Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Istituto Nazionale Previdenza Sociale (INPS): Non-compliance with general data processing principles

Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS).

€300,000 Fine
Istituto Nazionale Previdenza Sociale (INPS)
ITALY
Art. 5 GDPR Art. 25 GDPR Art. 35 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

Original fine summary: The Italian DPA (Garante) imposed a fine of EUR 300,000 on the Istituto Nazionale Previdenza Sociale (INPS). The Italian National Institute for Social Security had been tasked with anti-fraud investigations related to COVID-19 relief funds. After press reports raised problems with the institute's data processing practices around the application review of politicians, the Italian DPA opened an investigation against INPS in August 2020. During that investigation, the DPA identified several violations. The controller had collected data on tens of thousands of politicians from public sources and cross-checked it with data from applicants. In doing so, however, the controller had failed to ensure that data was collected only from those politicians who were eligible to receive the assistance funds. In doing so, the controller violated the principles of lawfulness, fairness, and transparency as set out in the GDPR.

§

Furthermore, the controller had violated the principle of data minimization by initiating checks on reimbursements even for individuals whose applications had been rejected and who had therefore never received payments. Furthermore, the controller had not adequately assessed the risks associated with a data processing operation as sensitive as that on applications for social benefits, since it had not carried out an impact assessment on the rights and freedoms of the data subjects. Update: Following an appeal presented by INPS the judge of the XVIII civil section of the Court of Rome annulled the fine of EUR 300,000. GDPR Articles: Art. 5 (1) a), c), d) GDPR, Art. 25 GDPR, Art. 35 GDPR Industry: Public Sector and Education

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
C-638/23 Amt der Tiroler Landesregierung v Datenschutzbehörde In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt… CJEU ·Eighth Chamber Feb 27, 2025 Public Authority Controllers Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… CJEU ·Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-740/22 Endemol Shine Finland Oy In Case C-740/22, the Court of Justice of the European Union (Sixth Chamber) ruled on a preliminary reference from the Itä-Suomen hovioikeus (Court of Appeal, Eastern Finland)… CJEU ·Sixth Chamber Mar 7, 2024 Criminal Data Personal Data Types of Special Categories of Personal Data
Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Jan 28, 2020 Personal Data Privacy by Design & Default Processing