🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
IT v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing25 sources retrieved model claude-sonnet-5 · 2026-08-03

Italy

IT schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 46 claims · 36 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
23Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 2 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Italy's Garante has moved decisively on the intersection of AI governance and data protection this cycle. The regulator gave a favourable opinion on Italy's draft legislative decree implementing the EU AI Act, a step that would designate the Garante as market-surveillance authority for high-risk AI systems deployed in justice, law-enforcement, immigration and border-management, and democratic-process contexts. This is the most material development of the cycle: it would extend the Garante's institutional remit well beyond its existing GDPR mandate into direct AI-systems oversight in some of the most sensitive application domains, though the decree itself remains at the proposed stage and has not yet been enacted.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.

Primary frameworkGDPR (Regulation (EU) 2016/679) + Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)
Traffic-light rationale — GreenMature, fully-operational omnibus regime with an active, well-resourced supervisory authority and dense enforcement caseload.

Sub-modules (5)

Regulator And AuthorityGreen

The Garante is Italy's independent DPA, based only in Rome, designated GDPR Art.51 supervisory authority.

Claims (1):

  • The Garante per la protezione dei dati personali is Italy's independent administrative authority, established by Law No. 675/1996 and subsequently regulated by the Codice Privacy, designated as GDPR Art.51 supervisory authority and based only in Rome.

Act And InstrumentsGreen

GDPR applies directly; Codice Privacy (D.Lgs.196/2003) as amended by D.Lgs.101/2018 is the national implementing/adapting act.

Claims (1):

  • GDPR (Regulation (EU) 2016/679) applies directly in Italy and is implemented/adapted via the Codice Privacy (D.Lgs. 196/2003) as amended by D.Lgs. 101/2018.

Material ScopeGreen

Material scope follows GDPR directly as an EU Regulation; Codice provisions (e.g. 2-septies, 2-decies) supplement special-category and remedies rules.

Claims (1):

  • Garante decisions consistently apply GDPR material-scope concepts (Art.4(2) processing, including dissemination) requiring a lawful basis for any processing operation under Italian law.

Territorial ScopeGreen

GDPR Art.3 territorial scope applies uniformly in Italy as directly-applicable EU law; non-EU providers (e.g. Character Technologies/US) have been pursued by the Garante including EU-representative designation failures.

Claims (1):

  • The Garante exercised jurisdiction over Character Technologies Inc. (a US company operating Character.AI), citing among other violations a delayed designation of its EU representative, confirming extraterritorial application of GDPR to non-EU controllers targeting Italian users.

Regulator Registration And FilingAmber

No general controller registration regime; residual duty to notify the Garante of DPO data changes, breach of which has been separately sanctioned.

Claims (1):

  • A public-sector controller (Comune di Mirabella Imbaccari) was sanctioned in part for failing to communicate a change of its DPO's data to the Garante, evidencing a binding filing obligation regarding DPO contact information.
Category narrative57 words

Italy is an EU Member State applying GDPR directly, supervised by the Garante per la protezione dei dati personali, seated in Rome, operating under the Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) which adapts national law to GDPR. No general controller registration/notification regime survives GDPR; residual filing duties concern DPO contact-data communication to the Garante.

Sources and claims (5)
  1. ConfirmedGarante Privacy — The Garante per la protezione dei dati personali is Italy's independent administrative authority, established by Law No. 675/1996 and subsequently regulated by the Codice Privacy, designated as GDPR Art.51 supervisory authority and based only in Rome.observed
  2. ConfirmedGarante Privacy — GDPR (Regulation (EU) 2016/679) applies directly in Italy and is implemented/adapted via the Codice Privacy (D.Lgs. 196/2003) as amended by D.Lgs. 101/2018.observed
  3. ConfirmedGarante Privacy — Garante decisions consistently apply GDPR material-scope concepts (Art.4(2) processing, including dissemination) requiring a lawful basis for any processing operation under Italian law.observed
  4. ConfirmedGarante Privacy — The Garante exercised jurisdiction over Character Technologies Inc. (a US company operating Character.AI), citing among other violations a delayed designation of its EU representative, confirming extraterritorial application of GDPR to non-EU controllers targeting Italian users.observed
  5. ConfirmedGarante Privacy — A public-sector controller (Comune di Mirabella Imbaccari) was sanctioned in part for failing to communicate a change of its DPO's data to the Garante, evidencing a binding filing obligation regarding DPO contact information.observed

#

Core lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.

Primary frameworkGDPR Arts. 6, 7, 9 + Codice Privacy Artt. 2-sexies, 2-septies, 2-quinquies
Traffic-light rationale — GreenCore lawful-basis and special-category doctrine is settled and actively enforced; anonymisation-specific guidance coverage is thinner.

