Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) ·419/2026 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The data controller for the case is a government body called the Agency for Digital Italy (AgID)

AgID is tasked with driving the adoption of digital technologies in both government and the private sector.

How it connects

58 of 74 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 74 findings

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

[web doc. no. 10259701] Measure of May 28, 2026 Register of Measures No. 419 of May 28, 2026 THE ITALIAN DATA PROTECTION AUTHORITY IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, General Data Protection Regulation (hereinafter, the Regulation); HAVING REGARD to Legislative Decree no. 196 of June 30, 2003 196 of 30 June 2003, containing the Personal Data Protection Code (hereinafter, the Code); CONSIDERING Regulation No. 1/2019 concerning internal procedures of external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No.

§

98 of April 4, 2019, published in the Official Journal No. it, web doc. No. 9107633 (hereinafter "Regulation No. 1/2019"); CONSIDERING the documentation in the file; CONSIDERING the observations made by the Secretary General pursuant to Article 15 of Regulation No. 1/2000 on the organization and functioning of the Office of the Italian Data Protection Authority (web doc. No. 1098801); Speaker: Dr. Agostino Ghiglia; WHEREAS 1. Introduction Beginning June 6, 2023, any adult citizen with a certified email address has been allowed to elect their "digital domicile" in the National Index of Digital Addresses of Natural Persons, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register (hereinafter, INAD). From the same date, all certified email addresses of professionals listed in INI-PEC have also been automatically elected in INAD as digital domiciles of natural persons, without prejudice to the possibility for these professionals to change their address in INAD to one other than that listed in the National Index of Certified Email Addresses of Businesses and Professionals (hereinafter, INI-PEC).

§

/home). As is known, the INAD was introduced by Legislative Decree No. 82 of March 7, 2005 (see specifically Articles 3-bis, 6-quater, and 6-quinquies; hereinafter, CAD) and regulated by specific Guidelines—adopted by the Agency for Digital Italy (hereinafter, AgID) with Directorial Resolution No. 529/2021 of September 15, 2021, and on which the Guarantor had expressed its opinion with Provision No. it, web doc. no. 9690742) – which also assumes the role of manager and, therefore, controller with respect to the processing of personal data carried out within its scope. Also following several appeals filed by professionals before the administrative court, with Directorial Decision no. " 2. The Investigation Over time, starting from the moment INAD was made available to the public, the Authority identified certain critical issues, including following the receipt of complaints and reports, regarding the processing of personal data carried out in this context.

§

Therefore, it initiated an investigation that required AgID to submit several requests for information pursuant to Article 157 of Legislative Decree No. 196 of June 30, 2003 (Personal Data Protection Code – hereinafter, the Code). The main issue that emerged – and one that the Authority immediately highlighted – concerns the fact that interested parties with certified email addresses already registered with INI-PEC were not informed of this additional processing at the time of transferring their email addresses to INAD (pursuant to Article 6-quater, paragraph 2, of the CAD). In this regard, the Agency stated, in particular, that: - "The information regarding the transfer of addresses from INI-PEC to INAD was provided to professionals registered with INI-PEC through a communication forwarded to the professional associations and bodies prior to the publication of the data on INAD for sharing with local associations and members" (note dated October 30, 2023).

§

In this regard, it provided a copy of the communication sent on June 21, 2023, to 16 professional associations and bodies, announcing the launch of INAD and attaching "an informational flyer on INAD that you can share with your members and provincial associations" (note dated March 27, 2024); - "has initiated direct discussions with the Ministry of Business and Made in Italy, where the INI-PEC is established, with a view to jointly drafting and subsequently disseminating a detailed statement on the functioning of the INAD and its interaction with the INI-PEC, with particular attention to the automatic import of the digital addresses of professionals registered with the INI-PEC into the INAD, pursuant to Article 6-quater, paragraph 2 of the CAD. The statement will be distributed to all professional associations and colleges required to communicate the digital addresses of their members to the INI-PEC, in order to ensure widespread and full awareness among all parties involved" (note dated November 20, 2024); - the "draft statement jointly signed by the Innovation and Digital Transition Directorate of the undersigned Agency and by Division VI, Chamber of Commerce System, of the aforementioned Ministry" was still "under review by the Ministry" (note dated March 18, 2025); - "As agreed, with Prot.

§

No. 156298 of July 29, the MIMIt forwarded the joint press release to the professional associations, councils, or colleges required by law to communicate the digital address of their members to INI-PEC, requesting that the notice be forwarded to the professional's digital address or by any other means suitable for wider and more widespread dissemination. This press release and the detailed information contained therein are being adequately publicized both on the INAD portal and on the institutional websites of this Agency and the MIMIt," attaching a copy of the aforementioned joint press release (note dated August 11, 2025). Another issue—also highlighted by this Authority in its note dated September 26, 2023—concerns the circumstance whereby, upon authentication for the service, UnionCamere is indicated as the Service Provider. In this regard, AgID stated, in particular, that: - "In compliance with the provisions of Article 6-quater, paragraph 1 of the CAD, the creation and management of the INAD are entrusted to the undersigned Agency, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis.

§

In compliance with this regulatory provision, AgID, pursuant to Articles 4, no. A. for the management of the index. A. as the IT structure of the Chambers of Commerce, pursuant to art. 6-quater, paragraph 1 of Legislative Decree 82/2005 and subsequent amendments (hereinafter CAD). The indication of UnionCamere as the service provider when authenticating the user via SPID is due to a material error in which the Agency, through InfoCamere, accidentally made. Indeed, InfoCamere, as a company of the Italian Chambers of Commerce for digital innovation, has always worked with UnionCamere. In the different context outlined by the aforementioned CAD provision, in the implementation of the SPID gateway on the INAD portal, the erroneous indication of UnionCamere was left instead of AgID. A. A. to change the SPID service provider's name on the INAD portal to avoid confusion among users. A. , we hereby inform you that, as of August 5, 2020, when authenticating access to the digital domicile registration service on INAD, the indication of the undersigned Agency as the service provider is correct" (note dated August 11, 2025).

§

In relation to the investigations carried out, based on the information acquired and the facts emerging from the investigation, as well as subsequent assessments, the Office, with a note dated December 5, 2025, notified AgID of the initiation of the procedure for the adoption of corrective measures and sanctions pursuant to Article 58, paragraph 1, of the Italian Civil Code. 2 of the Regulation, having ascertained, in the matter at hand, the existence of violations of the relevant regulations regarding the protection of personal data. Specifically, it was found that AgID: a) in relation to the activities carried out as manager of INAD, and therefore as controller of the related personal data processing, failed, by default, to implement measures aimed at adequately and in advance informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant Guidelines—as well as with reference to the indication of the data controller provided to users when authenticating to the relevant service, in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default pursuant to Article 5, paragraphs 1, letters a) and b), and 2, and Article 5, paragraphs 1, letters b), and c), and Article 5, paragraphs 2, and c), and d), and Article 5, paragraphs 2, and d), and e), and Article 5, paragraph 2, of the Regulation.

§

25 of the Regulation, as well as the transparency obligations set forth in Articles 12, 13, and 14 of the same Regulation; b) in taking action, following the initiation of the investigation, to address the identified critical issues, it initiated initiatives that were belated and not promptly implemented, resulting in the continuation of the same critical issues over time, impacting an ever-growing number of interested parties over the years, in violation of the principle of accountability set forth in Article 5, paragraph 2, of the Regulation and the obligations set forth in Article 31 of the same Regulation. With the same note, the aforementioned Institute was notified of the violations committed (pursuant to Article 166, paragraph 5, of the Code), inviting it to submit written defenses or documents and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No.

§

689 of November 24, 1981). On December 31, 2025, AgID submitted its written defenses, and a hearing was held on January 26, 2026, which concluded on December 4, 2026. 3. 1. The legislation on the protection of personal data Pursuant to Article 5, paragraph 1, letter b), of the Italian Legislative Decree no. 1(a) and (b) of the Regulation, personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (principle of lawfulness, fairness, and transparency) and "collected for specified, explicit, and legitimate purposes, and not further processed in a manner that is incompatible with those purposes" (principle of purpose limitation). In this regard, it is added that the data controller shall take appropriate measures to provide the data subject with all the information referred to in Articles. 13 and 14 relating to the processing and, if the data have not been obtained from the data subject, provides the data subject with all the information required by the regulations on the processing within the established timeframes.

§

This obligation does not apply if providing the required information proves impossible or would involve a disproportionate effort, or obtaining or communicating it is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the data subject's legitimate interests (Articles 12, 13, and 14 of the Regulation). In addition, Article 25 of the Regulation requires the data controller to comply with the principles of privacy by design and privacy by default. Furthermore, pursuant to Article 5, paragraph 2, of the Regulation, the data controller "shall be responsible for and able to demonstrate compliance with paragraph 1" (principle of accountability), and that, in this context, pursuant to Article 24, paragraph 1, of the Regulation, the controller shall be responsible for ensuring compliance with paragraph 1 (principle of accountability).

§

2. Legislation regarding INAD With reference to INAD, Article 3-bis of the CAD specifically provides that professionals required to be registered in professional registers and lists are required to have a digital domicile registered in the INI-PEC (paragraph 1). However, in any case, "anyone has the right to elect or modify their digital domicile to be included in the list referred to in Article 6-quater" (paragraph 1-bis, first sentence); these digital domiciles are elected according to the procedures established in the Guidelines adopted by AgID (paragraph 1-ter, first sentence). In turn, art. Article 6-quater of the CAD establishes that: "1. A public list of digital domiciles of natural persons, professionals, and other private law entities not required to be registered in the index referred to in Article 6-bis is established, indicating the domiciles elected pursuant to Article 3-bis, paragraph 1-bis.

§

The creation and management of this Index are entrusted to AgID, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. Professionals not registered in professional registers, lists, or directories referred to in Article 6-bis retain the right to elect a professional digital domicile and a personal digital domicile within this Index other than the first. 2. For professionals registered in registers and directories, the digital domicile is the address included in the list referred to in Article 6-bis, without prejudice to the right to elect a different one pursuant to Article 3-bis, paragraph 1-bis. For the purposes of including the professional addresses in the aforementioned list, the Ministry of Economic Development shall make the relevant addresses already included in the list referred to in Article 6-bis available to AgID, through the IT services identified in the Guidelines […].

§

Finally, Article 6-quinquies, paragraph 1, of the CAD provides that "Online consultation of the lists referred to in Articles 6-bis, 6-ter, and 6-quater is permitted to anyone without authentication. " By Resolution of the Director General No. 529 of September 15, 2021, this Agency adopted the "Guidelines for the National Index of Digital Addresses of Individuals, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register," which, for the purposes of this document, provide that: - "The Ministry of Economic Development, using the INI-PEC Manager, makes the addresses and names of professionals listed in the INI-PEC available to the INAD Manager, through IT services whose technical specifications are defined during the INAD development phase. The inclusion of the electronic addresses in the INI-PEC in the INAD consists of the following steps: 1.

§

Retrieval, through the aforementioned services, of the digital addresses and names of professionals listed in the INI-PEC, made available by the INI-PEC Manager to the INAD Manager; 2. Provisional inclusion in the INAD for 30 days, without publication, of the digital addresses and their names. In the case of professionals registered with multiple professional associations or colleges, the last digital address chronologically declared in the INI-PEC is entered in the INAD. 3. The INAD Manager, using the same methods, will also provide information on the processing of personal data. If, within 30 days of the provisional entry referred to in point 2 above, the professional has not exercised his or her right to change the digital address transmitted by the INI-PEC, the INAD Manager will publish the information set out in point 2. If the professional has opted to change the digital address in order to elect a personal address in INAD different from the one present in the INI-PEC, the INAD Manager will proceed to cancel the digital address initially transmitted.

§

by INI-PEC” (para. , this Agency)], as the data controller, in fulfillment of the legal responsibilities identified in Articles 3-bis, 6, and 6-quater of the CAD, as well as in these Guidelines, which have the nature of a regulatory source with universal validity. […] The complete information on the processing of personal data pursuant to Articles 13-14 of the GDPR is disseminated through all channels available for the purpose of electing digital domicile” (para. 8). 1 and condition a)), where it was noted that publishing the professional digital address of the professional in the INAD before the data subject can even exercise the right to elect a different digital address for personal use, increases "the risks – already high in themselves, due to the legislative provision – for the fundamental rights and freedoms of the data subjects. e. 1 of this provision). Moreover, this is in the absence of due transparency towards the data subjects, given that it is not clear when the professionals will be informed of the automatic registration of the professional address with the INAD.

§

INAD, and in any case at a later time (though it is not known how long) after the start of the processing (dissemination) within INAD itself. Therefore, given the current regulatory framework, and pending legislative action to bring Article 6-quater, paragraph 2, of the CAD into compliance with the Regulation, it is necessary to identify measures to mitigate the negative impact of this provision on the rights and freedoms of data subjects, as well as to adequately inform data subjects. For example, it could be provided that the digital address of the professional registered in the INI-PEC, once acquired by INAD, is not immediately published but is temporarily kept confidential, so as to allow the data subject, within a reasonable period of time from receiving the communication from the INAD Manager (for example, 30 days), to proceed with the election of a personal ad hoc digital address, so as to avoid the dissemination of data that does not correspond to that expressly and specifically desired by the data subject.

§

" 4. Outcome of the investigation From the investigation carried out, based on the information acquired and the facts that emerged during the investigation, as well as the assessments of this Department, it was established that the Agency, in the context under examination, committed the violations described below, failing to adopt the measure provided for in the Guidelines, at the direction of the Guarantor, in order to ensure compliance with the Regulation of the processing carried out within INAD (see the aforementioned paragraph 3 of the Guidelines). 1. Specifically, with specific reference to the processing of personal data relating to data subjects whose digital addresses were transferred from INI-PEC (professionals), AgID, as data controller, contrary to what is expressly provided in the aforementioned Guidelines, failed to provide them with the information necessary to ensure transparency of the processing under its jurisdiction.

§

It did not inform them of the ongoing processing (the acquisition of personal data), the origin of the data, subsequent operations, and their impact on the data (the publication of the acquired data on a website accessible to anyone without authentication), and their rights (the ability to modify or delete the digital address from INAD within a certain period of time prior to its publication). As emerged from the reports and complaints received by the Authority, the lack of the required information resulted in the digital addresses acquired from INI-PEC being published on INAD before the data subjects could be informed and, consequently, exercise their right to choose a different digital address for personal use. This, moreover, as feared by the Authority in the aforementioned opinion, has meant that professional digital addresses, initially collected and published on the INI-PEC for purposes exclusively related to professional use, have become, by default, subject to use, once published on the INAD, also for private and non-professional purposes.

§

This increases the risks to the fundamental rights and freedoms of data subjects, given that the professional PEC mailbox (sometimes lacking immediate reference to the professional's name) could be accessed by the professional's office collaborators, thus making communications intended for the professional in his or her capacity as a private individual accessible to them. it/cerca-pec) appeared in the list of entities to whom AgID sent the communication, a copy of which was provided in the reply; - certain professionals registered with associations belonging to national federations that received the aforementioned AgID communication did not receive any information regarding the automatic import of PEC addresses registered with INI-PEC into INAD; - The wording used in the aforementioned communication did not remind recipients of the need to launch an adequate information campaign targeting members of the relevant territorial associations, nor did it provide measures to ensure AgID that interested parties were duly informed.

§

" It provided a detailed (non-exhaustive) list of information initiatives, understood as "forms of dissemination accessible to the public, deemed suitable for reaching a broad audience of potential interested parties," implemented since INAD began operations. This was based on the "objective and reasonable impracticability of direct communication to each individual data subject given the very large number of individuals involved, which would have required a disproportionate effort pursuant to Article 14, paragraph 5, letter b) of the Regulation," following a "balance between administrative efficiency and the protection of data subjects' rights, with a proactive and collaborative approach with the Authority, favoring the form of a public message, also conveyed through media and social media; the Agency therefore deemed it disproportionate to send a single communication to all the professionals involved, amounting to approximately 2 million data subjects, also out of concern that such a communication could cause confusion (risk of classification as phishing or spam) among the data subjects themselves" (as supplemented during the hearing).

§

That said, in its defense briefs, the Agency reiterated what it had initially stated in its note dated November 20, 2024 (and in any case, more than a year after the start of processing), according to which, "In order to further ensure greater and more widespread dissemination of the information in question, the Agency then took care - as already known - of drafting and sharing with the Ministry of Business and Made in Italy, which manages the INI-PEC, a jointly signed press release addressed directly to the professional associations and orders to which, at the explicit request of AgID, the MiMIT - having completed the approval process - forwarded the detailed text, requesting that it be distributed to all its members, by forwarding it to the professional's digital address or by any other suitable means. Furthermore, the press release was published by both AgID and MiMIT, with news on their websites and a direct link to the press release," adding, during the hearing, that, "after the joint press release, Agency-MIMIT meeting of August 2025, the Agency conducted checks with the national federations and professional associations, finding that: in most cases, the latter had informed their members by publishing news and circulars on their respective websites; in some cases, this information was passed on by them to their local councils, which also published similar information; with regard to this latter hypothesis, the Agency, in some specific cases, is still awaiting documentation proving that the local councils were notified.

§

" In this regard, it should be noted that the aforementioned measure, outlined in the note dated November 20, 2024, but implemented in July 2025, consisting of the drafting, jointly with the Ministry of Business and Made in Italy, of a specific notice to be published and sent to professional associations and registers for dissemination in all relevant publications, was adopted late. , no earlier than July 2025), being affected by the highlighted information gaps for all those professionals whose professional digital addresses were published on INAD and, consequently, used for the various purposes for which they were collected. Furthermore, the adoption of this measure, although belated, invalidates in re ipsa the hypothesized applicability of the exception under Article 14, paragraph 5, letter a). 14(b) of the Regulation, as it demonstrates that, given the alleged "disproportionate effort" in individually communicating the information referred to in Article 14 of the Regulation, it was possible to adopt more effective measures, including through collaboration with other institutional entities, than simply implementing information campaigns aimed at members in general.

§

This also takes into account the role and functions that AgID performs within the institutional landscape regarding digitalization issues. , during 2023). These difficulties would have caused challenges in the performance of its duties, including in relation to the fulfillment of the obligations imposed on the data controller. This factor, while worthy of consideration for the purposes of assessing the conduct, does not, however, allow the main findings identified and notified by the Office to be overcome and lead to the case being closed. " On this point, it is noted that, while the exemptions referred to in Article 14, paragraph 5, of the Regulation are alternative and not cumulative, either the exemption referred to in letter b) or the exemption referred to in letter c) applies. c), according to the AGID's request, the measure that AgID failed to implement constituted precisely that "appropriate measure to protect the legitimate interests of the data subject" referred to in letter c) of the aforementioned provision, which the Garante set as a condition in its opinion on the guidelines—which constitute "Union or Member State law to which the data controller is subject"—to ensure compliance with the Regulation of the processing carried out when transferring professionals' digital addresses from INI-PEC to INAD.

§

This means that the failure to comply with the information obligations, established by the legal basis for the INAD manager, resulted in the professionals' professional digital address automatically becoming a personal one, in the absence of a communication adequately informing them of the transfer to INAD, to prevent the negative consequences arising from the use of that address, originally chosen for professional purposes, for notifications relating to the data subject's private sphere. The professional certified email inbox, often lacking immediate references to the professional's name, is typically accessed by the professional's office staff, who could thus also access personal communications addressed to the professional (as also emerged from complaints and reports examined by the Guarantor). 2. During the investigation, it was also established that the information provided to data subjects regarding the data controller's name when authenticating for access to INAD was inadequate.

§

This is because, from June 2023 until August 5, 2025, the contact information provided, despite numerous reminders from the Authority, was that of UnionCamere (a party completely unrelated to the processing in question), rather than AgID (the service provider and data controller). With reference to the aforementioned issue, AgID, in its defense, argued that "The erroneous indication of the SPID service provider—limitable and detectable only at the time of authentication via SPID to access the reserved area on the INAD portal—while, absurdly, may have caused confusion in the interested party upon access, it is not believed that it could have reasonably led to the undue belief that the undersigned Agency was not the index manager and data controller. A. remove the incorrect information, which is now effectively correct" (defense documents). In this regard, it is noted that, in the context in which the SPID authentication form appears, the data subject is nevertheless presented with a series of elements—such as those described by AgID—that allow them to deduce that the service provider, and therefore the controller of the related personal data processing, is the Agency itself.

§

Therefore, overall, it can reasonably be stated that the data subject has received the information that allows them to correctly identify the aforementioned Agency as the controller of the personal data. Therefore, with respect to this aspect, it is believed that the violation of Article 13 of the Regulation can be dismissed. 3. More generally, during the investigation, critical issues emerged regarding AgID's ability to implement adequate technical and organizational measures to ensure, and demonstrate, compliance with the Regulation, as well as the cooperation offered with respect to the Authority's institutional supervisory activities. The initiatives adopted by the Agency with respect to the aforementioned issues were only definitively implemented in the summer of 2025, two years after the start of the processing and, consequently, two years after the first requests from the Authority, and responses to requests for information were sometimes delayed.

§

On this point, in its defense briefs, AgID first claimed to have "promptly adopted a variety of measures to ensure adequate and comprehensive information to professionals registered with INI-PEC regarding the processing of their personal data within the different context of INAD. These initiatives, which resulted in numerous and repeated publications of news and press releases on institutional websites, as well as intense dissemination efforts through official social media channels, major press agencies, television news programs, and articles in national press outlets, highlight how the information dissemination efforts implemented by AgID must be considered not only timely but also adequate, excluding any instances of inertia or delay" (defense briefs). A. A. " This situation also necessitated a discussion with government departments. " Based on the above, it is certainly possible to confirm the relevance of these circumstances, which allow us to reconsider AgID's conduct during the investigation, ruling out the possibility that the Agency intentionally avoided collaborating with the Authority.

§

Therefore, we believe that the violation of Article 31 of the Regulation can be dismissed. However, the conduct that emerged during the investigation highlighted AgID's inadequacy in effectively and promptly implementing the measures identified to protect data subjects. This must be assessed in light of the principle of accountability. This principle, in fact, requires adequacy both in ensuring compliance with the Regulation (by delaying the disclosure obligations to professionals) and in proving such compliance (only through the defense briefs, after more than two years of investigation, was it possible to gain knowledge of the initiatives implemented in terms of public communication). This confirms the violation of Article 5, paragraph 1, of the Regulation. 2 of the Regulation, also in light of the provisions of Article 24 of the same Regulation. 5. Conclusions In light of the above assessments, the statements made by the data controller in the defence pleadings and during the hearing, although worthy of consideration for the purposes of assessing the conduct, do not address the main concerns notified by the Office in the document initiating the proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Garante Regulation No.

§

1/2019, since none of the cases provided for in Article 11 referred to therein apply. In this context, confirming the findings notified by the Office in its memo dated December 5, 2025, we note that, in the matter under review, AgID, in relation to its activities as manager of INAD and therefore as controller of the related personal data processing, has failed, by default, to implement measures aimed at adequately and preventively informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant guidelines—in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default set forth in Article 5, paragraphs 1, letters a) and b), and 2, and Article 25 of the Regulation, as well as the transparency obligations set forth in Articles 12 and 14 of the same Regulation.

§

3 of this order, the violations referred to in Articles 13 and 31 of the Regulation are dismissed. In this context, given that measures were adopted during the proceedings to address the critical issues described above, the conditions for adopting the corrective measures referred to in Article 58, paragraph 2, of the Regulation are no longer met. This is without prejudice to the fact that effective methods of fulfilling the information obligations, in accordance with the INAD guidelines, must be adopted for future transfers of digital addresses from INI-PEC to INAD, which pose the same risks to the fundamental rights and freedoms of the data subjects. 6. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the Regulation; Art. 166, paragraph 7, of the Code). " Within this framework, "the [Garante] Panel adopts the injunction order, by which it also orders, with regard to the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No.

§

1/2019). The aforementioned administrative pecuniary sanction, imposed based on the circumstances of each individual case, must be determined with due consideration of the factors set forth in Article 83, paragraph 2, of the Regulation. In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the provisions cited in paragraph 4 of this order is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. With specific regard to the nature, severity, and duration of the violations, whether they were intentional or negligent, and the categories of personal data affected (Article 83, paragraph 2, letters a), b), and g), of the Regulation), it should be noted that: - the violations affected the professional digital addresses of all professionals registered in the INI-PEC, which were then published on the INAD without the PEC inbox holders being fully aware of the processing operations performed and therefore without being able to manage their PEC inboxes pursuant to the provisions of the law; - adequate information measures were introduced only in the summer of 2025, two years after the start of the processing in question; - the obligation to adequately fulfill the information obligations towards data subjects was established, moreover, within the guidelines that AgID itself had adopted; - The Authority has received several complaints and reports in this regard, including negative consequences of the failure to provide information regarding the mechanism for transferring and publishing professional digital addresses to INAD, such as the receipt of notifications (sometimes with a significant impact on the rights and freedoms of data subjects) in certified email inboxes that are not suitable for receiving communications relating to the private sphere and are therefore not managed; - The violations are negligent, as AgID deemed it sufficient to fulfill its information obligations through various channels (such as communication campaigns).

§

In light of these circumstances, it is considered that, in this case, the severity of the violations committed by the data controller is medium (Guidelines 04/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, point 60). In favor of the data controller, it should be noted that, pursuant to Article 83, paragraph 2, letter a), the data controller is entitled to a minimum level of seriousness. c), d), e), f), and k) of the Regulation, AgID—which has not committed any relevant previous violations—had nevertheless launched communication campaigns at the time the processing began, albeit not individualized but rather aimed at the general public, confident in their effectiveness. Furthermore, albeit belatedly, it implemented risk mitigation measures (such as the joint note with the Ministry of Business and Made in Italy, transmitted to the professional associations and intended to be disseminated to each professional), also involving other institutional actors, and taking into account financial and organizational difficulties encountered during the proceedings.

§

1 and paragraph 5, letter a), of this provision), it is deemed appropriate to determine the amount of the pecuniary sanction at €55,000 (fifty-five thousand) for the violation of art. 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Garante Regulation No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the violation of the information obligations affected all professionals whose digital addresses were published on the INI-PEC. Finally, it is noted that the conditions set forth in Article 17 of the Garante Regulation No.

§

1/2019 are met. NOW, THEREFORE, THE AUTHORITY a) declares the processing of personal data carried out by AgID – Agency for Digital Italy, as described in the grounds for its decision, to be unlawful for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; b) orders the application of the administrative pecuniary sanction, pursuant to Article 58, paragraph 2, letter i), and Article 83 of the Regulation, for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; ORDER AgID – Agency for Digital Italy, represented by its legal representative pro tempore, with registered office at Via Liszt 21, 00144 Rome (RM), Tax Code 97735020584, to pay the sum of €55,000 (fifty-five thousand) as an administrative fine for the violations indicated in the grounds (violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulations).

§

It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS the aforementioned Agency, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €55,000 (fifty-five thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law 689/1981; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of the injunction order on the Italian Data Protection Authority's website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of Regulation No.

§

1/2019 of the Italian Data Protection Authority, the publication of this order on the Italian Data Protection Authority's website; c) pursuant to Article 17 of Regulation No. of the Guarantor No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Ghiglia THE SECRETARY GENERAL Montuori [web doc.

§

No. 10259701] Measure of May 28, 2026 Register of Measures No. Agostino Ghiglia, member, and Dr. Luigi Montuori, Secretary General; HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, the General Data Protection Regulation (hereinafter, the Regulation); HAVING REGARD to Legislative Decree No. 196 of 30 June 2003, establishing the Personal Data Protection Code (hereinafter, the Code); HAVING REGARD to Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Italian Data Protection Authority, approved by Resolution No. 98 of 4/4/2019, published in the Official Journal No. it, web doc. no.

§

9107633 (hereinafter "Regulation of the Italian Data Protection Authority no. 1/2019"); Having seen the documentation in the file; Having seen the observations made by the Secretary General pursuant to Article 15 of Regulation of the Italian Data Protection Authority no. 1/2000 on the organization and functioning of the Office of the Italian Data Protection Authority (web doc. no. 1098801); Rapporteur: Dr. Agostino Ghiglia; WHEREAS 1. Introduction Beginning June 6, 2023, any adult citizen with a certified email address has been allowed to elect their "digital domicile" in the National Index of Digital Addresses of Natural Persons, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or the Business Register (hereinafter, INAD). From the same date, all certified email addresses of professionals listed in INI-PEC have also been automatically elected in INAD as digital domiciles of natural persons, without prejudice to the possibility for these professionals to change their address in INAD to one other than the one listed in the National Index of Certified Email Addresses of Businesses and Professionals (hereinafter, INI-PEC).

§

/home). As is known, the INAD was introduced by Legislative Decree No. 82 of March 7, 2005 (see specifically Articles 3-bis, 6-quater, and 6-quinquies; hereinafter, CAD) and regulated by specific Guidelines—adopted by the Agency for Digital Italy (hereinafter, AgID) with Directorial Resolution No. 529/2021 of September 15, 2021, and on which the Guarantor had expressed its opinion with Provision No. it, web doc. no. 9690742) – which also assumes the role of manager and, therefore, controller with respect to the processing of personal data carried out within its scope. Also following several appeals filed by professionals before the administrative court, with Directorial Decision no. " 2. The Investigation Over time, starting from the moment INAD was made available to the public, the Authority identified certain critical issues, including following the receipt of complaints and reports, regarding the processing of personal data carried out in this context.

§

Therefore, it initiated an investigation that required AgID to submit several requests for information pursuant to Article 157 of Legislative Decree No. 196 of June 30, 2003 (Personal Data Protection Code – hereinafter, the Code). The main issue that emerged – and one that the Authority immediately highlighted – concerns the fact that interested parties with certified email addresses already registered with INI-PEC were not informed of this additional processing at the time of transferring their email addresses to INAD (pursuant to Article 6-quater, paragraph 2, of the CAD). In this regard, the Agency stated, in particular, that: - "The information regarding the transfer of addresses from INI-PEC to INAD was provided to professionals registered with INI-PEC through a communication forwarded to the professional associations and bodies prior to the publication of the data on INAD for sharing with local associations and members" (note dated October 30, 2023).

§

In this regard, it provided a copy of the communication sent on June 21, 2023, to 16 professional associations and bodies, announcing the launch of INAD and attaching "an informational flyer on INAD that you can share with your members and provincial associations" (note dated March 27, 2024); - "has initiated direct discussions with the Ministry of Business and Made in Italy, where the INI-PEC is established, with a view to jointly drafting and subsequently disseminating a detailed statement on the functioning of the INAD and its interaction with the INI-PEC, with particular attention to the automatic import of the digital addresses of professionals registered with the INI-PEC into the INAD, pursuant to Article 6-quater, paragraph 2 of the CAD. The statement will be distributed to all professional associations and colleges required to communicate the digital addresses of their members to the INI-PEC, in order to ensure widespread and full awareness among all parties involved" (note dated November 20, 2024); - the "draft statement jointly signed by the Innovation and Digital Transition Directorate of the undersigned Agency and by Division VI, Chamber of Commerce System, of the aforementioned Ministry" was still "under review by the Ministry" (note dated March 18, 2025); - "As agreed, with Prot.

§

No. 156298 of July 29, the MIMIt forwarded the joint press release to the professional associations, councils, or colleges required by law to communicate the digital address of their members to INI-PEC, requesting that the notice be forwarded to the professional's digital address or by any other means suitable for wider and more widespread dissemination. This press release and the detailed information contained therein are being adequately publicized both on the INAD portal and on the institutional websites of this Agency and the MIMIt," attaching a copy of the aforementioned joint press release (note dated August 11, 2025). Another issue—also highlighted by this Authority in its note dated September 26, 2023—concerns the circumstance whereby, upon authentication for the service, UnionCamere is indicated as the Service Provider. In this regard, AgID stated, in particular, that: - "In compliance with the provisions of Article 6-quater, paragraph 1 of the CAD, the creation and management of the INAD are entrusted to the undersigned Agency, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis.

§

In compliance with this regulatory provision, AgID, pursuant to Articles 4, no. A. to manage the index. A. as the IT structure of the Chambers of Commerce, pursuant to art. 6-quater, paragraph 1 of Legislative Decree 82/2005 and subsequent amendments (hereinafter CAD). The indication of UnionCamere as the service provider when authenticating the user via SPID is due to a material error in which the Agency, through InfoCamere, accidentally made. Indeed, InfoCamere, as a company of the Italian Chambers of Commerce for digital innovation, has always worked with UnionCamere. In the different context outlined by the aforementioned CAD provision, in the implementation of the SPID gateway on the INAD portal, the erroneous indication of UnionCamere was left instead of AgID. A. A. to change the SPID service provider's name on the INAD portal to avoid confusion among users. A. , we hereby inform you that, as of August 5, 2020, when authenticating access to the digital domicile registration service on INAD, the indication of the undersigned Agency as the service provider is correct" (note dated August 11, 2025).

§

In relation to the investigations carried out, based on the information acquired and the facts emerging from the investigation, as well as subsequent assessments, the Office, with a note dated December 5, 2025, notified AgID of the initiation of the procedure for the adoption of corrective measures and sanctions pursuant to Article 58, paragraph 1, of the Italian Civil Code. 2 of the Regulation, having ascertained, in the matter at hand, the existence of violations of the relevant regulations regarding the protection of personal data. Specifically, it was found that AgID: a) in relation to the activities carried out as manager of INAD, and therefore as controller of the related personal data processing, failed, by default, to implement measures aimed at adequately and in advance informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant Guidelines—as well as with reference to the indication of the data controller provided to users when authenticating to the relevant service, in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default pursuant to Article 5, paragraphs 1, letters a) and b), and 2, and Article 5, paragraphs 1, letters b), and c), and Article 5, paragraphs 2, and c), and d), and Article 5, paragraphs 2, and d), and e), and Article 5, paragraph 2, of the Regulation.

§

25 of the Regulation, as well as the transparency obligations set forth in Articles 12, 13, and 14 of the same Regulation; b) in taking action, following the initiation of the investigation, to address the identified critical issues, it initiated initiatives that were belated and not promptly implemented, resulting in the continuation of the same critical issues over time, impacting an ever-growing number of interested parties over the years, in violation of the principle of accountability set forth in Article 5, paragraph 2, of the Regulation and the obligations set forth in Article 31 of the same Regulation. With the same note, the aforementioned Institute was notified of the violations committed (pursuant to Article 166, paragraph 5, of the Code), inviting it to submit written defenses or documents and, if necessary, to request a hearing by this Authority, within 30 days (Article 166, paragraphs 6 and 7, of the Code; as well as Article 18, paragraph 1, of Law No.

§

689 of November 24, 1981). On December 31, 2025, AgID submitted its written defenses, and a hearing was held on January 26, 2026, which concluded on December 4, 2026. 3. 1. The legislation on the protection of personal data Pursuant to Article 5, paragraph 1, letter b), of the Italian Legislative Decree no. 1(a) and (b) of the Regulation, personal data must be "processed lawfully, fairly, and in a transparent manner in relation to the data subject" (principle of lawfulness, fairness, and transparency) and "collected for specified, explicit, and legitimate purposes, and not further processed in a manner that is incompatible with those purposes" (principle of purpose limitation). In this regard, it is added that the data controller shall take appropriate measures to provide the data subject with all the information referred to in Articles. 13 and 14 relating to the processing and, if the data have not been obtained from the data subject, provides the data subject with all the information required by the regulations on the processing within the established timeframes.

§

This obligation does not apply if providing the required information proves impossible or would involve a disproportionate effort, or obtaining or communicating it is expressly provided for by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the data subject's legitimate interests (Articles 12, 13, and 14 of the Regulation). In addition, Article 25 of the Regulation requires the data controller to comply with the principles of privacy by design and privacy by default. Furthermore, pursuant to Article 5, paragraph 2, of the Regulation, the data controller "shall be responsible for and able to demonstrate compliance with paragraph 1" (principle of accountability), and that, in this context, pursuant to Article 24, paragraph 1, of the Regulation, the controller shall be responsible for ensuring compliance with paragraph 1 (principle of accountability).

§

2. Legislation regarding INAD With reference to INAD, Article 3-bis of the CAD specifically provides that professionals required to be registered in professional registers and lists are required to have a digital domicile registered in the INI-PEC (paragraph 1). However, in any case, "anyone has the right to elect or modify their digital domicile to be included in the list referred to in Article 6-quater" (paragraph 1-bis, first sentence); these digital domiciles are elected according to the procedures established in the Guidelines adopted by AgID (paragraph 1-ter, first sentence). In turn, art. Article 6-quater of the CAD establishes that: "1. A public list of digital domiciles of natural persons, professionals, and other private law entities not required to be registered in the index referred to in Article 6-bis is established, indicating the domiciles elected pursuant to Article 3-bis, paragraph 1-bis.

§

The creation and management of this Index are entrusted to AgID, which will do so using the IT facilities of the Chambers of Commerce already responsible for managing the list referred to in Article 6-bis. Professionals not registered in professional registers, lists, or directories referred to in Article 6-bis retain the right to elect a professional digital domicile and a personal digital domicile within this Index other than the first. 2. For professionals registered in registers and directories, the digital domicile is the address included in the list referred to in Article 6-bis, without prejudice to the right to elect a different one pursuant to Article 3-bis, paragraph 1-bis. For the purposes of including the professional addresses in the aforementioned list, the Ministry of Economic Development shall make the relevant addresses already included in the list referred to in Article 6-bis available to AgID, through the IT services identified in the Guidelines […].

§

Finally, Article 6-quinquies, paragraph 1, of the CAD provides that "Online consultation of the lists referred to in Articles 6-bis, 6-ter, and 6-quater is permitted to anyone without authentication. " By Resolution of the Director General No. 529 of September 15, 2021, this Agency adopted the "Guidelines for the National Index of Digital Addresses of Individuals, Professionals, and Other Private Law Entities Not Required to Be Registered in Professional Rolls, Lists, or Registers, or in the Business Register," which, for the purposes of this document, provide that: - "The Ministry of Economic Development, using the INI-PEC Manager, makes the addresses and names of professionals listed in the INI-PEC available to the INAD Manager, through IT services whose technical specifications are defined during the INAD development phase. The inclusion of the electronic addresses in the INI-PEC in the INAD consists of the following steps: 1.

§

Retrieval, through the aforementioned services, of the digital addresses and names of professionals listed in the INI-PEC, made available by the INI-PEC Manager to the INAD Manager; 2. Provisional inclusion in the INAD for 30 days, without publication, of the digital addresses and their names. In the case of professionals registered with multiple professional associations or colleges, the last digital address chronologically declared in the INI-PEC is entered in the INAD. 3. The INAD Manager, using the same methods, will also provide information on the processing of personal data. If, within 30 days of the provisional entry referred to in point 2 above, the professional has not exercised his or her right to change the digital address transmitted by the INI-PEC, the INAD Manager will publish the information set out in point 2. If the professional has opted to change the digital address in order to elect a personal address in INAD different from the one present in the INI-PEC, the INAD Manager will proceed to cancel the digital address initially transmitted.

§

by INI-PEC” (para. , this Agency)], as the data controller, in fulfillment of the legal responsibilities identified in Articles 3-bis, 6, and 6-quater of the CAD, as well as in these Guidelines, which have the nature of a regulatory source with universal validity. […] The complete information on the processing of personal data pursuant to Articles 13-14 of the GDPR is disseminated through all channels available for the purpose of electing digital domicile” (para. 8). 1 and condition a)), where it was noted that publishing the professional digital address of the professional in the INAD before the data subject can even exercise the right to elect a different digital address for personal use, increases "the risks – already high in themselves, due to the legislative provision – for the fundamental rights and freedoms of the data subjects. e. 1 of this provision). Moreover, this is in the absence of due transparency towards the data subjects, given that it is not clear when the professionals will be informed of the automatic registration of the professional address with the INAD.

§

INAD, and in any case at a later time (though it is not known how long) after the start of the processing (dissemination) within INAD itself. Therefore, given the current regulatory framework, and pending legislative action to bring Article 6-quater, paragraph 2, of the CAD into compliance with the Regulation, it is necessary to identify measures to mitigate the negative impact of this provision on the rights and freedoms of data subjects, as well as to adequately inform data subjects. For example, it could be provided that the digital address of the professional registered in the INI-PEC, once acquired by INAD, is not immediately published but is temporarily kept confidential, so as to allow the data subject, within a reasonable period of time from receiving the communication from the INAD Manager (for example, 30 days), to proceed with the election of a personal ad hoc digital address, so as to avoid the dissemination of data that does not correspond to that expressly and specifically desired by the data subject.

§

" 4. Outcome of the investigation From the investigation carried out, based on the information acquired and the facts that emerged during the investigation, as well as the assessments of this Department, it was established that the Agency, in the context under examination, committed the violations described below, failing to adopt the measure provided for in the Guidelines, at the direction of the Guarantor, in order to ensure compliance with the Regulation of the processing carried out within INAD (see the aforementioned paragraph 3 of the Guidelines). 1. Specifically, with specific reference to the processing of personal data relating to data subjects whose digital addresses were transferred from INI-PEC (professionals), AgID, as data controller, contrary to what is expressly provided in the aforementioned Guidelines, failed to provide them with the information necessary to ensure transparency of the processing under its jurisdiction.

§

It did not inform them of the ongoing processing (the acquisition of personal data), the origin of the data, subsequent operations, and their impact on the data (the publication of the acquired data on a website accessible to anyone without authentication), and their rights (the ability to modify or delete the digital address from INAD within a certain period of time prior to its publication). As emerged from the reports and complaints received by the Authority, the lack of the required information resulted in the digital addresses acquired from INI-PEC being published on INAD before the data subjects could be informed and, consequently, exercise their right to choose a different digital address for personal use. This, moreover, as feared by the Authority in the aforementioned opinion, has meant that professional digital addresses, initially collected and published on the INI-PEC for purposes exclusively related to professional use, have become, by default, subject to use, once published on the INAD, also for private and non-professional purposes.

§

This increases the risks to the fundamental rights and freedoms of data subjects, given that the professional PEC mailbox (sometimes lacking immediate reference to the professional's name) could be accessed by the professional's office collaborators, thus making communications intended for the professional in his or her capacity as a private individual accessible to them. it/cerca-pec) appeared in the list of entities to whom AgID sent the communication, a copy of which was provided in the reply; - certain professionals registered with associations belonging to national federations that received the aforementioned AgID communication did not receive any information regarding the automatic import of PEC addresses registered with INI-PEC into INAD; - The wording used in the aforementioned communication did not remind recipients of the need to launch an adequate information campaign targeting members of the relevant territorial associations, nor did it provide measures to ensure AgID that interested parties were duly informed.

§

" It provided a detailed (non-exhaustive) list of information initiatives, understood as "forms of dissemination accessible to the public, deemed suitable for reaching a broad audience of potential interested parties," implemented since INAD began operations. This was based on the "objective and reasonable impracticability of direct communication to each individual data subject given the very large number of individuals involved, which would have required a disproportionate effort pursuant to Article 14, paragraph 5, letter b) of the Regulation," following a "balance between administrative efficiency and the protection of data subjects' rights, with a proactive and collaborative approach with the Authority, favoring the form of a public message, also conveyed through media and social media; the Agency therefore deemed it disproportionate to send a single communication to all the professionals involved, amounting to approximately 2 million data subjects, also out of concern that such a communication could cause confusion (risk of classification as phishing or spam) among the data subjects themselves" (as supplemented during the hearing).

§

That said, in its defense briefs, the Agency reiterated what it had initially stated in its note dated November 20, 2024 (and in any case, more than a year after the start of processing), according to which, "In order to further ensure greater and more widespread dissemination of the information in question, the Agency then took care - as already known - of drafting and sharing with the Ministry of Business and Made in Italy, which manages the INI-PEC, a jointly signed press release addressed directly to the professional associations and orders to which, at the explicit request of AgID, the MiMIT - having completed the approval process - forwarded the detailed text, requesting that it be distributed to all its members, by forwarding it to the professional's digital address or by any other suitable means. Furthermore, the press release was published by both AgID and MiMIT, with news on their websites and a direct link to the press release," adding, during the hearing, that, "after the joint press release, Agency-MIMIT meeting of August 2025, the Agency conducted checks with the national federations and professional associations, finding that: in most cases, the latter had informed their members by publishing news and circulars on their respective websites; in some cases, this information was passed on by them to their local councils, which also published similar information; with regard to this latter hypothesis, the Agency, in some specific cases, is still awaiting documentation proving that the local councils were notified.

§

" In this regard, it should be noted that the aforementioned measure, outlined in the note dated November 20, 2024, but implemented in July 2025, consisting of the drafting, jointly with the Ministry of Business and Made in Italy, of a specific notice to be published and sent to professional associations and registers for dissemination in all relevant publications, was adopted late. , no earlier than July 2025), being affected by the highlighted information gaps for all those professionals whose professional digital addresses were published on INAD and, consequently, used for the various purposes for which they were collected. Furthermore, the adoption of this measure, although belated, invalidates in re ipsa the hypothesized applicability of the exception under Article 14, paragraph 5, letter a). 14(b) of the Regulation, as it demonstrates that, given the alleged "disproportionate effort" in individually communicating the information referred to in Article 14 of the Regulation, it was possible to adopt more effective measures, including through collaboration with other institutional entities, than simply implementing information campaigns aimed at members in general.

§

This also takes into account the role and functions that AgID performs within the institutional landscape regarding digitalization issues. , during 2023). These difficulties would have caused challenges in the performance of its duties, including in relation to the fulfillment of the obligations imposed on the data controller. This factor, while worthy of consideration for the purposes of assessing the conduct, does not, however, allow the main findings identified and notified by the Office to be overcome and lead to the case being closed. " On this point, it is noted that, while the exemptions referred to in Article 14, paragraph 5, of the Regulation are alternative and not cumulative, either the exemption referred to in letter b) or the exemption referred to in letter c) applies. c), according to the AGID's request, the measure that AgID failed to implement constituted precisely that "appropriate measure to protect the legitimate interests of the data subject" referred to in letter c) of the aforementioned provision, which the Garante set as a condition in its opinion on the guidelines—which constitute "Union or Member State law to which the data controller is subject"—to ensure compliance with the Regulation of the processing carried out when transferring professionals' digital addresses from INI-PEC to INAD.

§

This means that the failure to comply with the information obligations, established by the legal basis for the INAD manager, resulted in the professionals' professional digital address automatically becoming a personal one, in the absence of a communication adequately informing them of the transfer to INAD, to prevent the negative consequences arising from the use of that address, originally chosen for professional purposes, for notifications relating to the data subject's private sphere. The professional certified email inbox, often lacking immediate references to the professional's name, is typically accessed by the professional's office staff, who could thus also access personal communications addressed to the professional (as also emerged from complaints and reports examined by the Guarantor). 2. During the investigation, it was also established that the information provided to data subjects regarding the data controller's name when authenticating for access to INAD was inadequate.

§

This is because, from June 2023 until August 5, 2025, the contact information provided, despite numerous reminders from the Authority, was that of UnionCamere (a party completely unrelated to the processing in question), rather than AgID (the service provider and data controller). With reference to the aforementioned issue, AgID, in its defense, argued that "The erroneous indication of the SPID service provider—limitable and detectable only at the time of authentication via SPID to access the reserved area on the INAD portal—while, absurdly, may have caused confusion in the interested party upon access, it is not believed that it could have reasonably led to the undue belief that the undersigned Agency was not the index manager and data controller. A. remove the incorrect information, which is now effectively correct" (defense documents). In this regard, it is noted that, in the context in which the SPID authentication form appears, the data subject is nevertheless presented with a series of elements—such as those described by AgID—that allow them to deduce that the service provider, and therefore the controller of the related personal data processing, is the Agency itself.

§

Therefore, overall, it can reasonably be stated that the data subject has received the information that allows them to correctly identify the aforementioned Agency as the controller of the personal data. Therefore, with respect to this aspect, it is believed that the violation of Article 13 of the Regulation can be dismissed. 3. More generally, during the investigation, critical issues emerged regarding AgID's ability to implement adequate technical and organizational measures to ensure, and demonstrate, compliance with the Regulation, as well as the cooperation offered with respect to the Authority's institutional supervisory activities. The initiatives adopted by the Agency with respect to the aforementioned issues were only definitively implemented in the summer of 2025, two years after the start of the processing and, consequently, two years after the first requests from the Authority, and responses to requests for information were sometimes delayed.

§

On this point, in its defense briefs, AgID first claimed to have "promptly adopted a variety of measures to ensure adequate and comprehensive information to professionals registered with INI-PEC regarding the processing of their personal data within the different context of INAD. These initiatives, which resulted in numerous and repeated publications of news and press releases on institutional websites, as well as intense dissemination efforts through official social media channels, major press agencies, television news programs, and articles in national press outlets, highlight how the information dissemination efforts implemented by AgID must be considered not only timely but also adequate, excluding any instances of inertia or delay" (defense briefs). A. A. " This situation also necessitated a discussion with government departments. " Based on the above, it is certainly possible to confirm the relevance of these circumstances, which allow us to reconsider AgID's conduct during the investigation, ruling out the possibility that the Agency intentionally avoided collaborating with the Authority.

§

Therefore, we believe that the violation of Article 31 of the Regulation can be dismissed. However, the conduct that emerged during the investigation highlighted AgID's inadequacy in effectively and promptly implementing the measures identified to protect data subjects. This must be assessed in light of the principle of accountability. This principle, in fact, requires adequacy both in ensuring compliance with the Regulation (by delaying the disclosure obligations to professionals) and in proving such compliance (only through the defense briefs, after more than two years of investigation, was it possible to gain knowledge of the initiatives implemented in terms of public communication). This confirms the violation of Article 5, paragraph 1, of the Regulation. 2 of the Regulation, also in light of the provisions of Article 24 of the same Regulation. 5. Conclusions In light of the above assessments, the statements made by the data controller in the defence pleadings and during the hearing, although worthy of consideration for the purposes of assessing the conduct, do not address the main concerns notified by the Office in the document initiating the proceedings for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation and are insufficient to permit the dismissal of this proceeding pursuant to Article 14, paragraph 1, of the Garante Regulation No.

§

1/2019, since none of the cases provided for in Article 11 referred to therein apply. In this context, confirming the findings notified by the Office in its memo dated December 5, 2025, we note that, in the matter under review, AgID, in relation to its activities as manager of INAD and therefore as controller of the related personal data processing, has failed, by default, to implement measures aimed at adequately and preventively informing data subjects, with particular reference to the digital addresses acquired by INI-PEC and published on INAD—which were disseminated for a purpose other than that for which they were originally collected, without complying with the guarantees set forth in the relevant guidelines—in violation of the principles of lawfulness, fairness, and transparency, purpose limitation, accountability, and privacy by design and by default set forth in Article 5, paragraphs 1, letters a) and b), and 2, and Article 25 of the Regulation, as well as the transparency obligations set forth in Articles 12 and 14 of the same Regulation.

§

3 of this order, the violations referred to in Articles 13 and 31 of the Regulation are dismissed. In this context, given that measures were adopted during the proceedings to address the critical issues described above, the conditions for adopting the corrective measures referred to in Article 58, paragraph 2, of the Regulation are no longer met. This is without prejudice to the fact that effective methods of fulfilling the information obligations, in accordance with the INAD guidelines, must be adopted for future transfers of digital addresses from INI-PEC to INAD, which pose the same risks to the fundamental rights and freedoms of the data subjects. 6. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the Regulation; Art. 166, paragraph 7, of the Code). " Within this framework, "the [Garante] Panel adopts the injunction order, by which it also orders, with regard to the application of the additional administrative sanction, its publication, in full or in extract, on the Guarantor's website pursuant to Article 166, paragraph 7, of the Code" (Article 16, paragraph 1, of the Guarantor Regulation No.

§

1/2019). The aforementioned administrative pecuniary sanction, imposed based on the circumstances of each individual case, must be determined with due consideration of the factors set forth in Article 83, paragraph 2, of the Regulation. In this regard, taking into account Article 83, paragraph 3, of the Regulation, in this case, violation of the provisions cited in paragraph 4 of this order is subject to the application of the administrative pecuniary sanction provided for in Article 83, paragraph 5, of the Regulation. With specific regard to the nature, severity, and duration of the violations, whether they were intentional or negligent, and the categories of personal data affected (Article 83, paragraph 2, letters a), b), and g), of the Regulation), it should be noted that: - the violations affected the professional digital addresses of all professionals registered in the INI-PEC, which were then published on the INAD without the PEC inbox holders being fully aware of the processing operations performed and therefore without being able to manage their PEC inboxes pursuant to the provisions of the law; - adequate information measures were introduced only in the summer of 2025, two years after the start of the processing in question; - the obligation to adequately fulfill the information obligations towards data subjects was established, moreover, within the guidelines that AgID itself had adopted; - The Authority has received several complaints and reports in this regard, including negative consequences of the failure to provide information regarding the mechanism for transferring and publishing professional digital addresses to INAD, such as the receipt of notifications (sometimes with a significant impact on the rights and freedoms of data subjects) in certified email inboxes that are not suitable for receiving communications relating to the private sphere and are therefore not managed; - The violations are negligent, as AgID deemed it sufficient to fulfill its information obligations through various channels (such as communication campaigns).

§

In light of these circumstances, it is considered that, in this case, the severity of the violations committed by the data controller is medium (Guidelines 04/2022 on the calculation of administrative fines under the GDPR, adopted by the Committee on May 23, 2023, point 60). In favor of the data controller, it should be noted that, pursuant to Article 83, paragraph 2, letter a), the data controller is entitled to a minimum level of seriousness. c), d), e), f), and k) of the Regulation, AgID—which has not committed any relevant previous violations—had nevertheless launched communication campaigns at the time the processing began, albeit not individualized but rather aimed at the general public, confident in their effectiveness. Furthermore, albeit belatedly, it implemented risk mitigation measures (such as the joint note with the Ministry of Business and Made in Italy, transmitted to the professional associations and intended to be disseminated to each professional), also involving other institutional actors, and taking into account financial and organizational difficulties encountered during the proceedings.

§

1 and paragraph 5, letter a), of this provision), it is deemed appropriate to determine the amount of the pecuniary sanction at €55,000 (fifty-five thousand) for the violation of art. 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation, as an administrative pecuniary sanction deemed, pursuant to Article 83, paragraph 1, of the Regulation, to be effective, proportionate, and dissuasive. In this context, it is also believed that, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Garante Regulation No. 1/2019, this chapter containing the injunction order should be published on the Garante's website. This is given that the violation of the information obligations affected all professionals whose digital addresses were published on the INI-PEC. Finally, it is noted that the conditions set forth in Article 17 of the Garante Regulation No.

§

1/2019 are met. NOW, THEREFORE, THE AUTHORITY a) declares the processing of personal data carried out by AgID – Agency for Digital Italy, as described in the grounds for its decision, to be unlawful for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; b) orders the application of the administrative pecuniary sanction, pursuant to Article 58, paragraph 2, letter i), and Article 83 of the Regulation, for violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulation; ORDER AgID – Agency for Digital Italy, represented by its legal representative pro tempore, with registered office at Via Liszt 21, 00144 Rome (RM), Tax Code 97735020584, to pay the sum of €55,000 (fifty-five thousand) as an administrative fine for the violations indicated in the grounds (violation of Article 5, paragraphs 1, letters a) and b), and 2, and Articles 12, 14, and 25 of the Regulations).

§

It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by paying, within 30 days, an amount equal to half the imposed fine; ORDERS the aforementioned Agency, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €55,000 (fifty-five thousand) according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law 689/1981; ORDERS a) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of Regulation No. 1/2019 of the Italian Data Protection Authority, the publication of the injunction order on the Italian Data Protection Authority's website; b) pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of Regulation No.

§

1/2019 of the Italian Data Protection Authority, the publication of this order on the Italian Data Protection Authority's website; c) pursuant to Article 17 of Regulation No. of the Guarantor No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2 of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this provision may be lodged before the ordinary judicial authority, under penalty of inadmissibility, within thirty days of the date of notification of the provision itself, or within sixty days if the appellant resides abroad. Rome, May 28, 2026 THE PRESIDENT Stanzione THE REPORTER Ghiglia THE SECRETARY GENERAL Montuori