All news
Enforcement July 8, 2026 3 min

Italy's DPA fines AgID: EUR 55,000 to the Agency for Digital Italy over transparency and privacy by design

Decision no. 419 of 28 May 2026: when the body steering the State's digitalisation gets it wrong, the message to the whole public sector is unmistakable

TL;DR for the DPO

Decision no. 419/2026: EUR 55,000 fine to AgID for breaching Arts. 5(1)(a)(b) and 5(2), 12, 14 and 25 GDPR, with publication of the order on the DPA's website. In short: lawfulness and purpose limitation, information to people whose data was NOT collected directly (Art. 14), and privacy by design. If it happens to the agency writing the technical rules of digital government, no public body can feel safe.

The three points that matter

  • Art. 14 is the great forgotten duty: when data comes from other sources (databases, other bodies, vendors) the notice is due anyway, within precise timeframes. It is the typical breach of projects that 'reuse' available data.
  • Privacy by design (Art. 25) enforced against a public body: compliance must be designed before launching platforms and services, not patched afterwards. Twice as true for public digital projects.
  • The public sanction weighs more than the EUR 55,000: publishing the order on the DPA's website is an accessory reputational sanction hitting institutional credibility.

What to do now, in practice

If you advise public bodies or their vendors: 1) for every project reusing data from other sources, check the Art. 14 notice exists and was given in time; 2) require the privacy assessment BEFORE launch (documented by design, not declared); 3) use this case in public-sector training: it is the perfect answer to 'we are a public body, it will not happen to us'.

Why it matters for your clients

The value of the case is both symbolic and practical: the authority applies the same rules to everyone, including the body coordinating the State's digital transformation. For a DPO working with the public sector it is leverage to obtain what is often postponed: complete notices on reused databases and design assessments actually done before go-live. The full text of the order on the DPA's website clarifies the specific context of the processing at issue.

Official source:Italian Data Protection Authority - injunction order no. 419 of 28 May 2026 (AgID)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min