Sub-modules (4)

Lawful BasesGreen

Garante enforcement confirms Art.6 GDPR consent/legitimate-interest requirements, e.g. sanctioning promotional emails sent absent consent or another suitable legal basis.

Claims (1):

  • The Garante fined a law firm for sending promotional emails absent consent and absent any other suitable lawful basis, in violation of Art.6(1)(a) GDPR and Art.130(2) of the Codice.

Special CategoriesGreen

The Garante applies a broad reading of special-category/health data, extending protection even to indirect health indicators such as sickness-absence records.

Claims (1):

  • Under settled Garante case law, the notion of health-related personal data extends even to information about an employee's absence from service for illness, independent of whether a specific diagnosis is disclosed.

Pseudonymisation And AnonymisationAmber

No dedicated Garante pseudonymisation/anonymisation guidance surfaced in this research cycle; GDPR Art.4(5)/Art.25 concepts apply by default as directly-applicable EU law.

Absence provenance: No Garante-specific anonymisation/pseudonymisation guideline document was returned; only general references within AI-training case files.. Searched: Garante anonymisation pseudonymisation guidance Italy.

Category narrative61 words

Lawful bases follow GDPR Art.6 as construed by the Garante (consent, contract, legal obligation, legitimate interest); consent for marketing/telemarketing must be freely given, specific, and revocable at any time. Special categories (Art.9) receive heightened protection under Codice Art. 2-septies, with a broad interpretation of 'health data' extended even to sickness-absence notices. Dedicated pseudonymisation/anonymisation guidance was not located in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedGarante Privacy — The Garante fined a law firm for sending promotional emails absent consent and absent any other suitable lawful basis, in violation of Art.6(1)(a) GDPR and Art.130(2) of the Codice.observed
  2. ConfirmedGarante Privacy — Consent to marketing communication in Italy must be documentable in writing to the Garante and can, in any event, always be withdrawn by the data subject at any time.observed
  3. ConfirmedGarante Privacy — Under settled Garante case law, the notion of health-related personal data extends even to information about an employee's absence from service for illness, independent of whether a specific diagnosis is disclosed.observed

#

Rights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.

Primary frameworkGDPR Arts. 12, 15-22 + Codice Privacy Artt. 2-decies, 130
Traffic-light rationale — GreenRights framework is GDPR-aligned and actively enforced with concrete recent case law on response deadlines and opposition rights.

Sub-modules (5)

Access RightGreen

Access and other Art.15-22 rights must receive an adequate, timely response under Art.12; failure led to a formal admonishment in a 2026 decision.

Claims (1):

  • The Garante issued a formal admonishment under Art.58(2)(b) GDPR against a controller for failing to comply with Art.12 obligations to provide an adequate and timely response to rights exercised under Arts.15-22 GDPR.

Rectification And ErasureGreen

Erasure/rectification obligations (Art.16-17 GDPR) are enforced, e.g. in minor-image publication cases requiring takedown upon parental request.

Claims (1):

  • The Garante has repeatedly ordered controllers/individuals to cease further processing of a minor's image absent both parents' consent, treating unlawful publication as requiring takedown under Art.17(1)(d) GDPR.

Restriction And ObjectionGreen

The right to object to direct-marketing processing is operationalised nationally via the Registro Pubblico delle Opposizioni (RPO); failure to timely register an opposition has been sanctioned.

Claims (1):

  • A telemarketing company was sanctioned for failing to timely register a data subject's opposition made via formal notice, despite repeated follow-up, confirming the RPO/objection mechanism as an enforceable data-subject right.

Data PortabilityGreen

Portability (Art.20 GDPR) applies directly as EU law; no Italy-specific derogation identified in this cycle.

Absence provenance: No dedicated Garante portability guidance/enforcement item surfaced in this pass; general GDPR Art.20 applies.. Searched: Garante data portability guidance Italy 2026.

Deadlines And Response WindowsGreen

Controllers must provide adequate and timely responses to rights requests under Art.12; the Garante has rejected staff-absence (holiday period) as an excuse for delay.

Claims (1):

  • The Garante held that a company's summer holiday period could not excuse a controller from its ongoing obligation to respond to data-subject rights requests without undue delay.
Category narrative43 words

Garante enforcement gives operative content to Arts.12 and 15-22 GDPR, requiring an adequate and timely response to rights requests, sanctioning controllers (including via formal admonishment) for delayed or absent responses, and treating opposition/telemarketing-suppression requests (Registro Pubblico delle Opposizioni) as an enforceable objection mechanism.

Sources and claims (4)
  1. ConfirmedGarante Privacy — The Garante issued a formal admonishment under Art.58(2)(b) GDPR against a controller for failing to comply with Art.12 obligations to provide an adequate and timely response to rights exercised under Arts.15-22 GDPR.observed
  2. ConfirmedGarante Privacy — The Garante has repeatedly ordered controllers/individuals to cease further processing of a minor's image absent both parents' consent, treating unlawful publication as requiring takedown under Art.17(1)(d) GDPR.observed
  3. ConfirmedGarante Privacy — A telemarketing company was sanctioned for failing to timely register a data subject's opposition made via formal notice, despite repeated follow-up, confirming the RPO/objection mechanism as an enforceable data-subject right.observed
  4. ConfirmedGarante Privacy — The Garante held that a company's summer holiday period could not excuse a controller from its ongoing obligation to respond to data-subject rights requests without undue delay.observed

#

Framework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.

Primary frameworkGDPR Arts. 24, 25, 30, 32-34, 35, 37-39 + Codice Privacy Artt. 2-quaterdecies, 166
Traffic-light rationale — AmberFramework is GDPR-aligned and enforced robustly, but repeated large fines for DPIA/retention/security gaps (Poste Italiane, public-sector breaches) indicate ongoing compliance friction.

Sub-modules (7)

Accountability And DpiaAmber

Poste Italiane and PostePay were fined EUR 12.5M in April 2026 in part for failing to conduct adequate DPIAs.

Claims (1):

  • The Garante fined Poste Italiane S.p.A. EUR 6,624,000 and PostePay S.p.A. EUR 5,877,000 (total EUR 12,501,000) partly because the companies failed to conduct adequate data protection impact assessments regarding mandatory device-monitoring authorizations in the BancoPosta/Postepay apps.

Dpo RequirementsAmber

Controllers must communicate DPO data/changes to the Garante; a municipality's failure to do so contributed to a 2026 sanction.

Claims (1):

  • The Comune di Mirabella Imbaccari was found non-compliant with GDPR partly for not communicating a change in its DPO's data to the Garante, alongside unlawful online disclosure of personal data.

Ropa RequirementsGreen

Art.30 GDPR ROPA duties apply directly as EU law; no Italy-specific ROPA enforcement case was located in this cycle.

Absence provenance: No dedicated ROPA-specific enforcement decision surfaced in this pass.. Searched: Garante ROPA registro delle attività di trattamento sanzione.

Joint Controller ArrangementsAmber

Marketing-data supply chains involving multiple controllers (data broker, buyer, sub-processor) were scrutinised in a 2026 telemarketing case examining controller allocation across Depurazione Acqua, Conversion Media and Unleadmited.

Claims (1):

  • In a 2026 telemarketing case, the Garante examined the controller/processor allocation of responsibility across a data-collection platform (Unleadmited), a data broker (Conversion Media) and an end-client (Depurazione Acqua) for marketing-data sharing.

Security MeasuresAmber

The Poste Italiane/PostePay decision found the companies failed to adopt appropriate security measures for app-based device-monitoring processing.

Claims (1):

  • Poste Italiane and PostePay were found to have failed to adopt appropriate security measures in connection with mandatory device-monitoring processing represented as necessary for fraud prevention.

Breach NotificationAmber

The Garante actively sanctions breach-notification and post-breach handling failures, including a 2026 decision against Città Metropolitana di Sassari and a separate case against a municipality for unlawful online disclosure of personal data over several years.

Claims (1):

  • The Garante sanctioned Città Metropolitana di Sassari in a 2026 data-breach case, as reported in the Authority's 29 July 2026 newsletter of enforcement actions.

Retention And DisposalAmber

Poste Italiane/PostePay were found to have undefined retention limits and shortcomings in data-retention policy design.

Claims (1):

  • The Poste Italiane/PostePay decision identified shortcomings in data-retention policies and undefined retention limits as among the compliance failures underlying the EUR 12.5M fine.
Category narrative62 words

Accountability, DPIA, DPO, security and breach-notification duties (GDPR Arts.24-25, 30, 32-34, 35, 37-39) are heavily litigated in Italy. The 2026 Poste Italiane/PostePay decision (EUR 12.5M) illustrates DPIA, retention and security-measure failures; a Comune's failure to notify DPO data changes and unlawful online disclosure of personal data drove a separate 2026 sanction; a further breach sanction was issued against Città Metropolitana di Sassari.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Garante's Provvedimento n. 237, dated 17 April 2026, sanctioned Poste Italiane and its PostePay division for unlawful monitoring of applications installed on users' Android devices. This matter falls squarely within the controller/processor duties framework because it turns on the adequacy of security-of-processing measures and the accountability obligations that attach to a controller operating consumer-facing mobile applications. Monitoring the applications installed on a user's device, beyond what is necessary for the stated purpose of the service being provided, raises questions of purpose limitation and data minimisation that sit at the heart of the controller's accountability obligations under the framework the Garante enforces.

While the sanction itself is reported at a probable confidence level, drawing on a secondary summary rather than direct retrieval of the full text of Provvedimento n. 237, the underlying pattern is consistent with the Garante's established enforcement posture toward large consumer-facing financial and postal-services groups: security-of-processing failures involving device-level data collection have previously drawn Garante attention, and this action continues that pattern. The involvement of PostePay, a payment-services brand operating under the broader Poste Italiane group, places the matter within a sector where the Garante has historically maintained close scrutiny given the scale of the consumer base involved.

For controllers operating consumer mobile applications in Italy, the practical implication is that monitoring practices extending to the broader set of applications installed on a user's device, rather than being confined to the data strictly necessary for the service's own functionality, present a live enforcement risk. The accountability principle requires that any such monitoring be justified by a documented, proportionate purpose and be transparent to the data subject; absent that justification, the Garante has shown itself willing to sanction on exactly this fact pattern.

Outlook

The Poste Italiane/PostePay sanction should be read as a signal that the Garante continues to treat device-level application monitoring as a live enforcement priority within its broader controller/processor duties remit. Operators of consumer-facing mobile applications in the Italian market, particularly within financial and postal services, should expect continuing scrutiny of similar monitoring practices. No further detail on the full scope or remedial requirements of Provvedimento n. 237 was available in the sources reviewed this cycle, and confirmation from a primary Garante publication would strengthen the evidentiary basis for this finding in a future cycle.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Controller/Processor Duties

The Garante's controller/processor duties enforcement this cycle centres on data-minimisation and retention accountability. On 24 February 2026, the Garante issued an order concerning Amazon worker-data record-keeping practices, addressing excess data retention in the employment context. Separately, on 29 April 2026, the Garante issued guidance against accommodation providers retaining copies of guest identity documents, a similar retention-minimisation intervention in the hospitality sector. Both are Probable-confidence findings, sourced from the Garante's own Tier-1 press-room index, though the full text of the underlying provvedimenti was not retrieved this cycle, which limits the granularity of what can be reported about the specific corrective measures ordered in each case.

Taken together, these two orders confirm active accountability and data-minimisation enforcement by the Garante across at least two distinct sectors, employment and hospitality, within a single reporting window. This pattern is consistent with tightening in this module's trajectory, reflecting a regulator actively testing retention practices against the GDPR's data-minimisation and storage-limitation principles rather than confining enforcement attention to breach-notification or consent failures alone.

Outlook

Watch for the full text of both the Amazon worker-data order and the accommodation-provider guidance to become available, which would allow a more granular assessment of what data-retention thresholds the Garante is now applying, and for whether this retention-focused enforcement pattern extends to further sectors in the coming cycle.

Sources and claims (6)
  1. ConfirmedDataGuidance — The Garante fined Poste Italiane S.p.A. EUR 6,624,000 and PostePay S.p.A. EUR 5,877,000 (total EUR 12,501,000) partly because the companies failed to conduct adequate data protection impact assessments regarding mandatory device-monitoring authorizations in the BancoPosta/Postepay apps.observed
  2. ConfirmedGarante Privacy — The Comune di Mirabella Imbaccari was found non-compliant with GDPR partly for not communicating a change in its DPO's data to the Garante, alongside unlawful online disclosure of personal data.observed
  3. ConfirmedGarante Privacy — In a 2026 telemarketing case, the Garante examined the controller/processor allocation of responsibility across a data-collection platform (Unleadmited), a data broker (Conversion Media) and an end-client (Depurazione Acqua) for marketing-data sharing.observed
  4. ConfirmedDataGuidance — Poste Italiane and PostePay were found to have failed to adopt appropriate security measures in connection with mandatory device-monitoring processing represented as necessary for fraud prevention.observed
  5. ProbableGarante Privacy — The Garante sanctioned Città Metropolitana di Sassari in a 2026 data-breach case, as reported in the Authority's 29 July 2026 newsletter of enforcement actions.observed
  6. ConfirmedDataGuidance — The Poste Italiane/PostePay decision identified shortcomings in data-retention policies and undefined retention limits as among the compliance failures underlying the EUR 12.5M fine.observed

#

Transfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.

Primary frameworkGDPR Arts. 44-49 (directly applicable EU Regulation)
Traffic-light rationale — GreenTransfer mechanisms are fully harmonised at EU level and directly applicable; no Italy-specific localisation barrier identified for AI systems.

Sub-modules (6)

Transfer MechanismsGreen

SCCs, BCRs, adequacy decisions and Art.49 derogations apply directly in Italy as components of the directly-applicable GDPR.

Claims (1):

  • As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.

Adequacy ReceivedGreen

Adequacy determinations are an EU Commission competence under Art.45 GDPR, not a discrete Italian national act; no IT-specific 'received' adequacy instrument exists.

Absence provenance: Adequacy is adopted centrally by the European Commission and binds all Member States uniformly; no separate Italian determination exists.. Searched: Italy national adequacy decision GDPR.

Adequacy GrantedGreen

As with 'received' adequacy, 'granted' adequacy decisions are issued by the European Commission (Art.45), not by Italy individually.

Absence provenance: No Italy-specific adequacy-granting instrument exists; competence sits with the European Commission.. Searched: Italy grants adequacy third country.

Sccs And BcrsGreen

The Garante participates in the EU one-stop-shop mechanism for BCR approval of Italian corporate groups and applies EU Commission SCCs directly.

Claims (1):

  • As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.

Transfer Impact AssessmentGreen

TIA obligations flow from EDPB/EU jurisprudence (Schrems II) and apply directly in Italy as part of the GDPR Art.46 framework.

Claims (1):

  • As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.

Data LocalisationGreen

Italy's 2025 AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, indicating no general data-localisation mandate for AI-related processing.

Claims (1):

  • The final text of Italy's AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, ensuring continuity in cloud-infrastructure use while upholding data-protection and security standards.
Category narrative66 words

As an EU Member State, Italy applies GDPR Chapter V (Arts.44-49) transfer mechanisms directly and uniformly; adequacy decisions are an EU Commission competence exercised at Union level rather than a discrete Italian instrument, so IT-specific 'adequacy received/granted' determinations do not exist as separate national acts. Italy's new AI Law (L.132/2025) expressly permits installing AI systems on non-EU servers, indicating no blanket data-localisation mandate for AI processing.

Sources and claims (2)
  1. ConfirmedGarante Privacy — As GDPR is directly applicable EU law in Italy, Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art.49 derogations) apply uniformly without a separate Italian transposition act.observed
  2. ConfirmedIAPP — The final text of Italy's AI Law confirms the possibility of installing AI systems on servers located outside the EU for both public and private use, ensuring continuity in cloud-infrastructure use while upholding data-protection and security standards.observed

#

Sectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.

Primary frameworkGDPR + Codice Privacy sectoral provisions (Artt.114, 122, 130) + Statuto dei Lavoratori (L.300/1970) + AI Act national implementing decree
Traffic-light rationale — AmberSectoral overlays are well documented and enforced, but employment/telecoms marketing overlays show recurrent, material non-compliance.

Sub-modules (7)

Financial Sector OverlayGreen

The Garante issues opinions to the Bank of Italy on personal-data processing in banking-complaint ('esposti') management, illustrating a financial-sector consultative overlay.

Claims (1):

  • The Garante issued an opinion to the Bank of Italy on a draft regulation concerning personal-data processing in the management of banking complaints ('esposti'), illustrating its consultative role in the financial sector.

Health Sector OverlayAmber

Health-sector data processing (hospitals, telemedicine platforms, health registries) is a recurrent enforcement and guidance focus of the Garante.

Claims (1):

  • The Garante's 2026 newsletter cycle reports continued sanctioning and guidance activity in the health sector, including a hospital-operator sanction and telemedicine-platform guidance.

Telecoms And EprivacyAmber

ePrivacy/telecoms overlay operates through Art.122 Codice cookie rules and Art.130 Codice / L.5-2018 telemarketing rules enforced via the Registro Pubblico delle Opposizioni, with fines up to EUR 20M or 4% of global turnover for opposition-right violations.

Claims (1):

  • Violation of the opposition right under the Registro Pubblico delle Opposizioni regime (L.5/2018) attracts sanctions under GDPR Art.83(5), reaching up to EUR 20 million or 4% of total worldwide annual turnover of the preceding year, if higher.

Employment DataAmber

Employment-sector overlay (Art.4 L.300/1970, referenced by Art.114 Codice) constrains remote-monitoring technologies; the Garante ordered Amazon to stop record-keeping of workers' personal data including health, union activity and personal-life information.

Claims (1):

  • The Garante ordered Amazon to stop record-keeping of workers' personal data, having found the company collected information on illnesses, union activity, and workers' personal and family lives.

Credit And ScoringGreen

The Garante confirmed a data subject's right to know the credit/energy score underlying a denied contract.

Claims (1):

  • The Garante confirmed a data subject's right to be informed of the score underlying a denied energy-supply contract, as reported in the Authority's 2026 press releases.

EducationGreen

The Garante has issued favourable opinions on AI-based educational platforms and guidelines for AI introduction in schools, subject to conditions.

Claims (1):

  • The Garante issued a favourable opinion on a Ministry of Education AI-based digital platform and accompanying guidelines for introducing AI in schools, subject to compliance observations.

InsuranceGreen

The AI Act national implementing decree introduces specific rules for the insurance sector alongside the financial sector.

Claims (1):

  • Italy's AI Act national implementing decree introduces specific rules for the financial and insurance sectors alongside broader AI governance provisions.
Category narrative79 words

Sector overlays include: healthcare (frequent Garante sanctions and guidance on health data and telemedicine); telecoms/eprivacy (Art.122 Codice cookie rules, Registro Pubblico delle Opposizioni for telemarketing); employment (Art.4 Statuto dei Lavoratori/L.300-1970 constraints on remote-control technologies referenced via Art.114 Codice, e.g. the Amazon worker-monitoring order); credit/scoring (2026 Garante position affirming a right to know the score underlying a denied energy contract); education (favourable Garante opinions on AI-based educational platforms); insurance (the 2026 AI Act implementing decree introduces sector rules for insurance).

Periodic update · new data 2026-09-28

Sectoral Watch

The Garante's inspection plan for the second half of 2026 identifies at least 35 inspections to be conducted between August and December. The plan marks a deliberate shift in sectoral focus: AI-system checks, which had previously concentrated on the education sector and schools specifically, are being redirected toward municipalities, local health authorities (ASL), geomarketing, neuromarketing, dynamic pricing, and DPO-supplier relationships. This redirection signals that the Garante's sectoral enforcement priorities for the remainder of 2026 are moving away from education-sector AI deployments and toward public-administration bodies and commercial pricing/marketing-technology practices that involve algorithmic processing of consumer or citizen data.

The inclusion of municipalities and local health authorities as inspection targets is notable because it extends the Garante's practical sectoral attention into public-sector bodies that increasingly deploy AI-assisted systems for service delivery and resource allocation, sectors that had not previously been named as a discrete inspection priority. Similarly, the explicit naming of geomarketing, neuromarketing and dynamic pricing as inspection targets reflects a sectoral focus on commercial practices that use behavioural or location data to shape consumer-facing pricing or marketing decisions, an area where AI-driven personalisation techniques raise the kind of profiling and transparency questions the Garante has flagged in other contexts this cycle.

This sectoral shift should be read alongside the broader enforcement-and-redress picture for the cycle, in which two concrete sanctions (Poste Italiane/PostePay and Altroconsumo Edizioni) were already recorded; the expanded inspection programme suggests the Garante intends to sustain, rather than taper, its practical enforcement tempo through the remainder of 2026, with AI systems and public-sector/commercial-marketing practices as the named sectoral targets.

Outlook

Operators in the named sectors, particularly municipalities, local health authorities, and providers of geomarketing, neuromarketing, or dynamic-pricing technology serving Italian consumers, should treat the August-December 2026 window as a period of elevated inspection risk. The DPO-supplier relationship focus also suggests that outsourced data-protection-officer arrangements will receive specific scrutiny during this period. No further detail on the specific inspection criteria or expected enforcement outcomes was available in the sources reviewed this cycle.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Sectoral Watch

Italy's telecoms and e-privacy sectoral overlay was confirmed applicable to a new use case this cycle: Codice Privacy Article 130(1) requires opt-in consent for automated calling systems, and this requirement is confirmed to extend to AI voice agents specifically. An opt-out mechanism such as the Registro delle Opposizioni (RPO) list is explicitly insufficient to satisfy this opt-in requirement, an Assessed-confidence finding sourced from the Garante's own Tier-1 guidance on artificial intelligence.

This finding is significant because it closes a potential ambiguity as automated calling technology increasingly incorporates generative AI voice capabilities: the existing sectoral telecoms consent standard, rather than being displaced or superseded by AI-specific rules, is confirmed to continue applying in full to AI-driven calling systems. Businesses deploying AI voice agents for outbound calling in Italy therefore cannot rely on opt-out registration alone and must secure affirmative opt-in consent under the existing Article 130(1) standard.

Outlook

Watch for whether the Garante issues further sector-specific guidance applying existing telecoms and e-privacy standards to other AI-driven communication channels, and for any enforcement action testing compliance with the opt-in standard specifically in the context of AI voice agents.

Sources and claims (7)
  1. Probableunavailable — The Garante issued an opinion to the Bank of Italy on a draft regulation concerning personal-data processing in the management of banking complaints ('esposti'), illustrating its consultative role in the financial sector.
  2. ProbableGarante Privacy — The Garante's 2026 newsletter cycle reports continued sanctioning and guidance activity in the health sector, including a hospital-operator sanction and telemedicine-platform guidance.observed
  3. ConfirmedGarante Privacy — Violation of the opposition right under the Registro Pubblico delle Opposizioni regime (L.5/2018) attracts sanctions under GDPR Art.83(5), reaching up to EUR 20 million or 4% of total worldwide annual turnover of the preceding year, if higher.observed
  4. ConfirmedGarante Privacy — The Garante ordered Amazon to stop record-keeping of workers' personal data, having found the company collected information on illnesses, union activity, and workers' personal and family lives.observed
  5. ProbableGarante Privacy — The Garante confirmed a data subject's right to be informed of the score underlying a denied energy-supply contract, as reported in the Authority's 2026 press releases.observed
  6. ConfirmedGarante Privacy — The Garante issued a favourable opinion on a Ministry of Education AI-based digital platform and accompanying guidelines for introducing AI in schools, subject to compliance observations.observed
  7. ProbableGarante Privacy — Italy's AI Act national implementing decree introduces specific rules for the financial and insurance sectors alongside broader AI governance provisions.observed

#

Rules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.

Primary frameworkePrivacy Directive 2002/58/EC as transposed by Art.122 Codice Privacy + GDPR Arts.4(11),6,7,12,13,25
Traffic-light rationale — AmberRules are clear and mature but enforcement volume against cookie-banner manipulation and unconsented marketing remains high.

Sub-modules (6)

Cookies And TrackersAmber

The 2021 Linee Guida cookie mandate a default no-cookie state on first access and ban cookie walls absent an equivalent no-consent path.

Claims (2):

  • Under the Garante's 2021 cookie guidelines, at first website access no cookie or tracking tool other than technical ones may be positioned on a user's device by default, and no active (third-party) or passive (fingerprinting) tracking may occur without consent.
  • Cookie walls are deemed unlawful by the Garante unless the site operator provides equivalent access to content/services without requiring consent to cookies or other trackers, and re-prompting consent at every visit is considered redundant and invasive.

Dark PatternsAmber

A 2025 decision sanctioned a cookie banner configured so that both 'accept technical only' and 'accept all' installed the same four cookies, a dark-pattern-style design flaw.

Claims (1):

  • The Garante found a violation of Arts.4(11),5,7,12,13,24 and 25 GDPR and Art.122 Codice where a cookie banner was configured so that clicking either 'accept technical cookies' or 'accept all cookies' resulted in the same four cookies being installed, undermining granular consent.

Opt Out SignalsGreen

The Registro Pubblico delle Opposizioni functions as Italy's institutionalised opt-out signal for telemarketing, free to consumers and overseen by the Garante.

Claims (1):

  • The Registro Pubblico delle Opposizioni (RPO) is a free, institutional service allowing consumers to register fixed and mobile numbers to block telemarketing, with Garante oversight of the register's operation.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific Garante guidance or enforcement was located in this research cycle.

Absence provenance: No dedicated Garante material on data clean rooms surfaced.. Searched: Garante clean room data collaboration room privacy.

Cross Context AdvertisingAmber

The Garante fined data-broker Lusha EUR 2 million for monitoring and selling the data of a large number of individuals, illustrating cross-context data monetisation enforcement.

Claims (1):

  • The Garante sanctioned data-broker Lusha EUR 2 million for monitoring and offering for sale the personal data of a large number of individuals.

Direct MarketingAmber

Multiple decisions (Lex Iuris, Enel Energia) sanction unconsented direct-marketing processing under Art.6(1)(a) GDPR and Art.130 Codice.

Claims (1):

  • The Garante fined Enel Energia EUR 26.5 million for aggressive telemarketing where consumers' data were used without consent and the accountability principle was not complied with.
Category narrative63 words

Italy's cookie/tracker regime rests on the Garante's 2021 Linee Guida (Art.122 Codice + Arts.4(11),7,12,13,25 GDPR): default no non-technical cookies on first access, prohibition of cookie walls (absent an equivalent no-consent alternative), rejection of scrolling as valid consent, and a 6-month minimum before re-prompting consent. Dark-pattern-style banner manipulation, data-broker cross-context monetisation (Lusha), and unconsented direct marketing (Lex Iuris, Enel Energia) have all been sanctioned.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The Garante's 29 July 2026 newsletter recorded a marketing-related enforcement matter against Altroconsumo Edizioni, resulting in a fine of EUR 280,000. This is the principal adtech and commercial-privacy development for Italy this cycle, though it should be treated with appropriate caution: the finding rests on a single source, the Garante's own newsletter announcement, and the underlying provvedimento's full reasoning and factual basis were not independently corroborated in the sources reviewed this cycle. Reports suggest the matter concerned marketing-related processing, though the precise nature of the violation, whether direct-marketing consent failures, unlawful profiling for marketing purposes, or another commercial-privacy issue, was not specified in the sources available.

The scale of the fine, at EUR 280,000, indicates the Garante treated the underlying violation as a serious matter within its marketing-enforcement practice, consistent with the broader pattern this cycle of the Garante maintaining an active enforcement tempo across multiple sectors simultaneously. However, given the single-source basis for this specific finding, readers should treat the characterisation of the violation itself as provisional pending corroboration from the Garante's own primary publication of the full provvedimento text.

Outlook

Corroboration of the Altroconsumo Edizioni matter through a primary Garante publication would materially strengthen confidence in this finding for a future cycle. In the interim, the EUR 280,000 fine should be read as one data point within the Garante's broader active-enforcement posture this cycle, alongside the Poste Italiane/PostePay sanction, rather than as a fully resolved standalone finding.

