The Italian authority imposes a €55,000 fine on the Agency for Digital Italy for failures in information obligations related to the National Index of Digital Domiciles

The Italian data protection authority (Garante) sanctions the Agency for Digital Italy (AgID) with a €55,000 fine for failing to inform professionals about the automatic transfer and publication of their professional digital domicile in a new public directory accessible to all.

Facts and context

The Italian data protection authority (Garante) today published a sanction decision against the Agency for Digital Italy (AgID), including the imposition of a €55,000 fine, for failures related to the information of data subjects and data protection by design during the creation of the National Index of Digital Domiciles (INAD).

The case originated from several complaints and reports received by the authority following the launch of the INAD, which enabled the automatic transfer of professional addresses from another register (INI-PEC).

Grounds for the decision

The authority found the following breaches against AgID, as the manager of the INAD and therefore the data controller:

  • Obligation of lawfulness, fairness, transparency, and purpose limitation (Article 5(1)(a) and (b) of the GDPR) and obligation to inform (Article 12 and Article 14 of the GDPR): AgID proceeded with the automatic transfer of professional email addresses (PEC) from the INI-PEC index to the new INAD index, thus making them publicly accessible to anyone. This processing constituted a new and expanded purpose, as a professional address by default became a personal digital domicile. The authority found that AgID did not adequately and priorly inform the concerned professionals of this transfer, depriving them of the possibility to choose a distinct personal digital domicile before publication. The authority rejected the "disproportionate effort" argument (Article 14(5)(b) of the GDPR), emphasizing that more effective, albeit belated, information measures were eventually implemented via professional orders, proving their feasibility.
  • Obligation of data protection by design and by default (Article 25 of the GDPR) and accountability (Article 5(2) of the GDPR): The authority considered that AgID did not implement, from the design phase of the INAD service, appropriate technical and organizational measures to ensure compliance with data protection principles. In particular, the system published the transferred data by default without ensuring that data subjects were previously informed and enabled to exercise their choices. The two-year delay in implementing effective corrective measures was also considered a breach of the accountability principle, which requires demonstrating compliance and taking adequate measures in a timely manner.

However, the authority decided to dismiss the complaints related to the incorrect indication of the service provider during authentication (violation of Article 13 of the GDPR) and the lack of cooperation (Article 31 of the GDPR), considering that other information elements allowed identification of the data controller and that response delays were justified by organizational difficulties.

Authority's decision

Consequently, the authority imposed a €55,000 fine on the Agency for Digital Italy (AgID).

Furthermore, the authority ordered the publication of its decision on its website.

Lessons learned

This decision confirms / specifies / recalls that:

  • The transfer of personal data to a new public directory for an expanded purpose constitutes further processing that requires specific and prior information of the data subjects.
  • The "disproportionate effort" exception for the information obligation (Article 14(5)(b) of the GDPR) is to be interpreted strictly and cannot be invoked when there are indirect but effective communication channels, such as professional orders.
  • Data protection by design requires integrating safeguards, such as information and the possibility of choice, into the process before any data publication, not adding them afterwards.
  • The accountability principle implies not only defining compliance measures but also implementing them effectively and responsively, notably by promptly correcting identified breaches.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire