AgID – €55,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
AgID was fined for improperly including professional email addresses in a public index without proper consent. This matters because it shows that even government agencies must respect privacy rights. Businesses should be careful about how they handle personal information to avoid similar issues.
What happened
AgID automatically included professionals' email addresses in a public index without their consent.
Who was affected
Professionals whose email addresses were included in the INAD index were affected.
What the authority found
The authority found that AgID did not have a valid legal basis for processing the email addresses, violating GDPR requirements.
Why this matters
This case emphasizes the need for transparency and consent when handling personal information. Companies should ensure they have the necessary permissions before using individuals' data.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian lawSee Articles 3-bis, 6-quater and 6-quinquies, d. lgs. 82/2005. and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complainedIt is not clear whether the DPA started the investigation ex officio or due to the complaints. that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. = == First of all, t
Related Enforcement Actions (0)
No other enforcement actions found for AgID in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
28 May 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€55,000
GDPRhub ID
gdprhub-10078About this data
Cite as: Cookie Fines. AgID - Italy (2026). Retrieved from cookiefines.eu
Last updated: