in the INI-PEC, once acquired by INAD, is not immediately published but is temporarily kept confidential, so as to allow the data subject, within a reasonable period of time from receiving the communication from the INAD Manager (for example, 30 days), to proceed with the election of a personal ad hoc digital address, so as to avoid the dissemination of data that does not correspond to that expressly and specifically desired by the data subject. Finally, as noted in the introduction, with a resolution dated August 8, 2023, the Agency amended the aforementioned Guidelines to "allow natural persons, simultaneously registered with INI-PEC, to voluntarily cease their domicile with INAD." 4. Outcome of the investigation From the investigation carried out, based on the information acquired and the facts that emerged during the investigation, as well as the assessments of this Department, it was established that the Agency, in the context under examination, committed the violations described below, failing to adopt the measure provided for in the Guidelines, at the direction of the Guarantor, in order to ensure compliance with the Regulation of the processing carried out within INAD (see the aforementioned paragraph 3 of the Guidelines). 4.1. Specifically, with specific reference to the processing of personal data relating to data subjects whose digital addresses were transferred from INI-PEC (professionals), AgID, as data controller, contrary to what is expressly provided in the aforementioned Guidelines, failed to provide them with the information necessary to ensure transparency of the processing under its jurisdiction. It did not inform them of the ongoing processing (the acquisition of personal data), the origin of the data, subsequent operations, and their impact on the data (the publication of the acquired data on a website accessible to anyone without authentication), and their rights (the ability to modify or delete the digital address from INAD within a certain period of time prior to its publication). As emerged from the reports and complaints received by the Authority, the lack of the required information resulted in the digital addresses acquired from INI-PEC being published on INAD before the data subjects could be informed and, consequently, exercise their right to choose a different digital address for personal use. This, moreover, as feared by the Authority in the aforementioned opinion, has meant that professional digital addresses, initially collected and published on the INI-PEC for purposes exclusively related to professional use, have become, by default, subject to use, once published on the INAD, also for private and non-professional purposes. This increases the risks to the fundamental rights and freedoms of data subjects, given that the professional PEC mailbox (sometimes lacking immediate reference to the professional's name) could be accessed by the professional's office collaborators, thus making communications intended for the professional in his or her capacity as a private individual accessible to them. The information provision adopted and described in the notes dated October 30, 2023, and March 27, 2024 (i.e., the communication to professional associations and bodies sent on June 21, 2023) cannot, in fact, be considered sufficient—as demonstrated by the facts—to satisfy professionals' necessary transparency needs, given that, in light of the findings from the reports and complaints received: - not all 31 professional categories listed in the INI-PEC (see the drop-down menu under "Professional category" on the webpage https://www.inipec.gov.it/cerca-pec) appeared in the list of entities to whom AgID sent the communication, a copy of which was provided in the reply; - certain professionals registered with associations belonging to national federations that received the aforementioned AgID communication did not receive any information regarding the automatic import of PEC addresses registered with INI-PEC into INAD; - The wording used in the aforementioned communication did not remind recipients of the need to launch an adequate information campaign targeting members of the relevant territorial associations, nor did it provide measures to ensure AgID that interested parties were duly informed. Only following the submissions made in the defense briefs—that is, after the preliminary investigation had been concluded and the procedure for adopting corrective and sanctioning measures had been initiated—AgID informed the Authority that it had "taken steps to prepare an adequate information campaign for interested parties, so as to further minimize, to the extent possible, the negative impacts that the wording of Article 6-quater, paragraph 2, of the CAD could reasonably have had" and that it had "drawn up a communications plan and subsequently organized and implemented various types of dissemination initiatives, with the aim of raising awareness of the issue." It provided a detailed (non-exhaustive) list of information initiatives, understood as "forms of dissemination accessible to the public, deemed suitable for reaching a broad audience of potential interested parties," implemented since INAD began operations. This was based on the "objective and reasonable impracticability of direct communication to each individual data subject given the very large number of individuals involved, which would have required a disproportionate effort pursuant to Article 14, paragraph 5, letter b) of the Regulation," following a "balance between administrative efficiency and the protection of data subjects' rights, with a proactive and collaborative approach with the Authority, favoring the form of a public message, also conveyed through media and social media; the Agency therefore deemed it disproportionate to send a single communication to all the professionals involved, amounting to approximately 2 million data subjects, also out of concern that such a communication could cause confusion (risk of classification as phishing or spam) among the data subjects themselves" (as supplemented during the hearing). That said, in its defense briefs, the Agency reiterated what it had initially stated in its note dated November 20, 2024 (and in any case, more than a year after the start of processing), according to which, "In order to further ensure greater and more widespread dissemination of the information in question, the Agency then took care - as already known - of drafting and sharing with the Ministry of Business and Made in Italy, which manages the INI-PEC, a jointly signed press release addressed directly to the professional associations and orders to which, at the explicit request of AgID, the MiMIT - having completed the approval process - forwarded the detailed text, requesting that it be distributed to all its members, by forwarding it to the professional's digital address or by any other suitable means. Furthermore, the press release was published by both AgID and MiMIT, with news on their websites and a direct link to the press release," adding, during the hearing, that, "after the joint press release, Agency-MIMIT meeting of August 2025, the Agency conducted checks with the national federations and professional associations, finding that: in most cases, the latter had informed their members by publishing news and circulars on their respective websites; in some cases, this information was passed on by them to their local councils, which also published similar information; with regard to this latter hypothesis, the Agency, in some specific cases, is still awaiting documentation proving that the local councils were notified. Finally, in the February 4, 2026, closing note of the hearing, the Agency provided "a summary document concerning the analysis conducted by the Agency, including through direct contact with the national associations of regulated professions, regarding the effective dissemination of the joint AgID-MIMIt press release." In this regard, it should be noted that the aforementioned measure, outlined in the note dated November 20, 2024, but implemented in July 2025, consisting of the drafting, jointly with the Ministry of Business and Made in Italy, of a specific notice to be published and sent to professional associations and registers for dissemination in all relevant publications, was adopted late. This resulted in the processing carried out by AgID from July 2023 until the measure became effective (i.e., no earlier than July 2025), being affected by the highlighted information gaps for all those professionals whose professional digital addresses were published on INAD and, consequently, used for the various purposes for which they were collected. Furthermore, the adoption of this measure, although belated, invalidates in re ipsa the hypothesized applicability of the exception under Article 14, paragraph 5, letter a). 14(b) of the Regulation, as it demonstrates that, given the alleged "disproportionate effort" in individually communicating the information referred to in Article 14 of the Regulation, it was possible to adopt more effective measures, including through collaboration with other institutional entities, than simply implementing information campaigns aimed at members in general. This also takes into account the role and functions that AgID performs within the institutional landscape regarding digitalization issues. AgID, in its defense pleadings and during the hearing, raised operational and organizational difficulties that arose during the period in which INAD was being made available and was starting processing (i.e., during 2023). These difficulties would have caused challenges in the performance of its duties, including in relation to the fulfillment of the obligations imposed on the data controller. This factor, while worthy of consideration for the purposes of assessing the conduct, does not, however, allow the main findings identified and notified by the Office to be overcome and lead to the case being closed. On the other hand, AgID, in its defense, invoked "the provisions of Article 14, paragraph 5, letter c) of Regulation (EU) 2016/679 (hereinafter "the Regulation"), since obtaining the personal data in question is expressly provided for by a regulatory provision (the aforementioned Article 6-quater, paragraph 2, of the CAD) and since appropriate measures have been established to protect the legitimate interests of data subjects both within the Guidelines governing INAD [...] and in the related data protection impact assessment, both of which were positively reviewed by this Department." "In the circumstances outlined above—where the collection of personal data is established by the Digital Administration Code and where, based on the secondary legislation provided for therein, appropriate measures have been effectively identified and implemented to protect the legitimate interests of data subjects, including in response to the observations and conditions formulated by this Department—the disclosure obligation under current EU legislation should legitimately be deemed excluded pursuant to Article 14, paragraph 5, letter c), of the Regulation." On this point, it is noted that, while the exemptions referred to in Article 14, paragraph 5, of the Regulation are alternative and not cumulative, either the exemption referred to in letter b) or the exemption referred to in letter c) applies. c), according to the AGID's request, the measure that AgID failed to implement constituted precisely that "appropriate measure to protect the legitimate interests of the data subject" referred to in letter c) of the aforementioned provision, which the Garante set as a condition in its opinion on the guidelines—which constitute "Union or Member State law to which the data controller is subject"—to ensure compliance with the Regulation of the processing carried out when transferring professionals' digital addresses from INI-PEC to INAD. This means that the failure to comply with the information obligations, established by the legal basis for the INAD manager, resulted in the professionals' professional digital address automatically becoming a personal one, in the absence of a communication adequately informing them of the transfer to INAD, to prevent the negative consequences arising from the use of that address, originally chosen for professional purposes, for notifications relating to the data subject's private sphere. The professional certified email inbox, often lacking immediate references to the professional's name, is typically accessed by the professional's office staff, who could thus also access personal communications addressed to the professional (as also emerged from complaints and reports examined by the Guarantor). 4.2. During the investigation, it was also established that the information provided to data subjects regarding the data controller's name when authenticating for access to INAD was inadequate. This is because, from June 2023 until August 5, 2025, the contact information provided, despite numerous reminders from the Authority, was that of UnionCamere (a party completely unrelated to the processing in question), rather than AgID (the service provider and data controller). With reference to the aforementioned issue, AgID, in its defense, argued that "The erroneous indication of the SPID service provider—limitable and detectable only at the time of authentication via SPID to access the reserved area on the INAD portal—while, absurdly, may have caused confusion in the interested party upon access, it is not believed that it could have reasonably led to the undue belief that the undersigned Agency was not the index manager and data controller. This reported belief is based on numerous, explicit, and recurring references to AgID's role, which, without a doubt, any interested party could not have failed to notice on the portal dedicated to the national index." "In light of the above context, it is believed that the criticality under analysis can be traced back to a mere material error," which "has never been found to have caused any interested party—to the best of our knowledge—to believe that the data controller of the data managed by INAD was not the undersigned Agency." Furthermore, "the Agency immediately took action with InfoCamere S.c.p.A., adopting a proactive approach and persistently and consistently working to effectively implement measures to ensure the application of the Regulation, including by involving the Department for Digital Transformation of the Presidency of the Council of Ministers to resolve the situation [...] and have InfoCamere S.c.p.A. remove the incorrect information, which is now effectively correct" (defense documents). In this regard, it is noted that, in the context in which the SPID authentication form appears, the data subject is nevertheless presented with a series of elements—such as those described by AgID—that allow them to deduce that the service provider, and therefore the controller of the related personal data processing, is the Agency itself. Therefore, overall, it can reasonably be stated that the data subject has received the information that allows them to correctly identify the aforementioned Agency as the controller of the personal data. Therefore, with respect to this aspect, it is believed that the violation of Article 13 of the Regulation can be dismissed. 4.3. More generally, during the investigation, critical issues emerged regarding AgID's ability to implement adequate technical and organizational measures to ensure, and demonstrate, compliance with the Regulation, as well as the cooperation offered with respect to the Authority's institutional supervisory activities. The initiatives adopted by the Agency with respect to the aforementioned issues were only definitively implemented in the summer of 2025, two years after the start of the processing and, consequently, two years after the first requests from the Authority, and responses to requests for information were sometimes delayed. On this point, in its defense briefs, AgID first claimed to have "promptly adopted a variety of measures to ensure adequate and comprehensive information to professionals registered with INI-PEC regarding the processing of their personal data within the different context of INAD. These initiatives, which resulted in numerous and repeated publications of news and press releases on institutional websites, as well as intense dissemination efforts through official social media channels, major press agencies, television news programs, and articles in national press outlets, highlight how the information dissemination efforts implemented by AgID must be considered not only timely but also adequate, excluding any instances of inertia or delay" (defense briefs). The Agency cited this timeliness in reference to the "request for correction that AgID made to InfoCamere S.c.p.A. immediately following the report received from that Department." However, it emphasized "an objective difficulty at the implementation level, when InfoCamere S.c.p.A. delayed correcting the typo, despite repeated requests." This situation also necessitated a discussion with government departments. In any case, AgID, during the hearing, also highlighted the difficulties it had experienced, related to specific, well-founded financial and organizational constraints, which "led to problems managing the response timelines to the Authority, with a significant delay recorded in only one related circumstance." Based on the above, it is certainly possible to confirm the relevance of these circumstances, which allow us to reconsider AgID's conduct during the investigation, ruling out the possibility that the Agency intentionally avoided collaborating with the Authority. Therefore, we believe that the violation of Article 31 of the Regulation can be dismissed. However, the conduct that emerged during the investigation highlighted AgID's inadequacy in effectively and promptly implementing the measures identified to protect data subjects. This must be assessed in light of the principle of accountability. This principle, in fact, requires adequacy both in ensuring compliance with the Regulation (by delaying the disclosure obligations to professionals) and in proving such compliance (only through the defense briefs, after more than two years of investigation, was it possible to gain knowledge of the initiatives implemented in terms of public communication). This confirms the violation of Article 5, paragraph 1, of the Regulation. 2 of the Regulation, also in light of the provisions of Article 24 of the same Regulation. 5. Conclusions In light of the above assessments, the statements made by the data controller in the defence pleadings and during the hearing, although worthy of consideration for the purposes of assessing the conduct, do not address the main concerns notified by the Office in the document initiating the proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Garante Regulation No. 1/2019, since none of the cases provided for in Article 11 referred to therein apply. In this context, confirming the findings notified by the Office in its memo dated December 5, 2025, we note that, in the matter under review, AgID, in relation to its activities as manager of INAD and therefore as controller of the related personal data processing, has failed, by default, to implement measures aimed at adequately and preventively informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant guidelines—in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default set forth in Article 5, paragraphs 1, letters a) and b), and 2, and Article 25 of the Regulation, as well as the transparency obligations set forth in Articles 12 and 14 of the same Regulation. For the reasons described in paragraphs 4.2 and 4.3 of this order, the violations referred to in Articles 13 and 31 of the Regulation are dismissed. In this context, given that measures were adopted during the proceedings to address the critical issues described above, the conditions for adopting the corrective measures referred to in Article 58, paragraph 2, of the Regulation are no longer met. This is without prejudice to the fact that effective methods of fulfilling the information obligations, in accordance with the INAD guidelines, must be adopted for future transfers of digital addresses from INI-PEC to INAD, which pose the same risks to the fundamental rights and freedoms of the data subjects. 6. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the Regulation; Art. 166, paragraph 7, of the Code). It is noted first of all that the Guarantor, pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose an administrative pecuniary sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel adopts the injunction order, by which it also orders, with regard to the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019). The aforementioned administrative pecuniary sanction, imposed based on the circumstances of each individual case, must be determined with due consideration of the factors set forth in Article 83, paragraph 2, of the Regulation. In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the provisions cited in paragraph 4 of this order is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. With specific regard to the nature, severity, and duration of the violations, whether they were intentional or negligent, and the categories of personal data affected (Article 83, paragraph 2, letters a), b), and g), of the Regulation), it should be noted that: - the violations affected the professional digital addresses of all professionals registered in the INI-PEC, which were then published on the INAD without the PEC inbox holders being fully aware of the processing operations performed and therefore without being able to manage their PEC inboxes pursuant to the provisions of the law; - adequate information measures were introduced only in the summer of 2025, two years after the start of the processing in question; - the obligation to adequately fulfill the information obligations towards data subjects was established, moreover, within the guidelines that AgID itself had adopted; - The Authority has received several complaints and reports in this regard, including negative consequences of the failure to provide information regarding the mechanism for transferring and publishing professional digital addresses to INAD, such as the receipt of notifications (sometimes with a significant impact on the rights and freedoms of data subjects) in certified email inboxes that are not suitable for receiving communications relating to the private sphere and are therefore not managed; - The violations are negligent, as AgID deemed it sufficient to fulfill its information obligations through various channels (such as communication campaigns). In light of these circumstances, it is considered that, in this case, the severity of the violations committed by the data controller is medium (Guidelines 04/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, point 60). In favor of the data controller, it should be noted that, pursuant to Article 83, paragraph 2, letter a), the data controller is entitled to a minimum level of seriousness. c), d), e), f), and k) of the Regulation, AgID—which has not committed any relevant previous violations—had nevertheless launched communication campaigns at the time the processing began, albeit not individualized but rather aimed at the general public, confident in their effectiveness. Furthermore, albeit belatedly, it implemented risk mitigation measures (such as the joint note with the Ministry of Business and Made in Italy, transmitted to the professional associations and intended to be disseminated to each professional), also involving other institutional actors, and taking into account financial and organizational difficulties encountered during the proceedings. In light of the above factors, assessed as a whole, with reference to the conduct consisting of the failure to comply with information obligations towards professionals (see paragraph 4.1 and paragraph 5, letter a), of this provision), it is deemed appropriate to determine the amount of the pecuniary sanction at €55,000 (fifty-five thousand) for the violation of art. 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Garante Regulation No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the violation of the information obligations affected all professionals whose digital addresses were published on the INI-PEC. Finally, it is noted that the conditions set forth in Article 17 of the Garante Regulation No. 1/2019 are met. NOW, THEREFORE, THE AUTHORITY a) declares the processing of personal data carried out by AgID – Agency for Digital Italy, as described in the grounds for its decision, to be unlawful for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; b) orders the application of the administrative pecuniary sanction, pursuant to Article 58, paragraph 2, letter i), and Article 83 of the Regulation, for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; ORDER AgID – Agency for Digital Italy, represented by its legal representative pro tempore, with registered office at Via Liszt 21, 00144 Rome (RM), Tax Code 97735020584, to pay the sum of €55,000 (fifty-five thousand) as an administrative fine for the violations indicated in the grounds (violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulations). It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS the aforementioned Agency, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €55,000 (fifty-five thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law 689/1981; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of the injunction order on the Italian Data Protection Authority's website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of this order on the Italian Data Protection Authority's website; c) pursuant to Article 17 of Regulation No. of the Guarantor No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Ghiglia THE SECRETARY GENERAL Montuori [web doc. No. 10259701] Measure of May 28, 2026 Register of Measures No. 419 of May 28, 2026 THE ITALIAN DATA PROTECTION AUTHORITY During today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr.Agostino Ghiglia, member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, the General Data Protection Regulation (hereinafter, the Regulation); HAVING REGARD to Legislative Decree No. 196 of 30 June 2003, establishing the Personal Data Protection Code (hereinafter, the Code); HAVING REGARD to Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No. 98 of 4/4/2019, published in the Official Journal No. 106 of 8/5/2019 and at www.garanteprivacy.it, web doc. no. 9107633 (hereinafter "Regulation of the Italian Data Protection Authority no. 1/2019"); Having seen the documentation in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of Regulation of the Italian Data Protection Authority no. 1/2000 on the organization and functioning of the Office of the Italian Data Protection Authority (web doc. no. 1098801); Rapporteur: Dr. Agostino Ghiglia; WHEREAS 1. Introduction Beginning June 6, 2023, any adult citizen with a certified email address has been allowed to elect their "digital domicile" in the National Index of Digital Addresses of Natural Persons, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or the Business Register (hereinafter, INAD). From the same date, all certified email addresses of professionals listed in INI-PEC have also been automatically elected in INAD as digital domiciles of natural persons, without prejudice to the possibility for these professionals to change their address in INAD to one other than the one listed in the National Index of Certified Email Addresses of Businesses and Professionals (hereinafter, INI-PEC). Subsequently, starting July 6, 2023, all domiciles thus elected were published on the INAD and made available for consultation (see the dedicated website at https://domiciliodigitale.gov.it/dgit/home/public/#!/home). As is known, the INAD was introduced by Legislative Decree No. 82 of March 7, 2005 (see specifically Articles 3-bis, 6-quater, and 6-quinquies; hereinafter, CAD) and regulated by specific Guidelines—adopted by the Agency for Digital Italy (hereinafter, AgID) with Directorial Resolution No. 529/2021 of September 15, 2021, and on which the Guarantor had expressed its opinion with Provision No. 288 of July 22, 2021 (available on the institutional website www.garanteprivacy.it, web doc. no. 9690742) – which also assumes the role of manager and, therefore, controller with respect to the processing of personal data carried out within its scope. Also following several appeals filed by professionals before the administrative court, with Directorial Decision no. 188 of August 8, 2023, the Agency adopted some amendments to the aforementioned Guidelines, specifically concerning the "limitation of the right to cease domicile for natural persons who are simultaneously registered in INI-PEC," as it created "unequal treatment between natural persons who are non-professionals and professionals not registered in registers or lists, on the one hand, and natural persons who are professionals registered in INI-PEC, on the other." Therefore, with a view to "reassessing the public interests involved, and in particular the right to equal treatment, in light of the provisions of Article 3 of the CAD and the general principles of equality and reasonableness enshrined in the Constitution," AgID introduced amendments aimed at "allowing natural persons simultaneously registered with INI-PEC to voluntarily cease their domicile with INAD." 2. The Investigation Over time, starting from the moment INAD was made available to the public, the Authority identified certain critical issues, including following the receipt of complaints and reports, regarding the processing of personal data carried out in this context. Therefore, it initiated an investigation that required AgID to submit several requests for information pursuant to Article 157 of Legislative Decree No. 196 of June 30, 2003 (Personal Data Protection Code – hereinafter, the Code). The main issue that emerged – and one that the Authority immediately highlighted – concerns the fact that interested parties with certified email addresses already registered with INI-PEC were not informed of this additional processing at the time of transferring their email addresses to INAD (pursuant to Article 6-quater, paragraph 2, of the CAD). In this regard, the Agency stated, in particular, that: - "The information regarding the transfer of addresses from INI-PEC to INAD was provided to professionals registered with INI-PEC through a communication forwarded to the professional associations and bodies prior to the publication of the data on INAD for sharing with local associations and members" (note dated October 30, 2023). In this regard, it provided a copy of the communication sent on June 21, 2023, to 16 professional associations and bodies, announcing the launch of INAD and attaching "an informational flyer on INAD that you can share with your members and provincial associations" (note dated March 27, 2024); - "has initiated direct discussions with the Ministry of Business and Made in Italy, where the INI-PEC is established, with a view to jointly drafting and subsequently disseminating a detailed statement on the functioning of the INAD and its interaction with the INI-PEC, with particular attention to the automatic import of the digital addresses of professionals registered with the INI-PEC into the INAD, pursuant to Article 6-quater, paragraph 2 of the CAD. The statement will be distributed to all professional associations and colleges required to communicate the digital addresses of their members to the INI-PEC, in order to ensure widespread and full awareness among all parties involved" (note dated November 20, 2024); - the "draft statement jointly signed by the Innovation and Digital Transition Directorate of the undersigned Agency and by Division VI, Chamber of Commerce System, of the aforementioned Ministry" was still "under review by the Ministry" (note dated March 18, 2025); - "As agreed, with Prot. No. 156298 of July 29, the MIMIt forwarded the joint press release to the professional associations, councils, or colleges required by law to communicate the digital address of their members to INI-PEC, requesting that the notice be forwarded to the professional's digital address or by any other means suitable for wider and more widespread dissemination. This press release and the detailed information contained therein are being adequately publicized both on the INAD portal and on the institutional websites of this Agency and the MIMIt," attaching a copy of the aforementioned joint press release (note dated August 11, 2025). Another issue—also highlighted by this Authority in its note dated September 26, 2023—concerns the circumstance whereby, upon authentication for the service, UnionCamere is indicated as the Service Provider. In this regard, AgID stated, in particular, that: - "In compliance with the provisions of Article 6-quater, paragraph 1 of the CAD, the creation and management of the INAD are entrusted to the undersigned Agency, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. In compliance with this regulatory provision, AgID, pursuant to Articles 4, no. 8) and 28 of Regulation (EU) 2016/679, will rely solely on Infocamere S.c.p.A. to manage the index. Unioncamere has no role in this regard" (note dated October 30, 2023); - "It is confirmed that UnionCamere does not play and has never played any role in the processing of personal data with reference to INAD, using AgID solely and directly through InfoCamere S.c.p.A. as the IT structure of the Chambers of Commerce, pursuant to art. 6-quater, paragraph 1 of Legislative Decree 82/2005 and subsequent amendments (hereinafter CAD). The indication of UnionCamere as the service provider when authenticating the user via SPID is due to a material error in which the Agency, through InfoCamere, accidentally made. Indeed, InfoCamere, as a company of the Italian Chambers of Commerce for digital innovation, has always worked with UnionCamere. In the different context outlined by the aforementioned CAD provision, in the implementation of the SPID gateway on the INAD portal, the erroneous indication of UnionCamere was left instead of AgID. While thanking this Authority for highlighting this anomaly, we inform you that the undersigned Agency immediately took action to ask InfoCamere S.c.p.A. to change the name to avoid confusion among users" (note dated March 27, 2024); - "Thanks to the notification from this Authority, the Agency has asked InfoCamere S.c.p.A. to change the SPID service provider's name on the INAD portal to avoid confusion among users. As communicated by InfoCamere S.c.p.A., this change will be finalized shortly and the Authority will be notified" (note dated November 20, 2024); - "Regarding the incorrect SPID service provider's name on the INAD portal https://domiciliodigitale.gov.it, we inform you that discussions are underway with InfoCamere S.c.p.A. regarding the name change, which will be confirmed shortly" (note dated March 18, 2025); - "Following discussions with InfoCamere S.c.p.A., we hereby inform you that, as of August 5, 2020, when authenticating access to the digital domicile registration service on INAD, the indication of the undersigned Agency as the service provider is correct" (note dated August 11, 2025). In relation to the investigations carried out, based on the information acquired and the facts emerging from the investigation, as well as subsequent assessments, the Office, with a note dated December 5, 2025, notified AgID of the initiation of the procedure for the adoption of corrective measures and sanctions pursuant to Article 58, paragraph 1, of the Italian Civil Code. 2 of the Regulation, having ascertained, in the matter at hand, the existence of violations of the relevant regulations regarding the protection of personal data. Specifically, it was found that AgID: a) in relation to the activities carried out as manager of INAD, and therefore as controller of the related personal data processing, failed, by default, to implement measures aimed at adequately and in advance informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant Guidelines—as well as with reference to the indication of the data controller provided to users when authenticating to the relevant service, in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default pursuant to Article 5, paragraphs 1, letters a) and b), and 2, and Article 5, paragraphs 1, letters b), and c), and Article 5, paragraphs 2, and c), and d), and Article 5, paragraphs 2, and d), and e), and Article 5, paragraph 2, of the Regulation. 25 of the Regulation, as well as the transparency obligations set forth in Articles 12, 13, and 14 of the same Regulation; b) in taking action, following the initiation of the investigation, to address the identified critical issues, it initiated initiatives that were belated and not promptly implemented, resulting in the continuation of the same critical issues over time, impacting an ever-growing number of interested parties over the years, in violation of the principle of accountability set forth in Article 5, paragraph 2, of the Regulation and the obligations set forth in Article 31 of the same Regulation. With the same note, the aforementioned Institute was notified of the violations committed (pursuant to Article 166, paragraph 5, of the Code), inviting it to submit written defenses or documents and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). On December 31, 2025, AgID submitted its written defenses, and a hearing was held on January 26, 2026, which concluded on December 4, 2026. 3. The applicable regulatory framework 3.1. The legislation on the protection of personal data Pursuant to Article 5, paragraph 1, letter b), of the Italian Legislative Decree no. 1.1(a) and (b) of the Regulation, personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (principle of lawfulness, fairness, and transparency) and "collected for specified, explicit, and legitimate purposes, and not further processed in a manner that is incompatible with those purposes" (principle of purpose limitation). In this regard, it is added that the data controller shall take appropriate measures to provide the data subject with all the information referred to in Articles. 13 and 14 relating to the processing and, if the data have not been obtained from the data subject, provides the data subject with all the information required by the regulations on the processing within the established timeframes. This obligation does not apply if providing the required information proves impossible or would involve a disproportionate effort, or obtaining or communicating it is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the data subject's legitimate interests (Articles 12, 13, and 14 of the Regulation). In addition, Article 25 of the Regulation requires the data controller to comply with the principles of privacy by design and privacy by default. Furthermore, pursuant to Article 5, paragraph 2, of the Regulation, the data controller "shall be responsible for and able to demonstrate compliance with paragraph 1" (principle of accountability), and that, in this context, pursuant to Article 24, paragraph 1, of the Regulation, the controller shall be responsible for ensuring compliance with paragraph 1 (principle of accountability). 1, "shall implement appropriate technical and organizational measures to ensure and demonstrate that processing is performed in accordance with this Regulation." Finally, it is recalled that, pursuant to Article 31 of the Regulation, the data controller "[shall] cooperate, upon request, with the supervisory authority in the performance of its tasks." 3.2. Legislation regarding INAD With reference to INAD, Article 3-bis of the CAD specifically provides that professionals required to be registered in professional registers and lists are required to have a digital domicile registered in the INI-PEC (paragraph 1). However, in any case, "anyone has the right to elect or modify their digital domicile to be included in the list referred to in Article 6-quater" (paragraph 1-bis, first sentence); these digital domiciles are elected according to the procedures established in the Guidelines adopted by AgID (paragraph 1-ter, first sentence). In turn, art. Article 6-quater of the CAD establishes that: "1. A public list of digital domiciles of natural persons, professionals, and other private law entities not required to be registered in the index referred to in Article 6-bis is established, indicating the domiciles elected pursuant to Article 3-bis, paragraph 1-bis. The creation and management of this Index are entrusted to AgID, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. Professionals not registered in professional registers, lists, or directories referred to in Article 6-bis retain the right to elect a professional digital domicile and a personal digital domicile within this Index other than the first. 2. For professionals registered in registers and directories, the digital domicile is the address included in the list referred to in Article 6-bis, without prejudice to the right to elect a different one pursuant to Article 3-bis, paragraph 1-bis. For the purposes of including the professional addresses in the aforementioned list, the Ministry of Economic Development shall make the relevant addresses already included in the list referred to in Article 6-bis available to AgID, through the IT services identified in the Guidelines […]. Finally, Article 6-quinquies, paragraph 1, of the CAD provides that "Online consultation of the lists referred to in Articles 6-bis, 6-ter, and 6-quater is permitted to anyone without authentication. The lists are created in open format." By Resolution of the Director General No. 529 of September 15, 2021, this Agency adopted the "Guidelines for the National Index of Digital Addresses of Individuals, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register," which, for the purposes of this document, provide that: - "The Ministry of Economic Development, using the INI-PEC Manager, makes the addresses and names of professionals listed in the INI-PEC available to the INAD Manager, through IT services whose technical specifications are defined during the INAD development phase. The inclusion of the electronic addresses in the INI-PEC in the INAD consists of the following steps: 1. Retrieval, through the aforementioned services, of the digital addresses and names of professionals listed in the INI-PEC, made available by the INI-PEC Manager to the INAD Manager; 2. Provisional inclusion in the INAD for 30 days, without publication, of the digital addresses and their names. In the case of professionals registered with multiple professional associations or colleges, the last digital address chronologically declared in the INI-PEC is entered in the INAD. The INAD Manager, possibly in agreement with the INI-PEC Manager, will provide professionals registered in the INI-PEC with the instructions needed to complete the INAD registration process, which is necessary to enable the management functions of their address, as set out in paragraph 2.3. The INAD Manager, using the same methods, will also provide information on the processing of personal data. If, within 30 days of the provisional entry referred to in point 2 above, the professional has not exercised his or her right to change the digital address transmitted by the INI-PEC, the INAD Manager will publish the information set out in point 2. If the professional has opted to change the digital address in order to elect a personal address in INAD different from the one present in the INI-PEC, the INAD Manager will proceed to cancel the digital address initially transmitted. by INI-PEC” (para. 3); - “the processing of personal data within INAD is carried out by the INAD Manager [(i.e., this Agency)], as the data controller, in fulfillment of the legal responsibilities identified in Articles 3-bis, 6, and 6-quater of the CAD, as well as in these Guidelines, which have the nature of a regulatory source with universal validity. […] The complete information on the processing of personal data pursuant to Articles 13-14 of the GDPR is disseminated through all channels available for the purpose of electing digital domicile” (para. 8). This specific measure was the subject of a condition in the aforementioned opinion of the Guarantor of 22 July 2021 (see paragraph 4.1 and condition a)), where it was noted that publishing the professional digital address of the professional in the INAD before the data subject can even exercise the right to elect a different digital address for personal use, increases "the risks – already high in themselves, due to the legislative provision – for the fundamental rights and freedoms of the data subjects. In fact, the dissemination operation makes immediately available to anyone information attributed to the data subject by default (i.e. the certified email address for professional use), in the absence of a voluntary choice regarding the certified email address to be made available to third parties, with the consequence of automatically making it the potential point of receipt of communications of a personal nature, with all the risks described above (see paragraph 3.1 of this provision). Moreover, this is in the absence of due transparency towards the data subjects, given that it is not clear when the professionals will be informed of the automatic registration of the professional address with the INAD. INAD, and in any case at a later time (though it is not known how long) after the start of the processing (dissemination) within INAD itself. Therefore, given the current regulatory framework, and pending legislative action to bring Article 6-quater, paragraph 2, of the CAD into compliance with the Regulation, it is necessary to identify measures to mitigate the negative impact of this provision on the rights and freedoms of data subjects, as well as to adequately inform data subjects. For example, it could be provided that the digital address of the professional registered in the INI-PEC, once acquired by INAD, is not immediately published but is temporarily kept confidential, so as to allow the data subject, within a reasonable period of time from receiving the communication from the INAD Manager (for example, 30 days), to proceed with the election of a personal ad hoc digital address, so as to avoid the dissemination of data that does not correspond to that expressly and specifically desired by the data subject. Finally, as noted in the introduction, with a resolution dated August 8, 2023, the Agency amended the aforementioned Guidelines to "allow natural persons, simultaneously registered with INI-PEC, to voluntarily cease their domicile with INAD." 4. Outcome of the investigation From the investigation carried out, based on the information acquired and the facts that emerged during the investigation, as well as the assessments of this Department, it was established that the Agency, in the context under examination, committed the violations described below, failing to adopt the measure provided for in the Guidelines, at the direction of the Guarantor, in order to ensure compliance with the Regulation of the processing carried out within INAD (see the aforementioned paragraph 3 of the Guidelines). 4.1. Specifically, with specific reference to the processing of personal data relating to data subjects whose digital addresses were transferred from INI-PEC (professionals), AgID, as data controller, contrary to what is expressly provided in the aforementioned Guidelines, failed to provide them with the information necessary to ensure transparency of the processing under its jurisdiction. It did not inform them of the ongoing processing (the acquisition of personal data), the origin of the data, subsequent operations, and their impact on the data (the publication of the acquired data on a website accessible to anyone without authentication), and their rights (the ability to modify or delete the digital address from INAD within a certain period of time prior to its publication). As emerged from the reports and complaints received by the Authority, the lack of the required information resulted in the digital addresses acquired from INI-PEC being published on INAD before the data subjects could be informed and, consequently, exercise their right to choose a different digital address for personal use. This, moreover, as feared by the Authority in the aforementioned opinion, has meant that professional digital addresses, initially collected and published on the INI-PEC for purposes exclusively related to professional use, have become, by default, subject to use, once published on the INAD, also for private and non-professional purposes. This increases the risks to the fundamental rights and freedoms of data subjects, given that the professional PEC mailbox (sometimes lacking immediate reference to the professional's name) could be accessed by the professional's office collaborators, thus making communications intended for the professional in his or her capacity as a private individual accessible to them. The information provision adopted and described in the notes dated October 30, 2023, and March 27, 2024 (i.e., the communication to professional associations and bodies sent on June 21, 2023) cannot, in fact, be considered sufficient—as demonstrated by the facts—to satisfy professionals' necessary transparency needs, given that, in light of the findings from the reports and complaints received: - not all 31 professional categories listed in the INI-PEC (see the drop-down menu under "Professional category" on the webpage https://www.inipec.gov.it/cerca-pec) appeared in the list of entities to whom AgID sent the communication, a copy of which was provided in the reply; - certain professionals registered with associations belonging to national federations that received the aforementioned AgID communication did not receive any information regarding the automatic import of PEC addresses registered with INI-PEC into INAD; - The wording used in the aforementioned communication did not remind recipients of the need to launch an adequate information campaign targeting members of the relevant territorial associations, nor did it provide measures to ensure AgID that interested parties were duly informed. Only following the submissions made in the defense briefs—that is, after the preliminary investigation had been concluded and the procedure for adopting corrective and sanctioning measures had been initiated—AgID informed the Authority that it had "taken steps to prepare an adequate information campaign for interested parties, so as to further minimize, to the extent possible, the negative impacts that the wording of Article 6-quater, paragraph 2, of the CAD could reasonably have had" and that it had "drawn up a communications plan and subsequently organized and implemented various types of dissemination initiatives, with the aim of raising awareness of the issue." It provided a detailed (non-exhaustive) list of information initiatives, understood as "forms of dissemination accessible to the public, deemed suitable for reaching a broad audience of potential interested parties," implemented since INAD began operations. This was based on the "objective and reasonable impracticability of direct communication to each individual data subject given the very large number of individuals involved, which would have required a disproportionate effort pursuant to Article 14, paragraph 5, letter b) of the Regulation," following a "balance between administrative efficiency and the protection of data subjects' rights, with a proactive and collaborative approach with the Authority, favoring the form of a public message, also conveyed through media and social media; the Agency therefore deemed it disproportionate to send a single communication to all the professionals involved, amounting to approximately 2 million data subjects, also out of concern that such a communication could cause confusion (risk of classification as phishing or spam) among the data subjects themselves" (as supplemented during the hearing). That said, in its defense briefs, the Agency reiterated what it had initially stated in its note dated November 20, 2024 (and in any case, more than a year after the start of processing), according to which, "In order to further ensure greater and more widespread dissemination of the information in question, the Agency then took care - as already known - of drafting and sharing with the Ministry of Business and Made in Italy, which manages the INI-PEC, a jointly signed press release addressed directly to the professional associations and orders to which, at the explicit request of AgID, the MiMIT - having completed the approval process - forwarded the detailed text, requesting that it be distributed to all its members, by forwarding it to the professional's digital address or by any other suitable means. Furthermore, the press release was published by both AgID and MiMIT, with news on their websites and a direct link to the press release," adding, during the hearing, that, "after the joint press release, Agency-MIMIT meeting of August 2025, the Agency conducted checks with the national federations and professional associations, finding that: in most cases, the latter had informed their members by publishing news and circulars on their respective websites; in some cases, this information was passed on by them to their local councils, which also published similar information; with regard to this latter hypothesis, the Agency, in some specific cases, is still awaiting documentation proving that the local councils were notified. Finally, in the February 4, 2026, closing note of the hearing, the Agency provided "a summary document concerning the analysis conducted by the Agency, including through direct contact with the national associations of regulated professions, regarding the effective dissemination of the joint AgID-MIMIt press release." In this regard, it should be noted that the aforementioned measure, outlined in the note dated November 20, 2024, but implemented in July 2025, consisting of the drafting, jointly with the Ministry of Business and Made in Italy, of a specific notice to be published and sent to professional associations and registers for dissemination in all relevant publications, was adopted late. This resulted in the processing carried out by AgID from July 2023 until the measure became effective (i.e., no earlier than July 2025), being affected by the highlighted information gaps for all those professionals whose professional digital addresses were published on INAD and, consequently, used for the various purposes for which they were collected. Furthermore, the adoption of this measure, although belated, invalidates in re ipsa the hypothesized applicability of the exception under Article 14, paragraph 5, letter a). 14(b) of the Regulation, as it demonstrates that, given the alleged "disproportionate effort" in individually communicating the information referred to in Article 14 of the Regulation, it was possible to adopt more effective measures, including through collaboration with other institutional entities, than simply implementing information campaigns aimed at members in general. This also takes into account the role and functions that AgID performs within the institutional landscape regarding digitalization issues. AgID, in its defense pleadings and during the hearing, raised operational and organizational difficulties that arose during the period in which INAD was being made available and was starting processing (i.e., during 2023). These difficulties would have caused challenges in the performance of its duties, including in relation to the fulfillment of the obligations imposed on the data controller. This factor, while worthy of consideration for the purposes of assessing the conduct, does not, however, allow the main findings identified and notified by the Office to be overcome and lead to the case being closed. On the other hand, AgID, in its defense, invoked "the provisions of Article 14, paragraph 5, letter c) of Regulation (EU) 2016/679 (hereinafter "the Regulation"), since obtaining the personal data in question is expressly provided for by a regulatory provision (the aforementioned Article 6-quater, paragraph 2, of the CAD) and since appropriate measures have been established to protect the legitimate interests of data subjects both within the Guidelines governing INAD [...] and in the related data protection impact assessment, both of which were positively reviewed by this Department." "In the circumstances outlined above—where the collection of personal data is established by the Digital Administration Code and where, based on the secondary legislation provided for therein, appropriate measures have been effectively identified and implemented to protect the legitimate interests of data subjects, including in response to the observations and conditions formulated by this Department—the disclosure obligation under current EU legislation should legitimately be deemed excluded pursuant to Article 14, paragraph 5, letter c), of the Regulation." On this point, it is noted that, while the exemptions referred to in Article 14, paragraph 5, of the Regulation are alternative and not cumulative, either the exemption referred to in letter b) or the exemption referred to in letter c) applies. c), according to the AGID's request, the measure that AgID failed to implement constituted precisely that "appropriate measure to protect the legitimate interests of the data subject" referred to in letter c) of the aforementioned provision, which the Garante set as a condition in its opinion on the guidelines—which constitute "Union or Member State law to which the data controller is subject"—to ensure compliance with the Regulation of the processing carried out when transferring professionals' digital addresses from INI-PEC to INAD. This means that the failure to comply with the information obligations, established by the legal basis for the INAD manager, resulted in the professionals' professional digital address automatically becoming a personal one, in the absence of a communication adequately informing them of the transfer to INAD, to prevent the negative consequences arising from the use of that address, originally chosen for professional purposes, for notifications relating to the data subject's private sphere. The professional certified email inbox, often lacking immediate references to the professional's name, is typically accessed by the professional's office staff, who could thus also access personal communications addressed to the professional (as also emerged from complaints and reports examined by the Guarantor). 4.2. During the investigation, it was also established that the information provided to data subjects regarding the data controller's name when authenticating for access to INAD was inadequate. This is because, from June 2023 until August 5, 2025, the contact information provided, despite numerous reminders from the Authority, was that of UnionCamere (a party completely unrelated to the processing in question), rather than AgID (the service provider and data controller). With reference to the aforementioned issue, AgID, in its defense, argued that "The erroneous indication of the SPID service provider—limitable and detectable only at the time of authentication via SPID to access the reserved area on the INAD portal—while, absurdly, may have caused confusion in the interested party upon access, it is not believed that it could have reasonably led to the undue belief that the undersigned Agency was not the index manager and data controller. This reported belief is based on numerous, explicit, and recurring references to AgID's role, which, without a doubt, any interested party could not have failed to notice on the portal dedicated to the national index." "In light of the above context, it is believed that the criticality under analysis can be traced back to a mere material error," which "has never been found to have caused any interested party—to the best of our knowledge—to believe that the data controller of the data managed by INAD was not the undersigned Agency." Furthermore, "the Agency immediately took action with InfoCamere S.c.p.A., adopting a proactive approach and persistently and consistently working to effectively implement measures to ensure the application of the Regulation, including by involving the Department for Digital Transformation of the Presidency of the Council of Ministers to resolve the situation [...] and have InfoCamere S.c.p.A. remove the incorrect information, which is now effectively correct" (defense documents). In this regard, it is noted that, in the context in which the SPID authentication form appears, the data subject is nevertheless presented with a series of elements—such as those described by AgID—that allow them to deduce that the service provider, and therefore the controller of the related personal data processing, is the Agency itself. Therefore, overall, it can reasonably be stated that the data subject has received the information that allows them to correctly identify the aforementioned Agency as the controller of the personal data. Therefore, with respect to this aspect, it is believed that the violation of Article 13 of the Regulation can be dismissed. 4.3. More generally, during the investigation, critical issues emerged regarding AgID's ability to implement adequate technical and organizational measures to ensure, and demonstrate, compliance with the Regulation, as well as the cooperation offered with respect to the Authority's institutional supervisory activities. The initiatives adopted by the Agency with respect to the aforementioned issues were only definitively implemented in the summer of 2025, two years after the start of the processing and, consequently, two years after the first requests from the Authority, and responses to requests for information were sometimes delayed. On this point, in its defense briefs, AgID first claimed to have "promptly adopted a variety of measures to ensure adequate and comprehensive information to professionals registered with INI-PEC regarding the processing of their personal data within the different context of INAD. These initiatives, which resulted in numerous and repeated publications of news and press releases on institutional websites, as well as intense dissemination efforts through official social media channels, major press agencies, television news programs, and articles in national press outlets, highlight how the information dissemination efforts implemented by AgID must be considered not only timely but also adequate, excluding any instances of inertia or delay" (defense briefs). The Agency cited this timeliness in reference to the "request for correction that AgID made to InfoCamere S.c.p.A. immediately following the report received from that Department." However, it emphasized "an objective difficulty at the implementation level, when InfoCamere S.c.p.A. delayed correcting the typo, despite repeated requests." This situation also necessitated a discussion with government departments. In any case, AgID, during the hearing, also highlighted the difficulties it had experienced, related to specific, well-founded financial and organizational constraints, which "led to problems managing the response timelines to the Authority, with a significant delay recorded in only one related circumstance." Based on the above, it is certainly possible to confirm the relevance of these circumstances, which allow us to reconsider AgID's conduct during the investigation, ruling out the possibility that the Agency intentionally avoided collaborating with the Authority. Therefore, we believe that the violation of Article 31 of the Regulation can be dismissed. However, the conduct that emerged during the investigation highlighted AgID's inadequacy in effectively and promptly implementing the measures identified to protect data subjects. This must be assessed in light of the principle of accountability. This principle, in fact, requires adequacy both in ensuring compliance with the Regulation (by delaying the disclosure obligations to professionals) and in proving such compliance (only through the defense briefs, after more than two years of investigation, was it possible to gain knowledge of the initiatives implemented in terms of public communication). This confirms the violation of Article 5, paragraph 1, of the Regulation. 2 of the Regulation, also in light of the provisions of Article 24 of the same Regulation. 5. Conclusions In light of the above assessments, the statements made by the data controller in the defence pleadings and during the hearing, although worthy of consideration for the purposes of assessing the conduct, do not address the main concerns notified by the Office in the document initiating the proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Garante Regulation No. 1/2019, since none of the cases provided for in Article 11 referred to therein apply. In this context, confirming the findings notified by the Office in its memo dated December 5, 2025, we note that, in the matter under review, AgID, in relation to its activities as manager of INAD and therefore as controller of the related personal data processing, has failed, by default, to implement measures aimed at adequately and preventively informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant guidelines—in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default set forth in Article 5, paragraphs 1, letters a) and b), and 2, and Article 25 of the Regulation, as well as the transparency obligations set forth in Articles 12 and 14 of the same Regulation. For the reasons described in paragraphs 4.2 and 4.3 of this order, the violations referred to in Articles 13 and 31 of the Regulation are dismissed. In this context, given that measures were adopted during the proceedings to address the critical issues described above, the conditions for adopting the corrective measures referred to in Article 58, paragraph 2, of the Regulation are no longer met. This is without prejudice to the fact that effective methods of fulfilling the information obligations, in accordance with the INAD guidelines, must be adopted for future transfers of digital addresses from INI-PEC to INAD, which pose the same risks to the fundamental rights and freedoms of the data subjects. 6. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the Regulation; Art. 166, paragraph 7, of the Code). It is noted first of all that the Guarantor, pursuant to Articles 58, paragraph 2, letter i), and 83 of the Regulation, as well as Article 166 of the Code, has the power to "impose an administrative pecuniary sanction pursuant to Article 83, in addition to the [other] corrective measures referred to in this paragraph, or in place of such measures, depending on the circumstances of each individual case." Within this framework, "the [Garante] Panel adopts the injunction order, by which it also orders, with regard to the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No. 1/2019). The aforementioned administrative pecuniary sanction, imposed based on the circumstances of each individual case, must be determined with due consideration of the factors set forth in Article 83, paragraph 2, of the Regulation. In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the provisions cited in paragraph 4 of this order is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. With specific regard to the nature, severity, and duration of the violations, whether they were intentional or negligent, and the categories of personal data affected (Article 83, paragraph 2, letters a), b), and g), of the Regulation), it should be noted that: - the violations affected the professional digital addresses of all professionals registered in the INI-PEC, which were then published on the INAD without the PEC inbox holders being fully aware of the processing operations performed and therefore without being able to manage their PEC inboxes pursuant to the provisions of the law; - adequate information measures were introduced only in the summer of 2025, two years after the start of the processing in question; - the obligation to adequately fulfill the information obligations towards data subjects was established, moreover, within the guidelines that AgID itself had adopted; - The Authority has received several complaints and reports in this regard, including negative consequences of the failure to provide information regarding the mechanism for transferring and publishing professional digital addresses to INAD, such as the receipt of notifications (sometimes with a significant impact on the rights and freedoms of data subjects) in certified email inboxes that are not suitable for receiving communications relating to the private sphere and are therefore not managed; - The violations are negligent, as AgID deemed it sufficient to fulfill its information obligations through various channels (such as communication campaigns). In light of these circumstances, it is considered that, in this case, the severity of the violations committed by the data controller is medium (Guidelines 04/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, point 60). In favor of the data controller, it should be noted that, pursuant to Article 83, paragraph 2, letter a), the data controller is entitled to a minimum level of seriousness. c), d), e), f), and k) of the Regulation, AgID—which has not committed any relevant previous violations—had nevertheless launched communication campaigns at the time the processing began, albeit not individualized but rather aimed at the general public, confident in their effectiveness. Furthermore, albeit belatedly, it implemented risk mitigation measures (such as the joint note with the Ministry of Business and Made in Italy, transmitted to the professional associations and intended to be disseminated to each professional), also involving other institutional actors, and taking into account financial and organizational difficulties encountered during the proceedings. In light of the above factors, assessed as a whole, with reference to the conduct consisting of the failure to comply with information obligations towards professionals (see paragraph 4.1 and paragraph 5, letter a), of this provision), it is deemed appropriate to determine the amount of the pecuniary sanction at €55,000 (fifty-five thousand) for the violation of art. 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Garante Regulation No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the violation of the information obligations affected all professionals whose digital addresses were published on the INI-PEC. Finally, it is noted that the conditions set forth in Article 17 of the Garante Regulation No. 1/2019 are met. NOW, THEREFORE, THE AUTHORITY a) declares the processing of personal data carried out by AgID – Agency for Digital Italy, as described in the grounds for its decision, to be unlawful for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; b) orders the application of the administrative pecuniary sanction, pursuant to Article 58, paragraph 2, letter i), and Article 83 of the Regulation, for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; ORDER AgID – Agency for Digital Italy, represented by its legal representative pro tempore, with registered office at Via Liszt 21, 00144 Rome (RM), Tax Code 97735020584, to pay the sum of €55,000 (fifty-five thousand) as an administrative fine for the violations indicated in the grounds (violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulations). It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS the aforementioned Agency, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €55,000 (fifty-five thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law 689/1981; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of the injunction order on the Italian Data Protection Authority's website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of this order on the Italian Data Protection Authority's website; c) pursuant to Article 17 of Regulation No. of the Guarantor No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Ghiglia THE SECRETARY GENERAL Montuori
- ↑ See Articles 3-bis, 6-quater and 6-quinquies, d. lgs. 82/2005.
- ↑ It is not clear whether the DPA started the investigation ex officio or due to the complaints.
- ↑ The DPA seems to have accepted this argument, as the decision contains no rebuttal; also see the "Comments" section on the lack of an injunction to inform data subjects).
- ↑ Garante per la protezione dei dati personali, Parere all’AgID sullo schema di Linee guida dell’Indice nazionale dei domicili digitali delle persone fisiche, dei professionisti e degli altri enti di diritto privato non tenuti all’iscrizione in albi, elenchi o registri professionali o nel registro delle imprese, July 2021 (available here).




