Istituto nazionale della previdenza sociale (INPS) – Court Ruling (Italy, 2026)

Court Ruling
DPA21 May 2026Italy
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An Italian court ruled that the Istituto nazionale della previdenza sociale (INPS) mishandled personal data during a subsidy program. The ruling highlights the need for organizations to follow data protection rules when processing personal information. Small businesses should ensure they comply with data protection principles to avoid penalties.

What happened

INPS was found to have processed personal data improperly while verifying eligibility for a COVID subsidy.

Who was affected

Individuals who applied for the COVID subsidy were affected by the mishandling of their personal data.

What the authority found

The court determined that INPS violated several GDPR principles, including lawfulness and data minimization, and ordered them to erase unlawfully processed data.

Why this matters

This ruling serves as a reminder that organizations must adhere to strict data protection standards. Small businesses should conduct regular audits of their data processing activities.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 25(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 5(2) GDPR
Art. 6(1)(e) GDPR
Art. 6(3) GDPR
View original scraped data
Art. 5(1)(c) GDPR
Art. 5(1)(d) GDPR
Art. 5(1)(a) GDPR
Art. 5(2) GDPR
Art. 6(1)(e) GDPR
Art. 6(3) GDPR
Art. 24(GDPR)
Art. 25(GDPR)
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityTribunale di Roma
Reviewed AuthorityDPA
Source verified 1 July 2026
verified correct
Full Legal Summary
Detailed

Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its data processing activities linked to a subsidy given during the pandemic (also called “the COVID bonus”). The DPA found that the controller had postponed its second screening of verifying the eligibility of data subjects to a later stage, on the grounds that there was a need to immediately pay the subsidy. The controller considered that politicians did not fall under the scope of eligible data subjects, as they were already enrolled in a mandatory social security scheme. The controller processed their personal data from databases to cross reference them with data subjects who had applied for the subsidy. The DPA found a violation of several GDPR principles: the principle of lawfulness (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), accuracy (Article 5(1)(d) GDPR) and accountability (Articles 5(2) and 24 GDPR). According to the DPA, the controller had not limited the cross referencing to data subjects that had received the allowance, but to those whose applications had already been rejected. In addition, the DPA found a violation of Articles 25 and 35 GDPR, as the controller failed to conduct a data protection impact assessment (DPIA). The DPA ordered the controller to erase all personal data that had been processed unlawfully and to carry out a DPIA before resuming its processing activities. The controller appealed the decision to the Court of Rome, and argued that the DPA’s decision was unfounded. The court upheld the appeal and dismissed the DPA’s decision. The court considered that the controller had processed data subjects’ data lawfully, as it had limited the amount of data to what was necessary to verify data subjects’ eligibility. The court also considered that the processing posed a low risk for data subjects’ rights, as the data subjects’ names were not disclosed. T

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Istituto nazionale della previdenza sociale (INPS) in IT

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

21 May 2026

Authority

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Istituto nazionale della previdenza sociale (INPS) - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: