INPS – €300,000 Fine (Italy, 2021)

€300,000Garante per la protezione dei dati personali25 February 2021Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Italy's national social security institute, INPS, was fined for collecting personal data without proper consent when assessing aid applications during the Covid crisis. This matters because it shows that organizations must follow strict rules about how they handle personal information. Businesses should ensure they have clear consent processes in place for collecting user data.

What happened

INPS collected personal data from applicants for financial aid without obtaining proper consent.

Who was affected

Italian citizens applying for financial aid from INPS whose personal data was collected during the application process.

What the authority found

The Garante found that INPS violated GDPR rules by not having a valid legal basis for processing personal data.

Why this matters

This ruling emphasizes the importance of obtaining consent before processing personal data. Organizations must review their data collection practices to comply with GDPR.

GDPR Articles Cited

AI-verified

Art. 25(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 5(2) GDPR
Art. 25(GDPR)
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
scope corrected
Full Legal Summary
Detailed

The Italian national social security institute (INPS) has provided financial aids to Italian citizens in order to face the Covid crisis. To access this aids, citizens were required to satisfy certain criteria. The INPS, in order to speed up the process to obtain the aid, first assessed the request only on the basis of the documentation provided in the request by the applicant, and just in a second moment, after the dispensing of the aid, carried out a more specific investigation for every applicant. During the second phase assessment, the INPS checked whether between the requests there were parliamentarians or holders of offices in public administrations. To do so, INPS collected some personal data from open source registers and generated from this open data the personal tax code of the applicants and compared it with the one in the application. This way of calculation of the tax code can entail some mistakes. The secondary examination was carried on also for the subjects to which the aid was already been refused under the first examination. Only afterwards, the Labour ministry declared that parliamentarians and holders of administrative office would be excluded from this financial aid. Were these activities contrary to the GDPR? The DPA found that the fact that the second examination on parliamentarians and holders of administrative offices has been carried out before the note of Labour ministry on the exclusion of these categories from the financial aid, comported a violation of the principles of lawfulness, fairness and transparency as per Article 5(1)(a) GDPR. The fact that the processing was not limited to who received the aid but included who had already been refused, was in violation of the principle of adequacy and minimisation as per Artcle 5(1)(c) GDPR. The fact that the tax code has been generated from open data and not obtain by official sources and thus potentially erroneous, was violating the principle of adequacy as per Article 5(1)(d) GDPR

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for INPS in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

25 February 2021

Authority

Garante per la protezione dei dati personali

Fine Amount

€300,000

GDPRhub ID

gdprhub-3235

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. INPS - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: