Pago PA S.p.A – Violation Found (Italy, 2021)

Violation Found
Garante per la protezione dei dati personali9 June 2021Italy
final
ePrivacy
Violation Found

Pago PA S.p.A's app, IO, was found to track users without their consent. This is important because it shows that even public services must follow privacy rules. Companies should ensure they get permission before using tracking technologies.

What happened

Pago PA S.p.A's app IO tracked user behavior through Google and Mixpanel without obtaining consent.

Who was affected

Users of the IO app who had their behavior monitored without consent.

What the authority found

The Italian data protection authority found that Pago PA S.p.A violated GDPR by using third-party cookies before obtaining user consent.

Why this matters

This case highlights the need for all companies, including public service apps, to prioritize user consent for tracking. It sets a precedent for stricter enforcement of privacy rules in digital services.

GDPR Articles Cited

AI-verified

Art. 5(1) GDPR
Art. 58(2)(d) GDPR
Art. 58(2)(f) GDPR
View original scraped data
Art. 5(1) GDPR
Art. 58(2)(d) GDPR
Art. 58(2)(f) GDPR

Original data from scraper before AI verification against source document.

Source verified 11 April 2026
verified correct
Full Legal Summary
Detailed

“IO” is an app run by the Italian public payment system “PagoPA S.p.A” (S.p.A is the Italian equivalent of PLC, Public Limited Company). The app IO offers access to all of the digital services of the Italian Public Administration, and has been downloaded by more than 11,5 million of users. It offers access to over 12,000 services, such as tax payment systems, which are provided by more than 5,000 national and local institutions. The Italian DPA (Garante per la protezione dei dati personali) previously recognized some weaknesses in the IO app, in an opinion issued on June 12th, 2020 ([https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9367375 9367375]). For this reason, after the decree of May 31st, 2021—which established the digital COVID-19 Green Certifications— the Italian DPA reserved the right to conduct further investigation of the app IO, since citizens can use the app to receive and demonstrate their Green Certifications. Through investigation, the Italian DPA detected some critical issues in the app’s interactions with Google LLC and Mixpanel Inc. These interactions include a tracking system that allows the app to link frequent behavioral patterns to certain identified (or identifiable) individuals while using the different services offered by the app IO. On the one hand, use of the app on an Android device automatically triggers Google's Firebase Analytics services, which allow Google to monitor installation of the app and to send push notifications. On the other hand, Mixpanel's tracking libraries, imbedded in the app IO, automatically sends data about a wide variety of app-based actions tied to a unique identified user back to Mixpanel systems. Both of these functions are triggered automatically during the user’s first access of the app IO, and it is up to the users themselves to disable the services if they are not interested in them. The Italian DPA opined that data processing by Google and Mixpanel on the app IO do not conf

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Violations (2)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Pago PA S.p.A in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

9 June 2021

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-3576

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 80%

Cite as: Cookie Fines. Pago PA S.p.A - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: