{
 "jurisdiction_id": "IT",
 "jurisdiction": "Italy",
 "url": "https://dataprotection.gi/jurisdictions/italy/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 46,
  "sub_modules": 57,
  "source_register": 25
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.",
   "claims": [
    {
     "statement": "The Garante per la protezione dei dati personali is Italy's independent administrative authority, established by Law No. 675/1996 and subsequently regulated by the Codice Privacy, designated as GDPR Art.51 supervisory authority and based only in Rome.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR (Regulation (EU) 2016/679) applies directly in Italy and is implemented/adapted via the Codice Privacy (D.Lgs. 196/2003) as amended by D.Lgs. 101/2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Garante decisions consistently apply GDPR material-scope concepts (Art.4(2) processing, including dissemination) requiring a lawful basis for any processing operation under Italian law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10243180",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante exercised jurisdiction over Character Technologies Inc. (a US company operating Character.AI), citing among other violations a delayed designation of its EU representative, confirming extraterritorial application of GDPR to non-EU controllers targeting Italian users.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10269594",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A public-sector controller (Comune di Mirabella Imbaccari) was sanctioned in part for failing to communicate a change of its DPO's data to the Garante, evidencing a binding filing obligation regarding DPO contact information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10259523",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.",
   "claims": [
    {
     "statement": "The Garante fined a law firm for sending promotional emails absent consent and absent any other suitable lawful basis, in violation of Art.6(1)(a) GDPR and Art.130(2) of the Codice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10225019",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consent to marketing communication in Italy must be documentable in writing to the Garante and can, in any event, always be withdrawn by the data subject at any time.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/1785597",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under settled Garante case law, the notion of health-related personal data extends even to information about an employee's absence from service for illness, independent of whether a specific diagnosis is disclosed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10243180",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.",
   "claims": [
    {
     "statement": "The Garante issued a formal admonishment under Art.58(2)(b) GDPR against a controller for failing to comply with Art.12 obligations to provide an adequate and timely response to rights exercised under Arts.15-22 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10241926",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante has repeatedly ordered controllers/individuals to cease further processing of a minor's image absent both parents' consent, treating unlawful publication as requiring takedown under Art.17(1)(d) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10181642",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A telemarketing company was sanctioned for failing to timely register a data subject's opposition made via formal notice, despite repeated follow-up, confirming the RPO/objection mechanism as an enforceable data-subject right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9921112",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante held that a company's summer holiday period could not excuse a controller from its ongoing obligation to respond to data-subject rights requests without undue delay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10241926",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Framework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.",
   "claims": [
    {
     "statement": "The Garante fined Poste Italiane S.p.A. EUR 6,624,000 and PostePay S.p.A. EUR 5,877,000 (total EUR 12,501,000) partly because the companies failed to conduct adequate data protection impact assessments regarding mandatory device-monitoring authorizations in the BancoPosta/Postepay apps.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/italy-garante-fines-poste-italiane-and-postepay-over",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Comune di Mirabella Imbaccari was found non-compliant with GDPR partly for not communicating a change in its DPO's data to the Garante, alongside unlawful online disclosure of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10259523",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In a 2026 telemarketing case, the Garante examined the controller/processor allocation of responsibility across a data-collection platform (Unleadmited), a data broker (Conversion Media) and an end-client (Depurazione Acqua) for marketing-data sharing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10232061",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Poste Italiane and PostePay were found to have failed to adopt appropriate security measures in connection with mandatory device-monitoring processing represented as necessary for fraud prevention.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/italy-garante-fines-poste-italiane-and-postepay-over",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante sanctioned Città Metropolitana di Sassari in a 2026 data-breach case, as reported in the Authority's 29 July 2026 newsletter of enforcement actions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/-/asset_publisher/4e4H/rss",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Poste Italiane/PostePay decision identified shortcomings in data-retention policies and undefined retention limits as among the compliance failures underlying the EUR 12.5M fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/italy-garante-fines-poste-italiane-and-postepay-over",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.",
   "claims": [
    {
     "statement": "As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The final text of Italy's AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, ensuring continuity in cloud-infrastructure use while upholding data-protection and security standards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/italy-becomes-first-eu-member-state-to-pass-an-ai-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.",
   "claims": [
    {
     "statement": "The Garante issued an opinion to the Bank of Italy on a draft regulation concerning personal-data processing in the management of banking complaints ('esposti'), illustrating its consultative role in the financial sector.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": null,
     "source_url": null,
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante's 2026 newsletter cycle reports continued sanctioning and guidance activity in the health sector, including a hospital-operator sanction and telemedicine-platform guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/-/asset_publisher/4e4H/rss",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Violation of the opposition right under the Registro Pubblico delle Opposizioni regime (L.5/2018) attracts sanctions under GDPR Art.83(5), reaching up to EUR 20 million or 4% of total worldwide annual turnover of the preceding year, if higher.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/temi/telemarketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante ordered Amazon to stop record-keeping of workers' personal data, having found the company collected information on illnesses, union activity, and workers' personal and family lives.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/-/asset_publisher/4e4H/rss",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante confirmed a data subject's right to be informed of the score underlying a denied energy-supply contract, as reported in the Authority's 2026 press releases.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/-/asset_publisher/4e4H/rss",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante issued a favourable opinion on a Ministry of Education AI-based digital platform and accompanying guidelines for introducing AI in schools, subject to compliance observations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10162698",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Italy's AI Act national implementing decree introduces specific rules for the financial and insurance sectors alongside broader AI governance provisions.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10275843",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Rules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.",
   "claims": [
    {
     "statement": "Under the Garante's 2021 cookie guidelines, at first website access no cookie or tracking tool other than technical ones may be positioned on a user's device by default, and no active (third-party) or passive (fingerprinting) tracking may occur without consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9679893",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cookie walls are deemed unlawful by the Garante unless the site operator provides equivalent access to content/services without requiring consent to cookies or other trackers, and re-prompting consent at every visit is considered redundant and invasive.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9679893",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante found a violation of Arts.4(11),5,7,12,13,24 and 25 GDPR and Art.122 Codice where a cookie banner was configured so that clicking either 'accept technical cookies' or 'accept all cookies' resulted in the same four cookies being installed, undermining granular consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10118222",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Registro Pubblico delle Opposizioni (RPO) is a free, institutional service allowing consumers to register fixed and mobile numbers to block telemarketing, with Garante oversight of the register's operation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/temi/telemarketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante sanctioned data-broker Lusha EUR 2 million for monitoring and offering for sale the personal data of a large number of individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/-/asset_publisher/4e4H/rss",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante fined Enel Energia EUR 26.5 million for aggressive telemarketing where consumers' data were used without consent and the accountability principle was not complied with.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en/press-room",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Governance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.",
   "claims": [
    {
     "statement": "The Garante fined a platform in the Glovo group EUR 2.6 million for using algorithms that caused discrimination among riders.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en/press-room",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In fining Character Technologies Inc. EUR 158,000, the Garante found deficiencies in the information provided to users and that the DPIA and EU-representative designation were carried out belatedly.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10269594",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Italy's AI Act implementing decree designates the Garante as the market-surveillance authority for high-risk AI systems used in justice, law-enforcement, immigration, border-management and democratic-process contexts.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10275843",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/web/garante-privacy-en/press-room",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Italy's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10275606",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.",
   "claims": [
    {
     "statement": "The Garante required Character Technologies to guarantee correctly functioning age-verification systems, ensure effective 'cooling-off' mechanisms preventing renewed registration attempts by blocked minors, and set minors' profiles to private by default.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10269594",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Art.2-quinquies of the Codice, implementing Art.8(1) GDPR, a minor who has reached 14 years of age may validly consent to processing of their personal data in relation to information-society services; below that age, consent must be given by whoever exercises parental responsibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+(Testo+coordinato)",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante held that where a platform cannot verify a user's age, any consent or contract entered into by an under-14 user is invalid, leaving any associated processing (including for commercial/profiling purposes) devoid of a legal basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy / Agenda Digitale",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9526211",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Garante issued a favourable opinion on a Ministry of Education AI-service scheme and accompanying guidelines for introducing AI in schools, requiring information notices to be easily comprehensible to minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10162698",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/italy/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "High-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.",
   "claims": [
    {
     "statement": "A March 2026 amendment to Garante Regulation 1/2019 delegates adoption of certain Art.58(2)(b) corrective measures to departmental directors for time-barred or fully-remedied conduct, expressly excluding journalistic-sector, political/union-rights, high-turnover (>EUR 500,000) and major public-body cases from the delegation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10239146",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2025 the Garante adopted 807 collegial decisions, responded to 4,288 complaints and 145,846 reports, and issued 65 opinions on regulatory and administrative measures spanning public-administration digitalisation, healthcare, tax and justice.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10266612",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Garante sanction order may be opposed before the ordinary courts, via petition filed within 30 days of notification (60 days if the appellant resides abroad), under Art.152 of the Codice, Art.10 of D.Lgs.150/2011 and Art.78 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10225019",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 29 July 2026 the Garante gave a favourable opinion on the AI Act national implementing decree while asking for clarified human-oversight rules, clearer research/experimentation responsibilities, its own involvement in the Italian AI regulatory sandbox, and strengthened guarantees on biometric-database quality.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Garante Privacy",
     "source_url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10275843",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}