Series
Blogs
Italy – The Garante fines a fellow government agency over digital transformation failure
Italy – The Garante fines a fellow government agency over digital transformation failure
14 July 2026
Series
Blogs
14 July 2026
Author: Eleonora Curreri
On 28 May 2026, the Italian Data Protection Authority (the “Garante”) issued a decision (No. 419 — doc. web n. 10259701) imposing a fine of €55,000 on AgID — the Agenzia per l’Italia Digitale, the Italian government agency responsible for coordinating Italy’s digital transformation agenda.
The fine was for multiple violations of the GDPR in connection with the management of Italy’s National Index of Digital Addresses (Indice Nazionale dei Domicili Digitali, “INAD”). The decision is significant on two levels. First, it clarifies the limits of key defences under Article 14(5) GDPR. Second, this is the first time the Garante has sanctioned a public body for failing to implement compliance conditions that the Garante itself had attached to a prior regulatory opinion.
In Italy, certified electronic mail, known as PEC (Posta Elettronica Certificata) has the legal value of a registered letter. This is the standard medium for official communications between individuals, professionals, businesses and public administrations.
The INAD is a public register managed by AgID in which citizens and professionals can register a PEC address as their “digital domicile”: the official address at which they receive communications from public authorities. A separate pre-existing register, the INI-PEC, holds the professional PEC addresses of companies and professionals and is administered by the Ministry of Enterprises.
Starting in June 2023, the professional PEC addresses of approximately two million professionals registered in INI-PEC were automatically migrated into the INAD. This change was mandated by Italian legislation (Article 6-quater of the Digital Administration Code). From July 2023, those addresses were published online and made accessible to anyone without authentication.
Importantly, AgID’s own INAD Guidelines (“INAD Guidelines”) were adopted in 2021 and incorporated conditions set by the Garante in a prior opinion. They required that affected professionals be individually notified before publication and given 30 days to elect a separate personal digital domicile if they wished.
AgID did not comply. Instead of targeted individual notifications, it relied on communications sent to selected professional associations, press releases and social media posts.
This triggered complaints from data subjects who started to receive legally sensitive personal notifications – including judicial notices – at a professional PEC inbox accessible to office collaborators.
The Garante opened a formal investigation and found AgID’s approach unlawful on the following grounds:
However, the Garante concluded that some potential breaches were not made out. For example, the alleged violation relating to the incorrect display of UnionCamere (a federation of Italian chambers of commerce, erroneously shown as the SPID digital identity service provider during login) was closed on the ground that, in the context of the portal as a whole, users could nonetheless identify AgID as the data controller.
Similarly, the alleged failure of AgID to cooperate with the Garante was closed after the Garante accepted AgID’s explanations regarding its financial and organisational difficulties. The delays did not amount to intentional non-cooperation.
AgID relied on two issues to justify its transparency failings. It first invoked Article 14(5)(b), the “disproportionate effort” exemption.
AgID argued that individually notifying two million professionals was impractical. The Garante rejected this based on AgID’s own subsequent conduct, which involved issuing a targeted joint communication with the Ministry of Enterprises directed at professional bodies with instructions to cascade it to members. This demonstrated that a more effective mechanism had been available all along. Having belatedly adopted a more targeted approach, AgID could not simultaneously maintain that such an approach had been impracticable from the outset.
AgID also invoked Article 14(5)(c), which disapplies the information obligation where data collection is mandated by law and appropriate safeguards are in place. The Garante also rejected this point. This condition is only available where there is an “appropriate safeguard” and that was precisely the individual notification that AgID had committed to give in the INAD Guidelines (reflecting the Garante’s 2021 opinion). A controller cannot invoke an exemption whose precondition is the very safeguard it has omitted.
AgID is not a private company. It is instead a public body established by statute, entrusted with a mandate of national strategic importance.
The decision confirms that GDPR accountability obligations apply with equal force to public sector bodies and that the Garante will not exercise restraint on grounds of institutional comity where data subjects’ rights are at stake. The relatively modest fine reflects a medium gravity assessment and several mitigating factors (no prior violations, some public awareness activities conducted, corrective measures ultimately adopted). Its institutional significance, however, goes beyond the quantum.
More broadly, where primary legislation mandates a data migration without embedding adequate transparency mechanisms, the implementing agency bears the full compliance risk — even though the design choice was made by the legislature.
The significance of the AgID case is not the Garante exercising its enforcement powers against a public body. This practice is well-established by the Garante across a wide range of public sector entities (and many other supervisory authorities have sanctioned public bodies in their jurisdiction).
Instead, the novelty lies in the convergence of three elements: (i) the regulatory status of the respondent, a body that itself issues legally binding guidelines governing Italy's entire digital public administration; (ii) the direct causal link between the Garante's own prior consultative intervention and the specific compliance obligation found to have been breached; and (iii) the decision to impose a monetary fine, rather than stopping short at a formal reprimand. For example, the Garante previously issued a reprimand to the National Social Security Institute (INPS) in July 2024 in circumstances that were, in many respects, equally constrained.
The most durable implication of the decision is doctrinal. The Garante's prior opinion of July 2021 (upon which the INAD Guidelines are based) was not a soft-law recommendation or a best-practice indication. It was, in effect, binding and AgID incorporated that condition into its own regulatory instrument. The decision makes clear that this created an accountability loop from which there is no exit via Article 14(5) GDPR. A controller cannot invoke the "appropriate safeguards" exemption when those safeguards are the very obligations it has itself undertaken and failed to discharge.
More broadly, conditions attached to the Garante's consultative opinions are not suggestions. Once incorporated into the relevant normative framework, their non-fulfilment is sanctionable even where the respondent drafted the normative instrument in question and formally accepted those conditions as its own.
For public bodies operating digital infrastructure platforms, a statutory mandate may create processing risks, but it does not displace the obligation to implement the safeguards designed to mitigate those risks. When the two conflict, the absence of agreed safeguards is an aggravating circumstance – not a mitigating one.