Traffic-light rationale — GreenMature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.
Sub-modules (5)
Regulator And AuthorityGreen
The Garante is Italy's independent DPA, based only in Rome, designated GDPR Art.51 supervisory authority.
Claims: CLM-IT-a1b2c301
Act And InstrumentsGreen
GDPR applies directly; Codice Privacy (D.Lgs.196/2003) as amended by D.Lgs.101/2018 is the national implementing/adapting act.
Claims: CLM-IT-a1b2c302
Material ScopeGreen
Material scope follows GDPR directly as an EU Regulation; Codice provisions (e.g. 2-septies, 2-decies) supplement special-category and remedies rules.
Claims: CLM-IT-a1b2c303
Territorial ScopeGreen
GDPR Art.3 territorial scope applies uniformly in Italy as directly-applicable EU law; non-EU providers (e.g. Character Technologies/US) have been pursued by the Garante including EU-representative designation failures.
Claims: CLM-IT-a1b2c304
Regulator Registration And FilingAmber
No general controller registration regime; residual duty to notify the Garante of DPO data changes, breach of which has been separately sanctioned.
Claims: CLM-IT-a1b2c305
Category narrative57 words
Italy is an EU Member State applying GDPR directly, supervised by the Garante per la protezione dei dati personali, seated in Rome, operating under the Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) which adapts national law to GDPR. No general controller registration/notification regime survives GDPR; residual filing duties concern DPO contact-data communication to the Garante.
Sources and claims (5)
ConfirmedGarante Privacy — The Garante per la protezione dei dati personali is Italy's independent administrative authority, established by Law No. 675/1996 and subsequently regulated by the Codice Privacy, designated as GDPR Art.51 supervisory authority and based only in Rome.
ConfirmedGarante Privacy — GDPR (Regulation (EU) 2016/679) applies directly in Italy and is implemented/adapted via the Codice Privacy (D.Lgs. 196/2003) as amended by D.Lgs. 101/2018.
ConfirmedGarante Privacy — Garante decisions consistently apply GDPR material-scope concepts (Art.4(2) processing, including dissemination) requiring a lawful basis for any processing operation under Italian law.
ConfirmedGarante Privacy — The Garante exercised jurisdiction over Character Technologies Inc. (a US company operating Character.AI), citing among other violations a delayed designation of its EU representative, confirming extraterritorial application of GDPR to non-EU controllers targeting Italian users.
ConfirmedGarante Privacy — A public-sector controller (Comune di Mirabella Imbaccari) was sanctioned in part for failing to communicate a change of its DPO's data to the Garante, evidencing a binding filing obligation regarding DPO contact information.
Traffic-light rationale — GreenCore lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.
Sub-modules (4)
Lawful BasesGreen
Garante enforcement confirms Art.6 GDPR consent/legitimate-interest requirements, e.g. sanctioning promotional emails sent absent consent or another suitable legal basis.
Claims: CLM-IT-b2c3d401
Consent ThresholdsGreen
Marketing consent must be documentable and is always revocable; Garante guidance requires unambiguous, specific, freely-given consent, rejecting scroll-based or pre-ticked mechanisms.
Claims: CLM-IT-b2c3d402
Special CategoriesGreen
The Garante applies a broad reading of special-category/health data, extending protection even to indirect health indicators such as sickness-absence records.
Claims: CLM-IT-b2c3d403
Pseudonymisation And AnonymisationAmber
No dedicated Garante pseudonymisation/anonymisation guidance surfaced in this research cycle; GDPR Art.4(5)/Art.25 concepts apply by default as directly-applicable EU law.
Absence provenance: No Garante-specific anonymisation/pseudonymisation guideline document was returned; only general references within AI-training case files.. Searched: Garante anonymisation pseudonymisation guidance Italy.
Category narrative61 words
Lawful bases follow GDPR Art.6 as construed by the Garante (consent, contract, legal obligation, legitimate interest); consent for marketing/telemarketing must be freely given, specific, and revocable at any time. Special categories (Art.9) receive heightened protection under Codice Art. 2-septies, with a broad interpretation of 'health data' extended even to sickness-absence notices. Dedicated pseudonymisation/anonymisation guidance was not located in this research pass.
Sources and claims (3)
ConfirmedGarante Privacy — The Garante fined a law firm for sending promotional emails absent consent and absent any other suitable lawful basis, in violation of Art.6(1)(a) GDPR and Art.130(2) of the Codice.
ConfirmedGarante Privacy — Consent to marketing communication in Italy must be documentable in writing to the Garante and can, in any event, always be withdrawn by the data subject at any time.
ConfirmedGarante Privacy — Under settled Garante case law, the notion of health-related personal data extends even to information about an employee's absence from service for illness, independent of whether a specific diagnosis is disclosed.
Traffic-light rationale — GreenRights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.
Sub-modules (5)
Access RightGreen
Access and other Art.15-22 rights must receive an adequate, timely response under Art.12; failure led to a formal admonishment in a 2026 decision.
Claims: CLM-IT-c3d4e501
Rectification And ErasureGreen
Erasure/rectification obligations (Art.16-17 GDPR) are enforced, e.g. in minor-image publication cases requiring takedown upon parental request.
Claims: CLM-IT-c3d4e502
Restriction And ObjectionGreen
The right to object to direct-marketing processing is operationalised nationally via the Registro Pubblico delle Opposizioni (RPO); failure to timely register an opposition has been sanctioned.
Claims: CLM-IT-c3d4e503
Data PortabilityGreen
Portability (Art.20 GDPR) applies directly as EU law; no Italy-specific derogation identified in this cycle.
Absence provenance: No dedicated Garante portability guidance/enforcement item surfaced in this pass; general GDPR Art.20 applies.. Searched: Garante data portability guidance Italy 2026.
Deadlines And Response WindowsGreen
Controllers must provide adequate and timely responses to rights requests under Art.12; the Garante has rejected staff-absence (holiday period) as an excuse for delay.
Claims: CLM-IT-c3d4e504
Category narrative43 words
Garante enforcement gives operative content to Arts.12 and 15-22 GDPR, requiring an adequate and timely response to rights requests, sanctioning controllers (including via formal admonishment) for delayed or absent responses, and treating opposition/telemarketing-suppression requests (Registro Pubblico delle Opposizioni) as an enforceable objection mechanism.
Sources and claims (4)
ConfirmedGarante Privacy — The Garante issued a formal admonishment under Art.58(2)(b) GDPR against a controller for failing to comply with Art.12 obligations to provide an adequate and timely response to rights exercised under Arts.15-22 GDPR.
ConfirmedGarante Privacy — The Garante has repeatedly ordered controllers/individuals to cease further processing of a minor's image absent both parents' consent, treating unlawful publication as requiring takedown under Art.17(1)(d) GDPR.
ConfirmedGarante Privacy — A telemarketing company was sanctioned for failing to timely register a data subject's opposition made via formal notice, despite repeated follow-up, confirming the RPO/objection mechanism as an enforceable data-subject right.
ConfirmedGarante Privacy — The Garante held that a company's summer holiday period could not excuse a controller from its ongoing obligation to respond to data-subject rights requests without undue delay.
Framework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.
Traffic-light rationale — AmberFramework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.
Sub-modules (7)
Accountability And DpiaAmber
Poste Italiane and PostePay were fined EUR 12.5M in April 2026 in part for failing to conduct adequate DPIAs.
Claims: CLM-IT-d4e5f601
Dpo RequirementsAmber
Controllers must communicate DPO data/changes to the Garante; a municipality's failure to do so contributed to a 2026 sanction.
Claims: CLM-IT-d4e5f602
Ropa RequirementsGreen
Art.30 GDPR ROPA duties apply directly as EU law; no Italy-specific ROPA enforcement case was located in this cycle.
Absence provenance: No dedicated ROPA-specific enforcement decision surfaced in this pass.. Searched: Garante ROPA registro delle attività di trattamento sanzione.
Joint Controller ArrangementsAmber
Marketing-data supply chains involving multiple controllers (data broker, buyer, sub-processor) were scrutinised in a 2026 telemarketing case examining controller allocation across Depurazione Acqua, Conversion Media and Unleadmited.
Claims: CLM-IT-d4e5f603
Security MeasuresAmber
The Poste Italiane/PostePay decision found the companies failed to adopt appropriate security measures for app-based device-monitoring processing.
Claims: CLM-IT-d4e5f604
Breach NotificationAmber
The Garante actively sanctions breach-notification and post-breach handling failures, including a 2026 decision against Città Metropolitana di Sassari and a separate case against a municipality for unlawful online disclosure of personal data over several years.
Claims: CLM-IT-d4e5f605
Retention And DisposalAmber
Poste Italiane/PostePay were found to have undefined retention limits and shortcomings in data-retention policy design.
Claims: CLM-IT-d4e5f606
Category narrative62 words
Accountability, DPIA, DPO, security and breach-notification duties (GDPR Arts.24-25, 30, 32-34, 35, 37-39) are heavily litigated in Italy. The 2026 Poste Italiane/PostePay decision (EUR 12.5M) illustrates DPIA, retention and security-measure failures; a Comune's failure to notify DPO data changes and unlawful online disclosure of personal data drove a separate 2026 sanction; a further breach sanction was issued against Città Metropolitana di Sassari.
Sources and claims (6)
ConfirmedDataGuidance — The Garante fined Poste Italiane S.p.A. EUR 6,624,000 and PostePay S.p.A. EUR 5,877,000 (total EUR 12,501,000) partly because the companies failed to conduct adequate data protection impact assessments regarding mandatory device-monitoring authorizations in the BancoPosta/Postepay apps.
ConfirmedGarante Privacy — The Comune di Mirabella Imbaccari was found non-compliant with GDPR partly for not communicating a change in its DPO's data to the Garante, alongside unlawful online disclosure of personal data.
ConfirmedGarante Privacy — In a 2026 telemarketing case, the Garante examined the controller/processor allocation of responsibility across a data-collection platform (Unleadmited), a data broker (Conversion Media) and an end-client (Depurazione Acqua) for marketing-data sharing.
ConfirmedDataGuidance — Poste Italiane and PostePay were found to have failed to adopt appropriate security measures in connection with mandatory device-monitoring processing represented as necessary for fraud prevention.
ProbableGarante Privacy — The Garante sanctioned Città Metropolitana di Sassari in a 2026 data-breach case, as reported in the Authority's 29 July 2026 newsletter of enforcement actions.
ConfirmedDataGuidance — The Poste Italiane/PostePay decision identified shortcomings in data-retention policies and undefined retention limits as among the compliance failures underlying the EUR 12.5M fine.
Traffic-light rationale — GreenTransfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.
Sub-modules (6)
Transfer MechanismsGreen
SCCs, BCRs, adequacy decisions and Art.49 derogations apply directly in Italy as components of the directly-applicable GDPR.
Claims: CLM-IT-e5f6a701
Adequacy ReceivedGreen
Adequacy determinations are an EU Commission competence under Art.45 GDPR, not a discrete Italian national act; no IT-specific 'received' adequacy instrument exists.
Absence provenance: Adequacy is adopted centrally by the European Commission and binds all Member States uniformly; no separate Italian determination exists.. Searched: Italy national adequacy decision GDPR.
Adequacy GrantedGreen
As with 'received' adequacy, 'granted' adequacy decisions are issued by the European Commission (Art.45), not by Italy individually.
Absence provenance: No Italy-specific adequacy-granting instrument exists; competence sits with the European Commission.. Searched: Italy grants adequacy third country.
Sccs And BcrsGreen
The Garante participates in the EU one-stop-shop mechanism for BCR approval of Italian corporate groups and applies EU Commission SCCs directly.
Claims: CLM-IT-e5f6a701
Transfer Impact AssessmentGreen
TIA obligations flow from EDPB/EU jurisprudence (Schrems II) and apply directly in Italy as part of the GDPR Art.46 framework.
Claims: CLM-IT-e5f6a701
Data LocalisationGreen
Italy's 2025 AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, indicating no general data-localisation mandate for AI-related processing.
Claims: CLM-IT-e5f6a702
Category narrative66 words
As an EU Member State, Italy applies GDPR Chapter V (Arts.44-49) transfer mechanisms directly and uniformly; adequacy decisions are an EU Commission competence exercised at Union level rather than a discrete Italian instrument, so IT-specific 'adequacy received/granted' determinations do not exist as separate national acts. Italy's new AI Law (L.132/2025) expressly permits installing AI systems on non-EU servers, indicating no blanket data-localisation mandate for AI processing.
Sources and claims (2)
ConfirmedGarante Privacy — As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.
ConfirmedIAPP — The final text of Italy's AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, ensuring continuity in cloud-infrastructure use while upholding data-protection and security standards.
Traffic-light rationale — AmberSectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.
Sub-modules (7)
Financial Sector OverlayGreen
The Garante issues opinions to the Bank of Italy on personal-data processing in banking-complaint ('esposti') management, illustrating a financial-sector consultative overlay.
Claims: CLM-IT-f6a7b801
Health Sector OverlayAmber
Health-sector data processing (hospitals, telemedicine platforms, health registries) is a recurrent enforcement and guidance focus of the Garante.
Claims: CLM-IT-f6a7b802
Telecoms And EprivacyAmber
ePrivacy/telecoms overlay operates through Art.122 Codice cookie rules and Art.130 Codice / L.5-2018 telemarketing rules enforced via the Registro Pubblico delle Opposizioni, with fines up to EUR 20M or 4% of global turnover for opposition-right violations.
Claims: CLM-IT-f6a7b803
Employment DataAmber
Employment-sector overlay (Art.4 L.300/1970, referenced by Art.114 Codice) constrains remote-monitoring technologies; the Garante ordered Amazon to stop record-keeping of workers' personal data including health, union activity and personal-life information.
Claims: CLM-IT-f6a7b804
Credit And ScoringGreen
The Garante confirmed a data subject's right to know the credit/energy score underlying a denied contract.
Claims: CLM-IT-f6a7b805
EducationGreen
The Garante has issued favourable opinions on AI-based educational platforms and guidelines for AI introduction in schools, subject to conditions.
Claims: CLM-IT-f6a7b806
InsuranceGreen
The AI Act national implementing decree introduces specific rules for the insurance sector alongside the financial sector.
Claims: CLM-IT-f6a7b807
Category narrative79 words
Sector overlays include: healthcare (frequent Garante sanctions and guidance on health data and telemedicine); telecoms/eprivacy (Art.122 Codice cookie rules, Registro Pubblico delle Opposizioni for telemarketing); employment (Art.4 Statuto dei Lavoratori/L.300-1970 constraints on remote-control technologies referenced via Art.114 Codice, e.g. the Amazon worker-monitoring order); credit/scoring (2026 Garante position affirming a right to know the score underlying a denied energy contract); education (favourable Garante opinions on AI-based educational platforms); insurance (the 2026 AI Act implementing decree introduces sector rules for insurance).
Sources and claims (7)
Probablesource not recorded — The Garante issued an opinion to the Bank of Italy on a draft regulation concerning personal-data processing in the management of banking complaints ('esposti'), illustrating its consultative role in the financial sector.
ProbableGarante Privacy — The Garante's 2026 newsletter cycle reports continued sanctioning and guidance activity in the health sector, including a hospital-operator sanction and telemedicine-platform guidance.
ConfirmedGarante Privacy — Violation of the opposition right under the Registro Pubblico delle Opposizioni regime (L.5/2018) attracts sanctions under GDPR Art.83(5), reaching up to EUR 20 million or 4% of total worldwide annual turnover of the preceding year, if higher.
ConfirmedGarante Privacy — The Garante ordered Amazon to stop record-keeping of workers' personal data, having found the company collected information on illnesses, union activity, and workers' personal and family lives.
ProbableGarante Privacy — The Garante confirmed a data subject's right to be informed of the score underlying a denied energy-supply contract, as reported in the Authority's 2026 press releases.
ConfirmedGarante Privacy — The Garante issued a favourable opinion on a Ministry of Education AI-based digital platform and accompanying guidelines for introducing AI in schools, subject to compliance observations.
ProbableGarante Privacy — Italy's AI Act national implementing decree introduces specific rules for the financial and insurance sectors alongside broader AI governance provisions.
Traffic-light rationale — AmberRules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.
Sub-modules (6)
Cookies And TrackersAmber
The 2021 Linee Guida cookie mandate a default no-cookie state on first access and ban cookie walls absent an equivalent no-consent path.
Claims: CLM-IT-a7b8c901, CLM-IT-a7b8c902
Dark PatternsAmber
A 2025 decision sanctioned a cookie banner configured so that both 'accept technical only' and 'accept all' installed the same four cookies, a dark-pattern-style design flaw.
Claims: CLM-IT-a7b8c903
Opt Out SignalsGreen
The Registro Pubblico delle Opposizioni functions as Italy's institutionalised opt-out signal for telemarketing, free to consumers and overseen by the Garante.
Claims: CLM-IT-a7b8c904
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific Garante guidance or enforcement was located in this research cycle.
Absence provenance: No dedicated Garante material on data clean rooms surfaced.. Searched: Garante clean room data collaboration room privacy.
Cross Context AdvertisingAmber
The Garante fined data-broker Lusha EUR 2 million for monitoring and selling the data of a large number of individuals, illustrating cross-context data monetisation enforcement.
Claims: CLM-IT-a7b8c905
Direct MarketingAmber
Multiple decisions (Lex Iuris, Enel Energia) sanction unconsented direct-marketing processing under Art.6(1)(a) GDPR and Art.130 Codice.
Claims: CLM-IT-a7b8c906
Category narrative63 words
Italy's cookie/tracker regime rests on the Garante's 2021 Linee Guida (Art.122 Codice + Arts.4(11),7,12,13,25 GDPR): default no non-technical cookies on first access, prohibition of cookie walls (absent an equivalent no-consent alternative), rejection of scrolling as valid consent, and a 6-month minimum before re-prompting consent. Dark-pattern-style banner manipulation, data-broker cross-context monetisation (Lusha), and unconsented direct marketing (Lex Iuris, Enel Energia) have all been sanctioned.
Sources and claims (6)
ConfirmedGarante Privacy — Under the Garante's 2021 cookie guidelines, at first website access no cookie or tracking tool other than technical ones may be positioned on a user's device by default, and no active (third-party) or passive (fingerprinting) tracking may occur without consent.
ConfirmedGarante Privacy — Cookie walls are deemed unlawful by the Garante unless the site operator provides equivalent access to content/services without requiring consent to cookies or other trackers, and re-prompting consent at every visit is considered redundant and invasive.
ConfirmedGarante Privacy — The Garante found a violation of Arts.4(11),5,7,12,13,24 and 25 GDPR and Art.122 Codice where a cookie banner was configured so that clicking either 'accept technical cookies' or 'accept all cookies' resulted in the same four cookies being installed, undermining granular consent.
ConfirmedGarante Privacy — The Registro Pubblico delle Opposizioni (RPO) is a free, institutional service allowing consumers to register fixed and mobile numbers to block telemarketing, with Garante oversight of the register's operation.
ProbableGarante Privacy — The Garante sanctioned data-broker Lusha EUR 2 million for monitoring and offering for sale the personal data of a large number of individuals.
ConfirmedGarante Privacy — The Garante fined Enel Energia EUR 26.5 million for aggressive telemarketing where consumers' data were used without consent and the accountability principle was not complied with.
Governance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.
Primary frameworkGDPR Art.22 + EU AI Act (Regulation (EU) 2024/1689) + Italian AI Law (L.132/2025) + national AI Act implementing decree
Traffic-light rationale — AmberGovernance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.
Sub-modules (6)
Profiling RestrictionsAmber
The Garante fined a Glovo-group platform EUR 2.6 million for using discriminatory rider-management algorithms.
Claims: CLM-IT-b8c9d001
Automated Decision Making TransparencyAmber
Character.AI was found to have provided insufficient information about processing operations and to have prepared its DPIA and EU-representative designation belatedly.
Claims: CLM-IT-b8c9d002
Ai Risk AssessmentsGreen
Italy's draft AI Act implementing decree designates the Garante as market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes.
Claims: CLM-IT-b8c9d003
Biometric RegimeAmber
The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects; a separate police-AI decree limits real-time remote biometric identification to specific serious-threat scenarios, though the Garante has urged strengthening biometric-database quality safeguards.
Claims: CLM-IT-b8c9d004, CLM-IT-b8c9d005
Genetic DataGreen
Genetic data receives heightened Art.9 GDPR/Art.2-septies Codice protection; no Italy-specific 2026 enforcement case was located in this cycle.
Absence provenance: No 2026 genetic-data-specific enforcement decision surfaced; general Art.9 GDPR/Art.2-septies Codice protection applies.. Searched: Garante dati genetici sanzione 2026.
State Surveillance CarveoutsAmber
Italy's police-AI decree permits real-time remote biometric identification only to confirm identity or locate specifically identified/identifiable individuals in relation to serious threats or missing-persons searches, per the AI Act (Art.5) framework.
Claims: CLM-IT-b8c9d005
Category narrative71 words
The Garante has been designated national market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes under Italy's AI Act implementing decree, while retaining full GDPR competence over any AI activity processing personal data. Enforcement precedent spans algorithmic-discrimination (Glovo riders), biometric/facial-recognition bans (Clearview AI), and transparency/DPIA failures in generative-AI chatbots (Character.AI). A separate police-use-of-AI decree restricts real-time remote biometric identification to narrowly defined serious-threat/missing-person scenarios.
Sources and claims (5)
ConfirmedGarante Privacy — The Garante fined a platform in the Glovo group EUR 2.6 million for using algorithms that caused discrimination among riders.
ConfirmedGarante Privacy — In fining Character Technologies Inc. EUR 158,000, the Garante found deficiencies in the information provided to users and that the DPIA and EU-representative designation were carried out belatedly.
ProbableGarante Privacy — Italy's AI Act implementing decree designates the Garante as the market-surveillance authority for high-risk AI systems used in justice, law-enforcement, immigration, border-management and democratic-process contexts.
ConfirmedGarante Privacy — The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects.
ProbableGarante Privacy — Italy's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.
Age-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.
Traffic-light rationale — AmberAge-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.
Sub-modules (5)
Age VerificationAmber
Character.AI was ordered to guarantee correctly functioning age-verification systems, a 'cooling-off' mechanism against repeat registration by blocked minors, and default-private profiles for minors.
Claims: CLM-IT-c9d0e101
Parental ConsentGreen
Below age 14, the Codice requires consent from whoever exercises parental responsibility for information-society-service processing to be lawful.
Claims: CLM-IT-c9d0e102
Minor Profiling BansAmber
The Garante blocked TikTok's processing where the platform could not verify user age, holding that consent/contract from under-14s is invalid and thus devoid of any legal basis for further processing including profiling.
Claims: CLM-IT-c9d0e103
Education SettingsGreen
School information notices must be easily comprehensible to minors and are subject to Garante prior review for AI-based educational platforms.
Claims: CLM-IT-c9d0e104
Dependent AdultsRed
No dedicated dependent-adults (elderly/incapacitated persons) data-protection regime distinct from general GDPR safeguards was located in this research cycle.
Absence provenance: No dedicated dependent-adults data-protection guidance or enforcement item surfaced in this pass.. Searched: Garante privacy anziani incapaci tutela dati personali 2026.
Category narrative57 words
The Italian digital age of consent is 14 (Codice Privacy Art.2-quinquies), below which parental/guardian consent is required for information-society services; below-14 consent is invalid absent parental authorisation, as applied in TikTok and social-media minor-image cases. Age-verification and default-privacy settings for minors were central to the 2026 Character.AI sanction. No dedicated dependent-adults (elderly/incapacitated) regime was identified this cycle.
Sources and claims (4)
ConfirmedGarante Privacy — The Garante required Character Technologies to guarantee correctly functioning age-verification systems, ensure effective 'cooling-off' mechanisms preventing renewed registration attempts by blocked minors, and set minors' profiles to private by default.
ConfirmedGarante Privacy — Under Art.2-quinquies of the Codice, implementing Art.8(1) GDPR, a minor who has reached 14 years of age may validly consent to processing of their personal data in relation to information-society services; below that age, consent must be given by whoever exercises parental responsibility.
ConfirmedGarante Privacy / Agenda Digitale — The Garante held that where a platform cannot verify a user's age, any consent or contract entered into by an under-14 user is invalid, leaving any associated processing (including for commercial/profiling purposes) devoid of a legal basis.
ConfirmedGarante Privacy — The Garante issued a favourable opinion on a Ministry of Education AI-service scheme and accompanying guidelines for introducing AI in schools, requiring information notices to be easily comprehensible to minors.
High-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.
Traffic-light rationale — GreenHigh-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Garante exercises full Art.58(2) GDPR corrective powers; internal Reg.1/2019 was amended in March 2026 to delegate certain time-barred/low-impact corrective measures to departmental directors, excluding journalistic, political/union, high-turnover, and major-public-body cases.
Claims: CLM-IT-d0e1f201
Enforcement Activity IndexGreen
In 2025 the Garante adopted 807 collegial decisions and handled 4,288 complaints and 145,846 reports; 2026 saw multiple 7-figure fines (Poste Italiane/PostePay, Lusha) alongside smaller sanctions (Piaggio, Altroconsumo, Character.AI).
Claims: CLM-IT-d0e1f202
Regulator Funding And CapacityAmber
Public information on current-year Garante staffing/budget levels is limited in this research pass; historically the Authority has supplemented its inspection capacity with seconded Guardia di Finanza personnel.
Absence provenance: Current-year (2025/2026) headcount/budget figures were not located; only a historical (2008) administrative report referencing Guardia di Finanza secondment surfaced.. Searched: Garante privacy organico personale bilancio 2025 relazione annuale risorse.
Collective Redress And Class ActionsAmber
No GDPR-specific Italian collective-redress case was located in this cycle; general azione di classe mechanisms under the Codice del Consumo remain the available collective-litigation route.
Absence provenance: No 2026 GDPR-specific class-action decision surfaced in this research pass.. Searched: Garante privacy azione di classe class action GDPR Italia 2026.
Private Right Of ActionGreen
Data subjects may oppose Garante sanction orders before the ordinary judiciary within 30 days (60 if residing abroad) under Art.152 Codice/Art.10 D.Lgs.150/2011 and Art.78 GDPR.
Claims: CLM-IT-d0e1f203
Recent Developments 180DGreen
Within the last 180 days: the Garante fined Character.AI (3 July 2026), gave a conditioned favourable opinion on the national AI Act implementing decree (29 July 2026) while flagging biometric-safeguard gaps, sanctioned Piaggio (EUR 460k) and Altroconsumo (EUR 280k), sanctioned Città Metropolitana di Sassari for a data breach, and presented its 2025 Annual Report to Parliament (2 July 2026).
Claims: CLM-IT-d0e1f204
Category narrative116 words
The Garante wields full GDPR Art.58 corrective powers (warnings, orders, bans, fines up to EUR 20M/4% global turnover) and delegated internal procedures (Reg. 1/2019) for time-barred/low-impact cases. 2025 activity: 807 collegial decisions, 4,288 complaints and 145,846 reports handled, and 65 opinions issued on regulatory/administrative measures. Recent months show sustained high-value enforcement (Poste Italiane/PostePay EUR 12.5M, Character.AI EUR 158k, Lusha EUR 2M, Piaggio EUR 460k, Altroconsumo EUR 280k) and judicial pushback (a March 2026 sanction order was suspended by the Tribunale di Roma). No dedicated GDPR-based class-action/collective-redress statistic was identified distinct from the general Italian collective-action (azione di classe) mechanism under Art.140-bis Codice del Consumo; individual judicial opposition to Garante orders is available under Art.152 Codice/Art.78 GDPR.
Sources and claims (4)
ConfirmedGarante Privacy — A March 2026 amendment to Garante Regulation 1/2019 delegates adoption of certain Art.58(2)(b) corrective measures to departmental directors for time-barred or fully-remedied conduct, expressly excluding journalistic-sector, political/union-rights, high-turnover (>EUR 500,000) and major public-body cases from the delegation.
ConfirmedGarante Privacy — In 2025 the Garante adopted 807 collegial decisions, responded to 4,288 complaints and 145,846 reports, and issued 65 opinions on regulatory and administrative measures spanning public-administration digitalisation, healthcare, tax and justice.
ConfirmedGarante Privacy — A Garante sanction order may be opposed before the ordinary courts, via petition filed within 30 days of notification (60 days if the appellant resides abroad), under Art.152 of the Codice, Art.10 of D.Lgs.150/2011 and Art.78 GDPR.
ConfirmedGarante Privacy — On 29 July 2026 the Garante gave a favourable opinion on the AI Act national implementing decree while asking for clarified human-oversight rules, clearer research/experimentation responsibilities, its own involvement in the Italian AI regulatory sandbox, and strengthened guarantees on biometric-database quality.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Italy
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 25 source(s) in the cumulative register.