🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
IT · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 25 sources retrieved model claude-sonnet-5 ·

Italy

IT schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 46 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.

Primary frameworkGDPR (Regulation (EU) 2016/679) + Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)
Traffic-light rationale — GreenMature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.

Sub-modules (5)

Regulator And AuthorityGreen

The Garante is Italy's independent DPA, based only in Rome, designated GDPR Art.51 supervisory authority.

Claims: CLM-IT-a1b2c301

Act And InstrumentsGreen

GDPR applies directly; Codice Privacy (D.Lgs.196/2003) as amended by D.Lgs.101/2018 is the national implementing/adapting act.

Claims: CLM-IT-a1b2c302

Material ScopeGreen

Material scope follows GDPR directly as an EU Regulation; Codice provisions (e.g. 2-septies, 2-decies) supplement special-category and remedies rules.

Claims: CLM-IT-a1b2c303

Territorial ScopeGreen

GDPR Art.3 territorial scope applies uniformly in Italy as directly-applicable EU law; non-EU providers (e.g. Character Technologies/US) have been pursued by the Garante including EU-representative designation failures.

Claims: CLM-IT-a1b2c304

Regulator Registration And FilingAmber

No general controller registration regime; residual duty to notify the Garante of DPO data changes, breach of which has been separately sanctioned.

Claims: CLM-IT-a1b2c305

Category narrative57 words

Italy is an EU Member State applying GDPR directly, supervised by the Garante per la protezione dei dati personali, seated in Rome, operating under the Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) which adapts national law to GDPR. No general controller registration/notification regime survives GDPR; residual filing duties concern DPO contact-data communication to the Garante.

Sources and claims (5)
  1. ConfirmedGarante PrivacyThe Garante per la protezione dei dati personali is Italy's independent administrative authority, established by Law No. 675/1996 and subsequently regulated by the Codice Privacy, designated as GDPR Art.51 supervisory authority and based only in Rome.
  2. ConfirmedGarante PrivacyGDPR (Regulation (EU) 2016/679) applies directly in Italy and is implemented/adapted via the Codice Privacy (D.Lgs. 196/2003) as amended by D.Lgs. 101/2018.
  3. ConfirmedGarante PrivacyGarante decisions consistently apply GDPR material-scope concepts (Art.4(2) processing, including dissemination) requiring a lawful basis for any processing operation under Italian law.
  4. ConfirmedGarante PrivacyThe Garante exercised jurisdiction over Character Technologies Inc. (a US company operating Character.AI), citing among other violations a delayed designation of its EU representative, confirming extraterritorial application of GDPR to non-EU controllers targeting Italian users.
  5. ConfirmedGarante PrivacyA public-sector controller (Comune di Mirabella Imbaccari) was sanctioned in part for failing to communicate a change of its DPO's data to the Garante, evidencing a binding filing obligation regarding DPO contact information.

#

Core lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.

Primary frameworkGDPR Arts. 6, 7, 9 + Codice Privacy Artt. 2-sexies, 2-septies, 2-quinquies
Traffic-light rationale — GreenCore lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.

Sub-modules (4)

Lawful BasesGreen

Garante enforcement confirms Art.6 GDPR consent/legitimate-interest requirements, e.g. sanctioning promotional emails sent absent consent or another suitable legal basis.

Claims: CLM-IT-b2c3d401

Special CategoriesGreen

The Garante applies a broad reading of special-category/health data, extending protection even to indirect health indicators such as sickness-absence records.

Claims: CLM-IT-b2c3d403

Pseudonymisation And AnonymisationAmber

No dedicated Garante pseudonymisation/anonymisation guidance surfaced in this research cycle; GDPR Art.4(5)/Art.25 concepts apply by default as directly-applicable EU law.

Absence provenance: No Garante-specific anonymisation/pseudonymisation guideline document was returned; only general references within AI-training case files.. Searched: Garante anonymisation pseudonymisation guidance Italy.

Category narrative61 words

Lawful bases follow GDPR Art.6 as construed by the Garante (consent, contract, legal obligation, legitimate interest); consent for marketing/telemarketing must be freely given, specific, and revocable at any time. Special categories (Art.9) receive heightened protection under Codice Art. 2-septies, with a broad interpretation of 'health data' extended even to sickness-absence notices. Dedicated pseudonymisation/anonymisation guidance was not located in this research pass.

Sources and claims (3)
  1. ConfirmedGarante PrivacyThe Garante fined a law firm for sending promotional emails absent consent and absent any other suitable lawful basis, in violation of Art.6(1)(a) GDPR and Art.130(2) of the Codice.
  2. ConfirmedGarante PrivacyConsent to marketing communication in Italy must be documentable in writing to the Garante and can, in any event, always be withdrawn by the data subject at any time.
  3. ConfirmedGarante PrivacyUnder settled Garante case law, the notion of health-related personal data extends even to information about an employee's absence from service for illness, independent of whether a specific diagnosis is disclosed.

#

Rights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.

Primary frameworkGDPR Arts. 12, 15-22 + Codice Privacy Artt. 2-decies, 130
Traffic-light rationale — GreenRights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.

Sub-modules (5)

Access RightGreen

Access and other Art.15-22 rights must receive an adequate, timely response under Art.12; failure led to a formal admonishment in a 2026 decision.

Claims: CLM-IT-c3d4e501

Rectification And ErasureGreen

Erasure/rectification obligations (Art.16-17 GDPR) are enforced, e.g. in minor-image publication cases requiring takedown upon parental request.

Claims: CLM-IT-c3d4e502

Restriction And ObjectionGreen

The right to object to direct-marketing processing is operationalised nationally via the Registro Pubblico delle Opposizioni (RPO); failure to timely register an opposition has been sanctioned.

Claims: CLM-IT-c3d4e503

Data PortabilityGreen

Portability (Art.20 GDPR) applies directly as EU law; no Italy-specific derogation identified in this cycle.

Absence provenance: No dedicated Garante portability guidance/enforcement item surfaced in this pass; general GDPR Art.20 applies.. Searched: Garante data portability guidance Italy 2026.

Deadlines And Response WindowsGreen

Controllers must provide adequate and timely responses to rights requests under Art.12; the Garante has rejected staff-absence (holiday period) as an excuse for delay.

Claims: CLM-IT-c3d4e504

Category narrative43 words

Garante enforcement gives operative content to Arts.12 and 15-22 GDPR, requiring an adequate and timely response to rights requests, sanctioning controllers (including via formal admonishment) for delayed or absent responses, and treating opposition/telemarketing-suppression requests (Registro Pubblico delle Opposizioni) as an enforceable objection mechanism.

Sources and claims (4)
  1. ConfirmedGarante PrivacyThe Garante issued a formal admonishment under Art.58(2)(b) GDPR against a controller for failing to comply with Art.12 obligations to provide an adequate and timely response to rights exercised under Arts.15-22 GDPR.
  2. ConfirmedGarante PrivacyThe Garante has repeatedly ordered controllers/individuals to cease further processing of a minor's image absent both parents' consent, treating unlawful publication as requiring takedown under Art.17(1)(d) GDPR.
  3. ConfirmedGarante PrivacyA telemarketing company was sanctioned for failing to timely register a data subject's opposition made via formal notice, despite repeated follow-up, confirming the RPO/objection mechanism as an enforceable data-subject right.
  4. ConfirmedGarante PrivacyThe Garante held that a company's summer holiday period could not excuse a controller from its ongoing obligation to respond to data-subject rights requests without undue delay.

#

Framework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.

Primary frameworkGDPR Arts. 24, 25, 30, 32-34, 35, 37-39 + Codice Privacy Artt. 2-quaterdecies, 166
Traffic-light rationale — AmberFramework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.

Sub-modules (7)

Accountability And DpiaAmber

Poste Italiane and PostePay were fined EUR 12.5M in April 2026 in part for failing to conduct adequate DPIAs.

Claims: CLM-IT-d4e5f601

Dpo RequirementsAmber

Controllers must communicate DPO data/changes to the Garante; a municipality's failure to do so contributed to a 2026 sanction.

Claims: CLM-IT-d4e5f602

Ropa RequirementsGreen

Art.30 GDPR ROPA duties apply directly as EU law; no Italy-specific ROPA enforcement case was located in this cycle.

Absence provenance: No dedicated ROPA-specific enforcement decision surfaced in this pass.. Searched: Garante ROPA registro delle attività di trattamento sanzione.

Joint Controller ArrangementsAmber

Marketing-data supply chains involving multiple controllers (data broker, buyer, sub-processor) were scrutinised in a 2026 telemarketing case examining controller allocation across Depurazione Acqua, Conversion Media and Unleadmited.

Claims: CLM-IT-d4e5f603

Security MeasuresAmber

The Poste Italiane/PostePay decision found the companies failed to adopt appropriate security measures for app-based device-monitoring processing.

Claims: CLM-IT-d4e5f604

Breach NotificationAmber

The Garante actively sanctions breach-notification and post-breach handling failures, including a 2026 decision against Città Metropolitana di Sassari and a separate case against a municipality for unlawful online disclosure of personal data over several years.

Claims: CLM-IT-d4e5f605

Retention And DisposalAmber

Poste Italiane/PostePay were found to have undefined retention limits and shortcomings in data-retention policy design.

Claims: CLM-IT-d4e5f606

Category narrative62 words

Accountability, DPIA, DPO, security and breach-notification duties (GDPR Arts.24-25, 30, 32-34, 35, 37-39) are heavily litigated in Italy. The 2026 Poste Italiane/PostePay decision (EUR 12.5M) illustrates DPIA, retention and security-measure failures; a Comune's failure to notify DPO data changes and unlawful online disclosure of personal data drove a separate 2026 sanction; a further breach sanction was issued against Città Metropolitana di Sassari.

Sources and claims (6)
  1. ConfirmedDataGuidanceThe Garante fined Poste Italiane S.p.A. EUR 6,624,000 and PostePay S.p.A. EUR 5,877,000 (total EUR 12,501,000) partly because the companies failed to conduct adequate data protection impact assessments regarding mandatory device-monitoring authorizations in the BancoPosta/Postepay apps.
  2. ConfirmedGarante PrivacyThe Comune di Mirabella Imbaccari was found non-compliant with GDPR partly for not communicating a change in its DPO's data to the Garante, alongside unlawful online disclosure of personal data.
  3. ConfirmedGarante PrivacyIn a 2026 telemarketing case, the Garante examined the controller/processor allocation of responsibility across a data-collection platform (Unleadmited), a data broker (Conversion Media) and an end-client (Depurazione Acqua) for marketing-data sharing.
  4. ConfirmedDataGuidancePoste Italiane and PostePay were found to have failed to adopt appropriate security measures in connection with mandatory device-monitoring processing represented as necessary for fraud prevention.
  5. ProbableGarante PrivacyThe Garante sanctioned Città Metropolitana di Sassari in a 2026 data-breach case, as reported in the Authority's 29 July 2026 newsletter of enforcement actions.
  6. ConfirmedDataGuidanceThe Poste Italiane/PostePay decision identified shortcomings in data-retention policies and undefined retention limits as among the compliance failures underlying the EUR 12.5M fine.

#

Transfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.

Primary frameworkGDPR Arts. 44-49 (directly applicable EU Regulation)
Traffic-light rationale — GreenTransfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.

Sub-modules (6)

Transfer MechanismsGreen

SCCs, BCRs, adequacy decisions and Art.49 derogations apply directly in Italy as components of the directly-applicable GDPR.

Claims: CLM-IT-e5f6a701

Adequacy ReceivedGreen

Adequacy determinations are an EU Commission competence under Art.45 GDPR, not a discrete Italian national act; no IT-specific 'received' adequacy instrument exists.

Absence provenance: Adequacy is adopted centrally by the European Commission and binds all Member States uniformly; no separate Italian determination exists.. Searched: Italy national adequacy decision GDPR.

Adequacy GrantedGreen

As with 'received' adequacy, 'granted' adequacy decisions are issued by the European Commission (Art.45), not by Italy individually.

Absence provenance: No Italy-specific adequacy-granting instrument exists; competence sits with the European Commission.. Searched: Italy grants adequacy third country.

Sccs And BcrsGreen

The Garante participates in the EU one-stop-shop mechanism for BCR approval of Italian corporate groups and applies EU Commission SCCs directly.

Claims: CLM-IT-e5f6a701

Transfer Impact AssessmentGreen

TIA obligations flow from EDPB/EU jurisprudence (Schrems II) and apply directly in Italy as part of the GDPR Art.46 framework.

Claims: CLM-IT-e5f6a701

Data LocalisationGreen

Italy's 2025 AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, indicating no general data-localisation mandate for AI-related processing.

Claims: CLM-IT-e5f6a702

Category narrative66 words

As an EU Member State, Italy applies GDPR Chapter V (Arts.44-49) transfer mechanisms directly and uniformly; adequacy decisions are an EU Commission competence exercised at Union level rather than a discrete Italian instrument, so IT-specific 'adequacy received/granted' determinations do not exist as separate national acts. Italy's new AI Law (L.132/2025) expressly permits installing AI systems on non-EU servers, indicating no blanket data-localisation mandate for AI processing.

Sources and claims (2)
  1. ConfirmedGarante PrivacyAs GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.
  2. ConfirmedIAPPThe final text of Italy's AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, ensuring continuity in cloud-infrastructure use while upholding data-protection and security standards.

#

Sectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.

Primary frameworkGDPR + Codice Privacy sectoral provisions (Artt.114, 122, 130) + Statuto dei Lavoratori (L.300/1970) + AI Act national implementing decree
Traffic-light rationale — AmberSectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.

Sub-modules (7)

Financial Sector OverlayGreen

The Garante issues opinions to the Bank of Italy on personal-data processing in banking-complaint ('esposti') management, illustrating a financial-sector consultative overlay.

Claims: CLM-IT-f6a7b801

Health Sector OverlayAmber

Health-sector data processing (hospitals, telemedicine platforms, health registries) is a recurrent enforcement and guidance focus of the Garante.

Claims: CLM-IT-f6a7b802

Telecoms And EprivacyAmber

ePrivacy/telecoms overlay operates through Art.122 Codice cookie rules and Art.130 Codice / L.5-2018 telemarketing rules enforced via the Registro Pubblico delle Opposizioni, with fines up to EUR 20M or 4% of global turnover for opposition-right violations.

Claims: CLM-IT-f6a7b803

Employment DataAmber

Employment-sector overlay (Art.4 L.300/1970, referenced by Art.114 Codice) constrains remote-monitoring technologies; the Garante ordered Amazon to stop record-keeping of workers' personal data including health, union activity and personal-life information.

Claims: CLM-IT-f6a7b804

Credit And ScoringGreen

The Garante confirmed a data subject's right to know the credit/energy score underlying a denied contract.

Claims: CLM-IT-f6a7b805

EducationGreen

The Garante has issued favourable opinions on AI-based educational platforms and guidelines for AI introduction in schools, subject to conditions.

Claims: CLM-IT-f6a7b806

InsuranceGreen

The AI Act national implementing decree introduces specific rules for the insurance sector alongside the financial sector.

Claims: CLM-IT-f6a7b807

Category narrative79 words

Sector overlays include: healthcare (frequent Garante sanctions and guidance on health data and telemedicine); telecoms/eprivacy (Art.122 Codice cookie rules, Registro Pubblico delle Opposizioni for telemarketing); employment (Art.4 Statuto dei Lavoratori/L.300-1970 constraints on remote-control technologies referenced via Art.114 Codice, e.g. the Amazon worker-monitoring order); credit/scoring (2026 Garante position affirming a right to know the score underlying a denied energy contract); education (favourable Garante opinions on AI-based educational platforms); insurance (the 2026 AI Act implementing decree introduces sector rules for insurance).

Sources and claims (7)
  1. Probablesource not recorded — The Garante issued an opinion to the Bank of Italy on a draft regulation concerning personal-data processing in the management of banking complaints ('esposti'), illustrating its consultative role in the financial sector.
  2. ProbableGarante PrivacyThe Garante's 2026 newsletter cycle reports continued sanctioning and guidance activity in the health sector, including a hospital-operator sanction and telemedicine-platform guidance.
  3. ConfirmedGarante PrivacyViolation of the opposition right under the Registro Pubblico delle Opposizioni regime (L.5/2018) attracts sanctions under GDPR Art.83(5), reaching up to EUR 20 million or 4% of total worldwide annual turnover of the preceding year, if higher.
  4. ConfirmedGarante PrivacyThe Garante ordered Amazon to stop record-keeping of workers' personal data, having found the company collected information on illnesses, union activity, and workers' personal and family lives.
  5. ProbableGarante PrivacyThe Garante confirmed a data subject's right to be informed of the score underlying a denied energy-supply contract, as reported in the Authority's 2026 press releases.
  6. ConfirmedGarante PrivacyThe Garante issued a favourable opinion on a Ministry of Education AI-based digital platform and accompanying guidelines for introducing AI in schools, subject to compliance observations.
  7. ProbableGarante PrivacyItaly's AI Act national implementing decree introduces specific rules for the financial and insurance sectors alongside broader AI governance provisions.

#

Rules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.

Primary frameworkePrivacy Directive 2002/58/EC as transposed by Art.122 Codice Privacy + GDPR Arts.4(11),6,7,12,13,25
Traffic-light rationale — AmberRules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.

Sub-modules (6)

Cookies And TrackersAmber

The 2021 Linee Guida cookie mandate a default no-cookie state on first access and ban cookie walls absent an equivalent no-consent path.

Claims: CLM-IT-a7b8c901, CLM-IT-a7b8c902

Dark PatternsAmber

A 2025 decision sanctioned a cookie banner configured so that both 'accept technical only' and 'accept all' installed the same four cookies, a dark-pattern-style design flaw.

Claims: CLM-IT-a7b8c903

Opt Out SignalsGreen

The Registro Pubblico delle Opposizioni functions as Italy's institutionalised opt-out signal for telemarketing, free to consumers and overseen by the Garante.

Claims: CLM-IT-a7b8c904

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific Garante guidance or enforcement was located in this research cycle.

Absence provenance: No dedicated Garante material on data clean rooms surfaced.. Searched: Garante clean room data collaboration room privacy.

Cross Context AdvertisingAmber

The Garante fined data-broker Lusha EUR 2 million for monitoring and selling the data of a large number of individuals, illustrating cross-context data monetisation enforcement.

Claims: CLM-IT-a7b8c905

Direct MarketingAmber

Multiple decisions (Lex Iuris, Enel Energia) sanction unconsented direct-marketing processing under Art.6(1)(a) GDPR and Art.130 Codice.

Claims: CLM-IT-a7b8c906

Category narrative63 words

Italy's cookie/tracker regime rests on the Garante's 2021 Linee Guida (Art.122 Codice + Arts.4(11),7,12,13,25 GDPR): default no non-technical cookies on first access, prohibition of cookie walls (absent an equivalent no-consent alternative), rejection of scrolling as valid consent, and a 6-month minimum before re-prompting consent. Dark-pattern-style banner manipulation, data-broker cross-context monetisation (Lusha), and unconsented direct marketing (Lex Iuris, Enel Energia) have all been sanctioned.

Sources and claims (6)
  1. ConfirmedGarante PrivacyUnder the Garante's 2021 cookie guidelines, at first website access no cookie or tracking tool other than technical ones may be positioned on a user's device by default, and no active (third-party) or passive (fingerprinting) tracking may occur without consent.
  2. ConfirmedGarante PrivacyCookie walls are deemed unlawful by the Garante unless the site operator provides equivalent access to content/services without requiring consent to cookies or other trackers, and re-prompting consent at every visit is considered redundant and invasive.
  3. ConfirmedGarante PrivacyThe Garante found a violation of Arts.4(11),5,7,12,13,24 and 25 GDPR and Art.122 Codice where a cookie banner was configured so that clicking either 'accept technical cookies' or 'accept all cookies' resulted in the same four cookies being installed, undermining granular consent.
  4. ConfirmedGarante PrivacyThe Registro Pubblico delle Opposizioni (RPO) is a free, institutional service allowing consumers to register fixed and mobile numbers to block telemarketing, with Garante oversight of the register's operation.
  5. ProbableGarante PrivacyThe Garante sanctioned data-broker Lusha EUR 2 million for monitoring and offering for sale the personal data of a large number of individuals.
  6. ConfirmedGarante PrivacyThe Garante fined Enel Energia EUR 26.5 million for aggressive telemarketing where consumers' data were used without consent and the accountability principle was not complied with.

#

Governance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.

Primary frameworkGDPR Art.22 + EU AI Act (Regulation (EU) 2024/1689) + Italian AI Law (L.132/2025) + national AI Act implementing decree
Traffic-light rationale — AmberGovernance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.

Sub-modules (6)

Profiling RestrictionsAmber

The Garante fined a Glovo-group platform EUR 2.6 million for using discriminatory rider-management algorithms.

Claims: CLM-IT-b8c9d001

Automated Decision Making TransparencyAmber

Character.AI was found to have provided insufficient information about processing operations and to have prepared its DPIA and EU-representative designation belatedly.

Claims: CLM-IT-b8c9d002

Ai Risk AssessmentsGreen

Italy's draft AI Act implementing decree designates the Garante as market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes.

Claims: CLM-IT-b8c9d003

Biometric RegimeAmber

The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects; a separate police-AI decree limits real-time remote biometric identification to specific serious-threat scenarios, though the Garante has urged strengthening biometric-database quality safeguards.

Claims: CLM-IT-b8c9d004, CLM-IT-b8c9d005

Genetic DataGreen

Genetic data receives heightened Art.9 GDPR/Art.2-septies Codice protection; no Italy-specific 2026 enforcement case was located in this cycle.

Absence provenance: No 2026 genetic-data-specific enforcement decision surfaced; general Art.9 GDPR/Art.2-septies Codice protection applies.. Searched: Garante dati genetici sanzione 2026.

State Surveillance CarveoutsAmber

Italy's police-AI decree permits real-time remote biometric identification only to confirm identity or locate specifically identified/identifiable individuals in relation to serious threats or missing-persons searches, per the AI Act (Art.5) framework.

Claims: CLM-IT-b8c9d005

Category narrative71 words

The Garante has been designated national market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes under Italy's AI Act implementing decree, while retaining full GDPR competence over any AI activity processing personal data. Enforcement precedent spans algorithmic-discrimination (Glovo riders), biometric/facial-recognition bans (Clearview AI), and transparency/DPIA failures in generative-AI chatbots (Character.AI). A separate police-use-of-AI decree restricts real-time remote biometric identification to narrowly defined serious-threat/missing-person scenarios.

Sources and claims (5)
  1. ConfirmedGarante PrivacyThe Garante fined a platform in the Glovo group EUR 2.6 million for using algorithms that caused discrimination among riders.
  2. ConfirmedGarante PrivacyIn fining Character Technologies Inc. EUR 158,000, the Garante found deficiencies in the information provided to users and that the DPIA and EU-representative designation were carried out belatedly.
  3. ProbableGarante PrivacyItaly's AI Act implementing decree designates the Garante as the market-surveillance authority for high-risk AI systems used in justice, law-enforcement, immigration, border-management and democratic-process contexts.
  4. ConfirmedGarante PrivacyThe Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects.
  5. ProbableGarante PrivacyItaly's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.

#

Age-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.

Primary frameworkGDPR Art.8 + Codice Privacy Art.2-quinquies
Traffic-light rationale — AmberAge-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.

Sub-modules (5)

Age VerificationAmber

Character.AI was ordered to guarantee correctly functioning age-verification systems, a 'cooling-off' mechanism against repeat registration by blocked minors, and default-private profiles for minors.

Claims: CLM-IT-c9d0e101

Minor Profiling BansAmber

The Garante blocked TikTok's processing where the platform could not verify user age, holding that consent/contract from under-14s is invalid and thus devoid of any legal basis for further processing including profiling.

Claims: CLM-IT-c9d0e103

Education SettingsGreen

School information notices must be easily comprehensible to minors and are subject to Garante prior review for AI-based educational platforms.

Claims: CLM-IT-c9d0e104

Dependent AdultsRed

No dedicated dependent-adults (elderly/incapacitated persons) data-protection regime distinct from general GDPR safeguards was located in this research cycle.

Absence provenance: No dedicated dependent-adults data-protection guidance or enforcement item surfaced in this pass.. Searched: Garante privacy anziani incapaci tutela dati personali 2026.

Category narrative57 words

The Italian digital age of consent is 14 (Codice Privacy Art.2-quinquies), below which parental/guardian consent is required for information-society services; below-14 consent is invalid absent parental authorisation, as applied in TikTok and social-media minor-image cases. Age-verification and default-privacy settings for minors were central to the 2026 Character.AI sanction. No dedicated dependent-adults (elderly/incapacitated) regime was identified this cycle.

Sources and claims (4)
  1. ConfirmedGarante PrivacyThe Garante required Character Technologies to guarantee correctly functioning age-verification systems, ensure effective 'cooling-off' mechanisms preventing renewed registration attempts by blocked minors, and set minors' profiles to private by default.
  2. ConfirmedGarante PrivacyUnder Art.2-quinquies of the Codice, implementing Art.8(1) GDPR, a minor who has reached 14 years of age may validly consent to processing of their personal data in relation to information-society services; below that age, consent must be given by whoever exercises parental responsibility.
  3. ConfirmedGarante Privacy / Agenda DigitaleThe Garante held that where a platform cannot verify a user's age, any consent or contract entered into by an under-14 user is invalid, leaving any associated processing (including for commercial/profiling purposes) devoid of a legal basis.
  4. ConfirmedGarante PrivacyThe Garante issued a favourable opinion on a Ministry of Education AI-service scheme and accompanying guidelines for introducing AI in schools, requiring information notices to be easily comprehensible to minors.

#

High-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.

Primary frameworkGDPR Arts. 58, 77-84, 83 + Codice Privacy Artt. 152, 154-bis, 166 + Reg. Garante 1/2019 and 2/2019
Traffic-light rationale — GreenHigh-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Garante exercises full Art.58(2) GDPR corrective powers; internal Reg.1/2019 was amended in March 2026 to delegate certain time-barred/low-impact corrective measures to departmental directors, excluding journalistic, political/union, high-turnover, and major-public-body cases.

Claims: CLM-IT-d0e1f201

Enforcement Activity IndexGreen

In 2025 the Garante adopted 807 collegial decisions and handled 4,288 complaints and 145,846 reports; 2026 saw multiple 7-figure fines (Poste Italiane/PostePay, Lusha) alongside smaller sanctions (Piaggio, Altroconsumo, Character.AI).

Claims: CLM-IT-d0e1f202

Regulator Funding And CapacityAmber

Public information on current-year Garante staffing/budget levels is limited in this research pass; historically the Authority has supplemented its inspection capacity with seconded Guardia di Finanza personnel.

Absence provenance: Current-year (2025/2026) headcount/budget figures were not located; only a historical (2008) administrative report referencing Guardia di Finanza secondment surfaced.. Searched: Garante privacy organico personale bilancio 2025 relazione annuale risorse.

Collective Redress And Class ActionsAmber

No GDPR-specific Italian collective-redress case was located in this cycle; general azione di classe mechanisms under the Codice del Consumo remain the available collective-litigation route.

Absence provenance: No 2026 GDPR-specific class-action decision surfaced in this research pass.. Searched: Garante privacy azione di classe class action GDPR Italia 2026.

Private Right Of ActionGreen

Data subjects may oppose Garante sanction orders before the ordinary judiciary within 30 days (60 if residing abroad) under Art.152 Codice/Art.10 D.Lgs.150/2011 and Art.78 GDPR.

Claims: CLM-IT-d0e1f203

Recent Developments 180DGreen

Within the last 180 days: the Garante fined Character.AI (3 July 2026), gave a conditioned favourable opinion on the national AI Act implementing decree (29 July 2026) while flagging biometric-safeguard gaps, sanctioned Piaggio (EUR 460k) and Altroconsumo (EUR 280k), sanctioned Città Metropolitana di Sassari for a data breach, and presented its 2025 Annual Report to Parliament (2 July 2026).

Claims: CLM-IT-d0e1f204

Category narrative116 words

The Garante wields full GDPR Art.58 corrective powers (warnings, orders, bans, fines up to EUR 20M/4% global turnover) and delegated internal procedures (Reg. 1/2019) for time-barred/low-impact cases. 2025 activity: 807 collegial decisions, 4,288 complaints and 145,846 reports handled, and 65 opinions issued on regulatory/administrative measures. Recent months show sustained high-value enforcement (Poste Italiane/PostePay EUR 12.5M, Character.AI EUR 158k, Lusha EUR 2M, Piaggio EUR 460k, Altroconsumo EUR 280k) and judicial pushback (a March 2026 sanction order was suspended by the Tribunale di Roma). No dedicated GDPR-based class-action/collective-redress statistic was identified distinct from the general Italian collective-action (azione di classe) mechanism under Art.140-bis Codice del Consumo; individual judicial opposition to Garante orders is available under Art.152 Codice/Art.78 GDPR.

Sources and claims (4)
  1. ConfirmedGarante PrivacyA March 2026 amendment to Garante Regulation 1/2019 delegates adoption of certain Art.58(2)(b) corrective measures to departmental directors for time-barred or fully-remedied conduct, expressly excluding journalistic-sector, political/union-rights, high-turnover (>EUR 500,000) and major public-body cases from the delegation.
  2. ConfirmedGarante PrivacyIn 2025 the Garante adopted 807 collegial decisions, responded to 4,288 complaints and 145,846 reports, and issued 65 opinions on regulatory and administrative measures spanning public-administration digitalisation, healthcare, tax and justice.
  3. ConfirmedGarante PrivacyA Garante sanction order may be opposed before the ordinary courts, via petition filed within 30 days of notification (60 days if the appellant resides abroad), under Art.152 of the Codice, Art.10 of D.Lgs.150/2011 and Art.78 GDPR.
  4. ConfirmedGarante PrivacyOn 29 July 2026 the Garante gave a favourable opinion on the AI Act national implementing decree while asking for clarified human-oversight rules, clearer research/experimentation responsibilities, its own involvement in the Italian AI regulatory sandbox, and strengthened guarantees on biometric-database quality.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Italy
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 25 source(s) in the cumulative register.