[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVlXqP3XGffBitWLyfMiccH49bQuDOT-1lYVl88J2LOk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"f362dd6e-ac17-4176-9e8f-227f9e71c9cc","agid-fined-55k-for-automatic-email-inclusion-without-proper-gdpr-consent","96bdd609-1861-4959-a9d3-c4f80d53fe33","AgID Fined €55K for Automatic Email Inclusion Without Proper GDPR Consent","Italy's Garante fined AgID €55,000 for automatically enrolling professionals' email addresses into the INAD digital domicile index without adequately informing them of the processing or providing a clear opt-out mechanism. This violates core GDPR principles of transparency (Article 5) and the rights of data subjects to be informed (Articles 13\u002F14). The case highlights that even government digital infrastructure agencies are not exempt from data protection obligations. Failing to communicate data processing activities clearly erodes public trust and exposes organizations to significant regulatory penalties. Consent and transparency mechanisms must be designed into systems from the outset, not retrofitted after complaints arise.","**Immediate actions:**\n- Audit all existing data collection and processing workflows to identify where personal data is enrolled automatically without explicit prior notice to data subjects.\n- Publish clear, accessible privacy notices detailing the legal basis, purpose, and opt-out procedures for any mandatory or automatic data processing.\n\n**Policy & Governance improvements:**\n- Conduct a Data Protection Impact Assessment (DPIA) before launching any system that processes personal data at scale or on behalf of public services.\n- Appoint or empower a Data Protection Officer (DPO) to review new digital services for GDPR compliance before go-live.\n- Establish a formal process for data subjects to exercise their rights (access, erasure, objection) with defined response SLAs.\n\n**Long-term compliance measures:**\n- Integrate privacy-by-design principles into the software development lifecycle so consent and notification mechanisms are built in by default.\n- Schedule periodic third-party GDPR compliance audits covering data inventories, legal bases, and subject rights fulfillment.\n- Maintain an up-to-date Record of Processing Activities (RoPA) as required under GDPR Article 30 and review it quarterly.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 14 – Information to be provided where personal data have not been obtained from the data subject","GDPR Article 21 – Right to object","GDPR Article 25 – Data protection by design and by default","GDPR Article 30 – Records of processing activities","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST SP 800-53 PT-1 (Privacy Policies and Procedures)","NIST SP 800-53 PT-5 (Privacy Notice)","NIST Privacy Framework – Govern-P and Communicate-P functions","CIS Control 3 – Data Protection","ISO\u002FIEC 29100 – Privacy Framework","published","2026-06-22T22:20:57.440995+00:00","2026-06-22T22:20:57.324+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419\u002F2026&diff=51945&oldid=51938","garante-per-la-protezione-dei-dati-personali-italy-419-2026-6b16fd","Garante per la protezione dei dati personali (Italy) - 419\u002F2026",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]