Italy Fines AgID €55,000 for GDPR Transparency Failures in INAD Email Index
Italy's Garante fined the Agency for Digital Italy (AgID) €55,000 for failing to adequately inform individuals that their professional email addresses would be included in the INAD public index, violating core GDPR principles of transparency, data minimization, and lawful processing. The agency used these email addresses for communications beyond their original professional purpose, effectively expanding data use without proper legal basis or user awareness. This matters because public-sector bodies are expected to model GDPR compliance, and failures here erode citizen trust in government-run digital infrastructure. Additionally, the lack of timely notification prevented data subjects from exercising their opt-out rights, compounding the harm.
Tactical Insight
Immediate actions
- Conduct a GDPR-aligned data inventory audit to verify that all data uses are covered by a documented lawful basis.
- Issue clear, prominent privacy notices to all data subjects whose information is held in public-facing registries before or at the point of collection.
Policy & governance improvements
- Establish a Data Protection Impact Assessment (DPIA) process mandatory for any new or expanded public digital index or registry.
- Define and enforce strict purpose limitation policies so that professional contact data cannot be repurposed for unrelated communications without explicit consent.
- Appoint or empower a qualified Data Protection Officer (DPO) to review communications campaigns before launch for GDPR compliance.
Detection & accountability measures
- Implement regular internal audits comparing actual data use against declared processing purposes in Records of Processing Activities (RoPA).
- Create a feedback and complaints mechanism allowing data subjects to easily flag misuse of their contact information and trigger a timely review.