Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data
Original title: Cass.Civ. - 15625/2026
Facts — Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. The DPA appealed this decision to the court. Holding — The court dismissed the appeal. The court first stated that the controller processed the data lawfully under Article 6(1)(e) GDPR (public interest) and Article 6(3)(b) GDPR. While the controller processed data of specific data subjects (politicians), the court stated that national law allowed the controller to check the eligibility of all data subjects applying for the subsidy. The controller had also obtained the personal data through public databases provided by the Chambers of Parliament and Ministry of the Interior. The court also dismissed the DPA’s arguments on data minimisation (Article 5(1)(c) GDPR). The court stated that the principle of data minimisation is not absolute, and must be balanced with other interests at stake. The court took into consideration the fact that the data was publicly available and the need to quickly verify a high number of applications during a state of emergency. According to the court, there was also no other way to check applications still under review, and concluded that there was an overriding public interest in carrying out the verification process quickly. Finally, the court considered that the controller complied with Article 25 GDPR, as it processed data lawfully and in compliance with Article 5(1)(c) GDPR. In terms of data accuracy (Article 5(1)(d) GDPR), the court dismissed the DPA’s argument that the controller’s system did not eliminate the risk of “homocodes” (identical tax numbers between two or more people). The court considered that the data collected by the Chambers of Parliament and Ministry of Interior were presumed to be accurate. The court also noted that national law foresees the risk of “homocodes” and sets specific procedures in such cases, and that no actual inaccuracies were found in the controller’s verification process. Finally, the court did not find a violation of Article 35 GDPR. The court stated that the controller did not have the obligation to conduct a DPIA, as it did not meet all the necessary criteria. According to the court, the DPA failed to explain the potential high risks of large scale processing that would have justified the need for a DPIA. Given the previous dismissed arguments, the court considered that the controller had also complied with the principle of accountability (Articles 5(2) and 24 GDPR).
How it connects
References
Cited by
- VG Düsseldorf - 29 K 3490/24
- VG Düsseldorf - 29 K 3490/24
- BGH: Court must grant unredacted file access in compulsory auctions under Art. 6(1)(e)
- Judgment of the Court (Third Chamber) of 2 March 2023.#Norra Stockholm Bygg AB v Per Nycander AB.#Request for a preliminary ruling from the Högsta domstolen.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 6(3) and (4) – Lawfulness of processing – Production of a document containing personal data in civil court proceedings – Article 23(1)(f) and (j) – Protection of judicial independence and judicial proceedings – Enforcement of civil law clai
Related across sources
Full text
JUDGMENT on the appeal registered under No. 20692/2022 R.G. filed by: Personal Data Protection Authority, represented and defended by the State Attorney General -appellant- against INPS – National Institute for Social Security, represented and defended by attorneys Gaetano De Ruvo, Paolo Aquilone, and Mauro Sferrazza -counterappellant- against the judgment of the Court of Rome No. 4735/2022 filed on March 24, 2022. Having heard the report of the case presented at the public hearing on January 22, 2026 by Councilor Davide De Giorgio; Having heard the Public Prosecutor represented by Deputy Attorney General Michele Di Mauro, who concluded that the appeal be granted; Court of Cassation - unofficial copy Civil Sentence, Section 2 No. 15625 Year 2026 President: MILENA FALASCHI Rapporteur: DAVIDE DE GIORGIO Publication date: 05/21/2026 2 Having heard Marina Russo of the State Attorney's Office, counsel for the appellant, who referred to the defense; Having heard Gaetano De Ruvo and Paolo Aquilone, counsel for the counter-appellant, who referred to the defense briefs. FACTS OF THE CASE INPS – National Institute for Social Security filed an appeal before the Court of Rome pursuant to Articles 152 of Legislative Decree No. 196/2003 and 10 of Legislative Decree No. 150/2011 against Order No. 87/2021 of the Italian Data Protection Authority, with which the latter, having declared the unlawfulness of the processing carried out by the institution in violation of EU Regulation no. 679/2016 on the protection of personal data, had ordered the institution to pay a fine of €300,000.00, in addition to the deletion of all personal data processed up to that point in violation of the data minimization principle and the performance of a data protection impact assessment pursuant to Article 35 of the Regulation with reference to the processing, before restarting any processing operation, including as part of a comprehensive impact assessment relating to all processing carried out by the Institute for this purpose. As emerges from the contested ruling, the disputed issue revolved around the methods by which INPS had performed some of the second-level checks following the disbursement of the so-called "Covid bonus" during the pandemic emergency. Given the need to proceed with the immediate payment of the benefit, a complete verification of the requirements for obtaining it was reserved for a later phase. On the assumption that parliamentarians and regional and local administrators fell under a social security regime incompatible with receiving the benefit in question, the institute conducted a verification by acquiring the personal data of elected office holders from the databases of the Chamber of Deputies, the Ministry of the Interior, and, later, the Senate. It extracted their Court of Cassation - unofficial copy 3 tax codes using the criteria set out in the Ministerial Decree of March 12, 1974, and, by cross-referencing the data thus obtained with the tax codes of those who had submitted an application for the bonus, it identified the holders of political office who had submitted the request. With the provision in question, the Italian Data Protection Authority found the following to have been violated: 1) the principle of lawfulness, fairness, and transparency of processing pursuant to Article 5, paragraph 1, letter a), of the Regulation; 2) the principle of data minimization pursuant to Article 5, paragraph 1, letter c), of the Regulation; 3) the principle of accuracy pursuant to Article 5, paragraph 1, letter d), of the Regulation; 4) the protection of personal data by design and by default pursuant to Article 25 of the Regulation; 5) the obligation to conduct a data protection impact assessment pursuant to Article 35 of the Regulation; 6) the principle of accountability pursuant to Articles 5, paragraph 2, and 24 of the Regulation. The opponent argued that the Guarantor's findings were unfounded and requested the annulment of the decision, or, alternatively, a reduction of the imposed fine. The respondent appeared in court, requesting that the opposition be dismissed. With ruling no. 4735/2022, published on March 24, 2022, the Court of Rome, upholding the appeal, annulled the contested decision and ordered the respondent to reimburse the opponent for the legal costs. In its reasoning, the Court noted the following: With reference to the violation of the principle of lawfulness, fairness, and transparency of processing, it should be noted that the same legislative provision as set out in Legislative Decree no. 18/2020 to exclude the right to the Covid bonus for those who were enrolled, at the time of submitting the application, in other mandatory social security schemes, nor did the request to the Ministry of Labor for Court of Cassation - unofficial copy 4 for an opinion, the content of which was found to be in accordance with the decisions adopted by the institution, lead to any conclusions to the contrary. The Court also found the respondent's conduct to be compliant with the principle of minimization in light of the following considerations: - it guaranteed faster checks and was the only one capable of also including applications still under investigation, which could have been accepted at a later time because they were still pending, or by virtue of the subsequent extension of the deadlines for submitting applications; - limiting the benefit to only successfully resolved applications would have entailed, in the event of a review or appeals, the need to implement new benefits; - the data processed had been limited to the minimum necessary to verify entitlement to the bonus, or for the specific (and dutiful, as well as legitimate) purpose pursued by INPS. As for the violation of the principle of accuracy, the complaint had to be considered raised in the abstract, given that no case of so-called homocody appeared to have occurred in practice. Furthermore, given that Article 5 of the Regulation, in recommending "taking all reasonable measures to promptly erase or rectify inaccurate data with respect to the purposes for which they are processed," provides for the possibility of a post-processing accuracy check, provided that it is collected on the basis of sufficiently reliable elements, it should have been noted that the tax codes had been calculated based on a procedure established by a regulatory law and on personal data extracted from official databases and open to free consultation. A violation of the principle of personal data protection by design and by default was ruled out on the basis of the general nature of the complaint, in the absence of any concrete suggestion of a lawful alternative course of action, and also given the fact that the procedural processing of the compensation application did not Court of Cassation - unofficial copy 5 include the performance of subsequent checks, and, finally, taking into account the foreseeability of the processing for the control purposes in question; as for the risks to the rights and freedoms of the data subjects, they had to be deemed nonexistent, given the failure to disclose the names of the politicians who had requested the payment of the bonus and the absence of any concrete interference of such risks with the specific violations contested. Regarding the violation of the obligation to conduct a data protection impact assessment, the Court, despite noting that the processing was carried out on a large scale, ruled out the existence of the conditions for such an assessment, since the only concrete risk of the cross-referencing of data was the loss of an unduly paid economic benefit, a risk not contemplated in Recital 75 of the Regulation, while the risk of disclosure of the data was not causally related to the processing itself. Finally, once the existence of other violations had been ruled out, the violation of the principle of accountability had also been deemed nonexistent. It was also noted that INPS had sent a communication to the Garante in which, in addition to indicating the role of the data protection officer, identified as the Central Anti-Fraud Directorate, it also specified that the press reports relating to the matter had been disseminated through sources outside the institute, as the press outlets involved had reported, and that the measures adopted appeared entirely adequate, given that the processing did not present any high risk, given that it consisted of cross-referencing non-sensitive information, taken from an open data system, with information provided by the data subjects, within the specific purposes for which it had been collected. The Italian Data Protection Authority appealed the ruling in question on eight grounds. Court of Cassation - unofficial copy 6 The INPS – National Institute for Social Security (INPS) opposed the appeal with a counterappeal. After a public hearing was scheduled, the Public Prosecutor, represented by Deputy Prosecutor General Dr. Michele Di Mauro, presented written conclusions, and the INPS filed an explanatory memorandum. REASONS FOR THE DECISION 1. The objection of inadmissibility of the appeal for lack of specificity, raised by the counterappellant, must be dismissed, noting, in general, that the appellant has fully identified the provisions of law allegedly violated, examined their content, and recalled the statements contained in the contested judgment deemed to be in conflict with the provisions in question, stating the reasons therefor. 2. The first ground is listed as follows: violation and/or misapplication of the law in relation to Article 5, paragraph 1, letter a) of Regulation (EU) No. 679/2016 of the European Parliament and of the Council of 17 December 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also in conjunction with Articles 27 to 31 and 38 of Legislative Decree 18/2020 – Article 360, paragraph 1, no. 3 of the Italian Code of Civil Procedure. In particular, according to the appellant, given that the INPS had not been accused of lacking a legal basis for the benefit, it was noted that the institution had carried out its assessments on the existence of the conditions legitimizing the payment of the bonus for specific categories of individuals, and not in relation to the individual beneficiary. This was evident from the fact that the Ministry of Labor's opinion had been requested after the benefits had begun, in relation to parliamentarians and the representative bodies of local authorities, and not in general terms with respect to the requirements established by law (existence, or otherwise, of other significant social security schemes). According to the appellant, any interpretative doubts regarding the scope of the provision should have been resolved in relation to the individual applicants in the abstract, and in any case before carrying out the second-level assessment regarding whether the individual belonged to one or the other category. Specifically, while the method chosen by INPS had involved checks on categories of individuals (members of parliament and local administrators) who could have (along with many other categories) applied for the benefit, the law instead allowed checks on all individuals who had actually requested and obtained the benefit, to verify the existence of the legal requirements to obtain it. For the purposes of these checks, the tax codes declared when submitting the application could have been cross-referenced with those in the available databases (INPS and Tax Registry). The reason is unfounded. The processing at issue appears to have been carried out by INPS for the performance of a task carried out in the public interest or connected to the exercise of public authority vested in the data controller. In this regard, the Guarantor has framed the aforementioned public interest within the provision of art. 2-sexies, paragraph 2, letters l) and m) of Legislative Decree No. 196/2003, concerning, respectively, "control and inspection activities" and "granting, liquidation, modification, and revocation of economic benefits, incentives, donations, other emoluments, and authorizations." The acquisition aimed at carrying out second-level controls concerned the personal data of regional and local deputies and administrators and was carried out from open databases made available to anyone, via the dedicated web pages made available by the Chambers of Parliament and the Department for Internal and Territorial Affairs of the Ministry of the Interior. Court of Cassation - unofficial copy 8 In this regard, it is undisputed that the sensitive data referred to in art. 9 of Regulation (EU) 2016/679 of the European Parliament, namely personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data intended to uniquely identify a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation: both parties denied that the data processed fell within the aforementioned provision, and the Court also expressly noted that they were not sensitive data. Therefore, the processing itself falls legally within the scope of Article 6, paragraph 3, letter b) of the Regulation, referred to in Article 2-ter of Legislative Decree No. 196/2003, in the text in force at the time the incident occurred that led to the imposition of the sanction, i.e., before the amendment introduced by Legislative Decree No. October 8, 2021, No. 139, converted with amendments by Law No. 205 of December 3, 2021. In particular, the applicability of Article 2-sexies of Legislative Decree No. 196/2003, which specifically concerns the processing of the special categories of personal data referred to in Article 9, paragraph 1, of the Regulation, must be excluded. Moving on to examine the appellant's complaints, the first provision which the appellant claims has been violated is Article 5, paragraph 1, letter a) of Regulation (EU) No. 679/2016 of the European Parliament, which provides that personal data shall be "processed lawfully, fairly and in a transparent manner in relation to the data subject (lawfulness, fairness and transparency)". In turn, Article Article 6 of the Regulation governs the lawfulness of the processing itself, providing, among other things, in paragraph 3, that in the event that it occurs, without the data subject's consent, for the performance of a task carried out in the public interest or connected to the exercise of official authorities vested in the data controller, the data processing must be based on an adequate regulatory basis. Court of Cassation - unofficial copy 9 With the contested ruling, INPS was accused of processing data for the purpose of second-level checks regarding the disbursement of the bonus under the relevant aspect, solely because it occurred before the entitlement to it had been established in the cases in question. In this regard, recital 41 of the Regulation contains the following indications: "Where this Regulation refers to a legal basis or legislative measure, this does not necessarily require the adoption of a legislative act by a parliament, without prejudice to the requirements of the constitutional order of the Member State concerned. However, such a legal basis or legislative measure should be clear and precise, and its application foreseeable, for the persons subject to it, in accordance with the case law of the Court of Justice of the European Union (the "Court of Justice") and the European Court of Human Rights." For its part, the Court of Rome, in relation to the above, essentially deemed the legal basis consisting of the emergency legislation referred to in Legislative Decree no. 101/2001 to be sufficiently clear and precise. 18/2020, with the consequent finding of irrelevance of the subsequent request for a ministerial opinion, which had confirmed the institution's decisions. The assessment in question is based on the merits and is therefore unquestionable in this case, except for any flaw in the reasoning, which is not alleged in this case. In any case, it should be noted that: - the condition for the benefit, consisting in the applicants' failure to enroll in other mandatory social security schemes, was directly provided for by Legislative Decree no. 18/2020; - any interpretative doubts on the part of INPS at the time of the treatment did not in itself affect the clarity and precision of the rules; - the ministerial opinion, subsequently acquired, did not constitute a secondary source of detailed legislation compared to the primary one mentioned above, so it was only to the latter that it was necessary Court of Cassation - unofficial copy 10 to refer in order to verify whether, at the time of the processing, the relevant legal basis was sufficiently clear and precise; - the same paragraph 1 of Article 2-ter of Legislative Decree No. 196/2003, in the text currently in force ratine temporis, provides, in relation to the processing of personal data carried out for the performance of a task carried out in the public interest or connected to the exercise of official authority, that the legal basis provided for in Article 6, paragraph 3, letter b), of the Regulation is constituted exclusively by a provision of law or, in the cases provided for by law, by a regulation, sources both different from the ministerial opinion. Therefore, the violation of the law alleged by the appellant cannot be identified, given the objections raised in the contested decision. The additional considerations formulated in the appeal for annulment, far from contradicting the reasoning adopted on this point by the trial judge, concern different aspects that, with specific reference to the violation in question, were not considered either in the contested decision or, therefore, in the contested judgment. In any case, the appeal does not specify whether and in what terms the arguments in question were formulated during the trial on the merits, and therefore they are inadmissible here. 3. The second ground is titled as follows: violation and/or false application of the law in relation to Article 5, paragraph 1, letter c), of Regulation (EU) 2016/679 of the European Parliament and of the Council of 17 December 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also in conjunction with Articles 27 to 31 and 38 of Legislative Decree 18/2020 – Article 360, paragraph 1, no. 3 of the Italian Code of Civil Procedure. In particular, according to the appellant, given that the processing of personal data relating to parliamentarians and regional and local administrators Court of Cassation - unofficial copy 11 had not been limited to the beneficiaries of the benefit, but had instead involved all those who had applied for the Covid bonus, including those whose applications, already at the first-level review, had been examined and rejected, it should have been considered that, if the purpose of the scheme was to recover the sums illegitimately received by political office holders, the processing should have been limited to those who had actually received the benefit. With regard to those who, despite having submitted an application, had not received the bonus, there was no reason to carry out a second-level review and, therefore, no reason to process the data. Ultimately, according to the appellant, it was not permissible to apply preventive and generalized treatment to any non-beneficiary applicant, including those who had demonstrated acquiescence to the institution's rejection decision. The fourth ground is listed as follows: violation and/or misapplication of the law in relation to Article 25 of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – Article 360, paragraph 1, no. 3 of the Italian Code of Civil Procedure. In particular, according to the appellant authority, the failure to adopt predetermined criteria to limit the processing of personal data to that which is strictly necessary was an undisputed fact and such as to constitute a violation of Article 25 of the Regulation. The foreseeability of the processing in the presence of a legitimate interest of the data controller did not affect the need to implement the aforementioned provision, and this is without considering that the processing at issue was carried out not for a legitimate interest of the data controller, but rather for the performance of a task in the public interest, a hypothesis that is very different from the first. Court of Cassation - unofficial copy 12 The two grounds in question appear closely connected, given that the lack of adequate processing planning criticized by the INPS by the Data Protection Authority resulted, in the latter's opinion, in the omission of appropriate measures to ensure that, by default, only the data necessary for each specific purpose of the processing was processed, thus violating the principle of data minimization. These grounds are unfounded. Art. 5, paragraph 1, letter Article 25(2) of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 provides that personal data shall be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimization")." Recital 39 of the Regulation also states that "personal data should be processed only if the purpose of the processing cannot reasonably be achieved by other means." In turn, Article 25(2) of Regulation (EU) No 679/2016 of the European Parliament and of the Council of 17 December 2016 provides as follows: "The controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This obligation applies to the amount of personal data collected, the scope of the processing, the period of retention, and accessibility. In particular, these measures ensure that, by default, personal data are not made accessible to an indefinite number of natural persons without the intervention of the natural person." In this regard, it has been observed that the principle of privacy by design aims to ensure the existence of an appropriate level of privacy and protection of personal data from the design phase of any system, service, product, or process, as well as throughout their lifecycle. In other words, it aims to ensure an appropriate level of data protection in all processing activities and implementations Court of Cassation - unofficial copy 13 carried out within an organization. To fulfill this principle, data controllers and processors must be proactive and preventative, evaluating and implementing suitable technical and organizational measures to integrate data subject protection safeguards into the processing and to apply the fundamental data protection principles specified in Article 5 of EU Regulation no. 2016/679, such as transparency, purpose limitation, and minimization (see: Cass. No. 28385/2023). Specifically, it is undisputed that the cross-referencing of data did not only concern political office holders who had actually received the allowance, but also extended to individuals whose applications had already been rejected. The counter-appellant, moreover, pointed out that, as deduced in the original appeal filed before the Court, the processing of all applications was still ongoing, and even those initially rejected were subject to re-examination, because Legislative Decree No. 24/2020 had extended the deadline for submission and removed some incompatibilities already foreseen with the previous Legislative Decree No. 18/2020. In this regard, it should be noted that, in general, recital 4 of the Regulation states that "the right to the protection of personal data is not an absolute prerogative, but must be considered in light of its social function and must be balanced with other fundamental rights, in accordance with the principle of proportionality." Even the principle of data minimization, by its very formulation, cannot be considered absolute, as it requires carrying out, on a case-by-case basis, a comparison between the protection of the right to the confidentiality of personal data and the needs justifying its processing. Furthermore, this comparison cannot fail to take into account the type of data being processed, since it is clear that, for this purpose, Supreme Court - unofficial copy 14 sensitive data as referred to in Article 9 of the Regulation cannot be placed on the same level as data that are not sensitive. In this case, as seen above, the INPS's needs were institutional ones related to the performance of second-level checks on applications for access to the so-called Covid bonus, in order to verify actual entitlement to the benefit and avoid undue payments or fraud. In general, the interpretation of case law has found that the right to demand proper management of one's personal data, although falling within the fundamental rights set forth in Article 2 of the Constitution, is not a "tyrant" or a "totem" to which other rights that are equally constitutionally relevant must always be sacrificed. On the contrary, the rules on the protection of sensitive data must be coordinated and balanced with the constitutional provisions that protect other, overriding rights, as far as the public interest in the speed, transparency, and effectiveness of administrative activity is concerned. Determining whether a data subject has violated the legal rules governing the management of other people's data requires interpreting the latter, balancing the interests they protect with other potentially conflicting constitutionally protected interests (see: Cass. No. 10280/2015; Cass. No. 6177/2023). The need to balance the various interests at stake with reference to the principle of data minimization under Article 5, paragraph 1, letter c), of the Regulation has also been affirmed by the Court of Justice of the European Union (see: judgment of 02.03.2023 of the Third Chamber of the Court in Case No. C-268/21, concerning the production of a document containing personal data in civil proceedings). The assessment of the adequacy, relevance, and necessity of the processing with respect to its purposes, taking into account all the circumstances of the specific case, is the responsibility of the judge on the merits and is final in the legitimacy proceedings, where duly justified. Court of Cassation - unofficial copy 15 In this case, the data extracted from the institutional databases and used for the purposes of the checks were clearly public registry data, since they are freely accessible to anyone, and the additional data with which they were cross-referenced were those provided to the institution by those who had submitted the application for access to the bonus and whose treatment constituted a mandatory step in assessing whether or not they were entitled to the benefit. Furthermore, the processing clearly took place in a particular context, linked to the state of emergency, the high number of requests submitted, and the need to ensure a prompt institutional response. The Court, taking into account the Guarantor's observations and the defenses presented by INPS, held that the treatment complied with the principle of minimization, given that the procedure followed ensured greater speed of checks and was the only one capable of also including applications still under investigation, which could have been accepted at a later time, either because they were still pending or by virtue of the subsequent extension of the deadlines for submitting them. In this case, considering the foregoing and taking into account the prevalence of the public interest in a speedy conclusion of the procedure, it must be considered that the reasoning of the judge of the merits complied with the principles set out above. For the rest, this is an assessment of the merits, adequately motivated and not subject to review here since it is governed by the determination of the indispensability of the treatment as carried out (see: Cass. No. 9922/2022). According to the Guarantor, the processing in question was not carried out in compliance with the principles of personal data protection, from design and by default, enshrined in Article 25 of the Regulation. This is due to the failure to predetermine the conditions Court of Cassation - unofficial copy 16 preventing parliamentarians and regional and local administrators from being entitled to the bonus, the processing of data not necessary for the performance of second-level controls, and the failure to consider the risks that the processing posed to the rights and freedoms of data subjects, including those arising from possible inaccuracies in the methods used to calculate the data subjects' tax codes. In this regard, the absence of objective grounds for uncertainty relevant to the identification of the regulatory basis for the processing and the lack of a violation of the principle of data minimization clearly demonstrate that the counter-appellant institution is not obliged to establish default data processing settings that are different and additional to those commonly used in carrying out the institution's normal institutional activities. Therefore, on this point too, the contested decision appears to comply with Article 25 of the Regulation. 4. The third ground is listed as follows: violation and/or misapplication of the law in relation to Article 5, paragraph 1, letter d) of Regulation (EU) No. 679/2016 of the European Parliament on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – Article 360, paragraph 1, no. 3 of the Italian Code of Civil Procedure. In particular, according to the appellant, the INPS's extraction of the tax codes of members of the political class was incorrect, using personal data acquired by consulting the databases of the Chambers of Parliament and the Ministry of the Interior, and the use of the system referred to in Ministerial Decree No. 2227 of 12 March 1974, which did not avoid the risk of so-called "unauthorized access." homocodie (i.e., identical tax code between two or more people); in fact, according to the court, the potential harm resulting from the risk in question would be significant in itself. Court of Cassation - unofficial copy 17 The reason is unfounded. Art. 5, paragraph 1, letter d) of the European Parliament Regulation 679/2016/EU provides that personal data must be "accurate and, where necessary, kept up to date; every reasonable step must be taken to erase or rectify without delay any data that are inaccurate, having regard to the purposes for which they are processed ('accuracy')". Recital 39 of the Regulation also states that "every reasonable step should be taken to ensure that inaccurate personal data are rectified or erased". Since the topic of identifying data is concerned, Recital 26 is also relevant. After stating that "it is desirable to apply the principles of data protection to all information relating to an identified or identifiable natural person," it states that "to establish the identifiability of a natural person, account should be taken of all means, such as single-handling, which the controller or a third party may reasonably use to identify that natural person, directly or indirectly." Furthermore, "to determine whether means are reasonably likely to be used to identify the natural person, all objective factors should be taken into account, including the costs and the time required for identification, taking into account both the technologies available at the time of the processing and technological developments." In this regard, it is true that the accuracy of the data, although it can be further verified after acquisition, constitutes a very specific objective of the acquisition activity, to be pursued by adopting the most suitable methods to achieve it. It should be noted, however, that the personal data collected from the public databases of the Chambers of Deputies and the Ministry of the Interior were to be presumed accurate, given their institutional origin, and that the procedure Court of Cassation - unofficial copy 18 used to extract the tax code from them was the official one established by Ministerial Decree no. 2227 of March 12, 1974. Regarding the risk of so-called homocodiality, Article 6 of the aforementioned Ministerial Decree provides that, when the alphanumeric expression relating to the first fifteen characters of the code is common to two or more subjects, it is differentiated for each of the subjects following the first coded subject, which means that none of the subjects involved is assigned the code thus determined. From the foregoing, it follows that, in the event that the alphanumeric expression relating to the first fifteen characters thus calculated is common to multiple subjects, none of these subjects could have been identified using the code thus obtained. A further corollary of the foregoing is the absolute absence, in such a case, of any risks to confidentiality, given the impossibility of associating any subject with the possibly incorrect code. Moreover, the legitimate possibility of error is permitted in light of the legislative provision concerning the deletion or rectification of data that may be inaccurate with respect to the purposes for which they are processed. As noted by the trial judge and not questioned here, in practice, no inaccuracy was found in the identification of the individuals whose data were cross-referenced, so the Garante's challenge is purely abstract. The considerations formulated by the trial judge appear correct in light of the foregoing, and to them it must be added that the alternative course of action proposed by the Garante, consisting in requesting tax codes from the Tax Registry, would have caused, in addition to a delay in the timing of second-level checks, also a wider circulation of the personal data necessary for their performance. 5. The fifth ground is listed as follows: violation and/or false application of the law in relation to art. 35 of the Rules of Procedure of the Court of Cassation - unofficial copy 19 European Parliament 679/2016/EU on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - Art. 360, paragraph 1, no. 3, Code of Civil Procedure. In particular, according to the appellant authority, there was a risk to the rights and freedoms of individuals, which was not constituted by the possibility of losing, as a result of the controls, an unduly received economic benefit; on the contrary, it was the processing itself, if carried out without a prior risk assessment, that could result (potentially even unjustly) in the loss of the right. The sixth ground is listed as follows: failure to provide reasons regarding a fact that is decisive for the judgment and was the subject of discussion between the parties (Article 360, paragraph 1, no. 5, Code of Civil Procedure). In particular, the appellant complains that, in examining whether the conditions for the impact assessment were met, the judge on the merits referred to a prerequisite ("a method that goes beyond the reasonable expectations of the interested party") not mentioned in the contested decision, and instead completely ignored the decisive criterion relating to the "creation of a correspondence or combination of a set of data," expressly indicated. The grounds, which must be examined together given their connection, are unfounded. Article 35, paragraph Article 1 of Regulation (EU) No 679/2016 of the European Parliament and of the Council provides that, "where a type of processing, in particular using new technologies, and taking into account the nature, scope, context, and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing on the protection of personal data." Court of Cassation - unofficial copy 20 The risks to the rights and freedoms of natural persons that may justify the need for an impact assessment are described as follows in Recital 75: "Risks to the rights and freedoms of natural persons, of varying likelihood and severity, may result from processing of personal data that may result in physical, material or non-material damage, in particular: if the processing may lead to discrimination, identity theft or fraud, financial loss, damage to reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorized reversal of pseudonymisation, or any other significant economic or social harm; if data subjects risk being deprived of their rights and freedoms or prevented from exercising control over their personal data; if personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as genetic data, data concerning health, or data concerning a person's sex life or criminal convictions or offences or related security measures are processed; if personal aspects are evaluated, in particular by analyzing or predicting aspects concerning professional performance, economic situation, health, personal preferences or interests, reliability or behavior, location or movements, for the purpose of creating or using personal profiles; if personal data of vulnerable natural persons, in particular minors, are processed; if the processing concerns a significant amount of personal data and a large number of data subjects. It should be noted at the outset that neither party has referred to the use, for the purposes of the processing, of technologies that are new or different from those usually employed by the respondent institution for its institutional activities. That said, it is noted that the "Guidelines on data protection impact assessment and determining whether processing is likely to result in a high risk" for the purposes of Regulation (EU) 2016/679" of the Article 29 Data Protection Working Party of 4 April 2017, as amended and last adopted on 4 October 2017 and endorsed by the European Data Protection Board on 25 May 2018 ("WP 248, rev. 01"), have identified nine criteria to be taken into account for the purpose of identifying processing operations that may result in a "high risk": 1) assessment or assignment of a score, including profiling and prediction, in particular taking into account "aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or the movements of the data subject”; 2) automated decision-making that produces legal effects or similarly significantly affects individuals; 3) systematic monitoring of data subjects; 4) sensitive data or data of a highly personal nature; 5) large-scale data processing; 6) matching or combining data sets; 7) data relating to vulnerable data subjects; 8) innovative use or application of new technological or organizational solutions; 9) when the processing itself "prevents data subjects from exercising a right or from availing themselves of a service or a contract" In turn, the Garante, with provision no. 467 of 11 October 2018, deemed that the presence of two or more of the aforementioned criteria indicates a processing that presents a high risk to the rights and freedoms of data subjects and for which a data protection impact assessment is therefore required. It identified the list of types of processing, subject to the consistency mechanism, to be subjected to an impact assessment, reported in Annex 1, which is an integral part of the provision in question. In this case, the criteria indicated in the contested provision of the Garante are the following: 1) the processing of Court of Cassation - unofficial copy 22 data on a large scale; 2) the creation of correspondences or combinations of data sets; 3) the fact that the processing itself prevents data subjects from exercising a right or availing themselves of a service or contract. Now, in the contested ruling, the existence of the first condition is positively verified (with the clarification that it concerned large-scale processing, but not involving the sensitive data referred to in Article 9 of the Regulation), while the existence of the third was excluded. As for the second, contrary to what the appellant complained about, it was taken into consideration in the ruling, in the part where reference was made to the "manner that goes beyond the reasonable expectations of the data subject." It should be noted that the text of the WP29 guidelines, cited by both the parties and the trial judge, on this point is as follows: "creating correspondences or combining sets of data, for example starting from data deriving from two or more processing operations carried out for different purposes and/or by different data controllers in a manner that goes beyond the reasonable expectations of the data subject." It follows that the trial judge's reference to exceeding the data subject's reasonable expectations refers precisely to the criterion in question, a criterion that the appellant authority erroneously believes - given the above - to have been overlooked, and whose presence, however, was taken into consideration and reasonedly excluded by the Court. On this point, apart from complaining of a lack of consideration - non-existent in light of the above - the appellant has made no submissions. Furthermore, the element relating to exceeding the reasonable expectations of the data subject was deemed incompatible with the public nature of the identification data used by INPS. The sixth ground of appeal therefore has been rejected. From the foregoing, the fifth ground of appeal must also be rejected. Court of Cassation - unofficial copy 23 Indeed, Article 35, paragraph 1, of Regulation (EU) No 679/2016 of the European Parliament and of the Council 679/2016/EU, in providing for the possibility of "a high risk to the rights and freedoms of natural persons" such as to require a prior impact assessment, refers to the processing to be carried out in itself, regardless of the manner in which it was subsequently carried out. In fact, the impact assessment, which must be conducted before the processing is carried out, presupposes an ex ante assessment of the existence of any risks; the appellant also agrees with this, as is evident from the appeal on page 16. Now, the Guarantor, in addition to failing to mention the use of new technologies, does not explain the potential risks of a large-scale processing operation that would have justified, ex ante, and therefore regardless of the violations currently attributed to INPS, an impact assessment. This is in contrast to the judge on the merits, who instead noted that the processing itself did not involve any publication or disclosure of personal data and that the only potential risk for its recipients was the loss, in the event of an unfavorable outcome of the checks, of an unduly received benefit. Moreover, as the Court accurately stated, it was the lack of requirements that led to the revocation of the benefit, and not the treatment itself. It follows that, given the lack of coexistence of multiple indicators of the necessity of an impact assessment, the contested ruling is legally correct. 6. The seventh ground of appeal is listed as follows: violation and/or misapplication of the law in relation to Articles 5, paragraph 2, and 24 of Regulation (EU) No 679/2016 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC. Court of Cassation - unofficial copy 24 (General Data Protection Regulation) - Article 360, paragraph 1, no. 3 CPC. In particular, according to the appellant, the Court's finding that there was no violation of the principle of accountability was erroneous when based on the non-existence of other violations. The eighth ground is listed as follows: nullity of the judgment due to the mere appearance of the reasoning (Article 360, paragraph 1, no. 4, Code of Civil Procedure). In particular, according to the appellant, the arguments used by the Court to affirm the non-existence of the violation in question were eccentric with respect to what the Garante contested in the contested order, as well as irrelevant to the principle of accountability, so that the reasoning on this point was merely apparent. The two grounds, which must be examined together because they are connected, are unfounded. Article 5, paragraph 2, of Regulation (EU) No 679/2016 of the European Parliament provides that "the controller is responsible for compliance with paragraph 1 and able to demonstrate it ('accountability')". In turn, Article 24 of Regulation (EU) No 679/2016 of the European Parliament provides the following: "1. Taking into account the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary. 2. Where proportionate to the processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller. 3. Adherence to codes of conduct referred to in Article 40 or to a certification mechanism Corte di Cassazione - unofficial copy 25 referred to in Article 42 may be used as an element to demonstrate compliance with the controller's obligations. Specifically, the Guarantor, in its challenged ruling, deemed it to identify a specific violation of the above-mentioned provisions, noting that, during the investigation conducted, INPS had not adequately documented, from various perspectives, the circumstances surrounding the measures taken and the related reasons. For his part, the trial judge, in addition to ruling out the existence of the violation in question in light of the non-existence of the other violations, cited in his reasoning , deeming it relevant, the communication sent by INPS to the authority. In this communication, in addition to indicating the data protection officer, identified as the Central Anti-Fraud Directorate, it was also specified that the press reports relating to the incident had been disseminated through sources external to the institute, as the media involved had themselves reported, and that the measures adopted appeared entirely adequate, given that the processing did not present any type of high risk, given that it consisted of the cross-referencing of non-sensitive information, taken from an open data system, with elements provided by the data subjects themselves, within the specific purposes for which they had been collected. Now, the reasoning in question cannot be considered merely apparent. In truth, the reasoning is only apparent, and the ruling is null and void because it is affected by error in procedendo, when, although graphically present, it does not make the basis of the decision perceptible, because it contains arguments that are objectively inappropriate to clarify the reasoning used by the judge to form his or her conviction. It is not possible to leave it to the interpreter to supplement it with the most varied hypothetical conjectures (see: Cass. No. 1986/2025). Court of Cassation - unofficial copy 26 On the contrary, in the present case, the reasoning of the trial judge is clearly evident from an examination of the considerations set out in the reasoning, even if they are not shared by the appellant, who considers them eccentric with respect to the objections contained in the contested ruling. In this case, the aforementioned lack of obligation on the counter-appellant institution to establish predefined data processing settings, different and additional to those commonly used in the performance of its normal institutional activity, the similar lack of the requirements for carrying out a preliminary impact assessment, and the type and origin of the data processed lead us to consider the reasoning of the trial judge to be legally correct, given that the institution had nothing concrete to prove other than the organization of its normal activity. 7. In light of the foregoing, the appeal must be dismissed. Costs follow the unsuccessful party and must be awarded as per the order. The procedural requirements exist, pursuant to art. 13, paragraph 1-quater, Presidential Decree no. 115/02, inserted by art. 1, paragraph 17, Law no. 228/12, for the appellant to pay an additional amount as a unified fee equal to that for the appeal, pursuant to paragraph 1-bis of the same Article 13, if applicable. P.Q.M. The Court dismisses the appeal and orders the appellant to reimburse the counter-appellant for the legal costs of the appeal, which it awards at €200.00 for expenses and €12,000.00 for fees, plus 15% for a lump sum reimbursement of general and incidental legal expenses, if and to the extent due. The procedural requirements are met, pursuant to Article 13, paragraph 1- quater, of Presidential Decree No. 115/02, inserted by Article 1, paragraph 17, of Law No. 228/12, Court of Cassation - unofficial copy 27 for the payment by the appellant of the additional amount as a unified fee equal to that for the appeal, pursuant to paragraph 1-bis of the same Article 13, if due. Thus decided in Rome, in the chambers of the Second Civil Section of the Court of Cassation, on January 22, 2026. Councillor Davide De Giorgio President Milena Falaschi Court of Cassation - unofficial copy