Sources and claims (6)
  1. ConfirmedGarante Privacy — Under the Garante's 2021 cookie guidelines, at first website access no cookie or tracking tool other than technical ones may be positioned on a user's device by default, and no active (third-party) or passive (fingerprinting) tracking may occur without consent.observed
  2. ConfirmedGarante Privacy — Cookie walls are deemed unlawful by the Garante unless the site operator provides equivalent access to content/services without requiring consent to cookies or other trackers, and re-prompting consent at every visit is considered redundant and invasive.observed
  3. ConfirmedGarante Privacy — The Garante found a violation of Arts.4(11),5,7,12,13,24 and 25 GDPR and Art.122 Codice where a cookie banner was configured so that clicking either 'accept technical cookies' or 'accept all cookies' resulted in the same four cookies being installed, undermining granular consent.observed
  4. ConfirmedGarante Privacy — The Registro Pubblico delle Opposizioni (RPO) is a free, institutional service allowing consumers to register fixed and mobile numbers to block telemarketing, with Garante oversight of the register's operation.observed
  5. ProbableGarante Privacy — The Garante sanctioned data-broker Lusha EUR 2 million for monitoring and offering for sale the personal data of a large number of individuals.observed
  6. ConfirmedGarante Privacy — The Garante fined Enel Energia EUR 26.5 million for aggressive telemarketing where consumers' data were used without consent and the accountability principle was not complied with.observed

#

Governance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.

Primary frameworkGDPR Art.22 + EU AI Act (Regulation (EU) 2024/1689) + Italian AI Law (L.132/2025) + national AI Act implementing decree
Traffic-light rationale — AmberGovernance architecture is advanced and the Garante has secured a central supervisory role, but the AI Act implementing framework remains partly in legislative process and biometric safeguards are still being strengthened per the Garante's own July 2026 comments.

Sub-modules (6)

Profiling RestrictionsAmber

The Garante fined a Glovo-group platform EUR 2.6 million for using discriminatory rider-management algorithms.

Claims (1):

  • The Garante fined a platform in the Glovo group EUR 2.6 million for using algorithms that caused discrimination among riders.

Automated Decision Making TransparencyAmber

Character.AI was found to have provided insufficient information about processing operations and to have prepared its DPIA and EU-representative designation belatedly.

Claims (1):

  • In fining Character Technologies Inc. EUR 158,000, the Garante found deficiencies in the information provided to users and that the DPIA and EU-representative designation were carried out belatedly.

Ai Risk AssessmentsGreen

Italy's draft AI Act implementing decree designates the Garante as market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes.

Claims (1):

  • Italy's AI Act implementing decree designates the Garante as the market-surveillance authority for high-risk AI systems used in justice, law-enforcement, immigration, border-management and democratic-process contexts.

Biometric RegimeAmber

The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects; a separate police-AI decree limits real-time remote biometric identification to specific serious-threat scenarios, though the Garante has urged strengthening biometric-database quality safeguards.

Claims (2):

  • The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects.
  • Italy's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.

Genetic DataGreen

Genetic data receives heightened Art.9 GDPR/Art.2-septies Codice protection; no Italy-specific 2026 enforcement case was located in this cycle.

Absence provenance: No 2026 genetic-data-specific enforcement decision surfaced; general Art.9 GDPR/Art.2-septies Codice protection applies.. Searched: Garante dati genetici sanzione 2026.

State Surveillance CarveoutsAmber

Italy's police-AI decree permits real-time remote biometric identification only to confirm identity or locate specifically identified/identifiable individuals in relation to serious threats or missing-persons searches, per the AI Act (Art.5) framework.

Claims (1):

  • Italy's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.

Key findings (1)

  • Court of Rome annulled the Garante's EUR 15M OpenAI fine on 18 March 2026. — source on file
Category narrative71 words

The Garante has been designated national market-surveillance authority for high-risk AI systems in justice, law enforcement, immigration, border management and democratic processes under Italy's AI Act implementing decree, while retaining full GDPR competence over any AI activity processing personal data. Enforcement precedent spans algorithmic-discrimination (Glovo riders), biometric/facial-recognition bans (Clearview AI), and transparency/DPIA failures in generative-AI chatbots (Character.AI). A separate police-use-of-AI decree restricts real-time remote biometric identification to narrowly defined serious-threat/missing-person scenarios.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

This is the most significant module for Italy this cycle, carrying four distinct developments that together indicate an escalating pattern of Garante engagement with algorithmic and AI-adjacent governance ahead of, and independent of, the formal enactment of Italy's AI Act implementing legislation.

The most material of these developments is the Garante's favourable opinion on Italy's draft legislative decree implementing the EU AI Act. The draft decree, as reviewed by the Garante, would designate the Garante itself as the market-surveillance authority for high-risk AI systems deployed in four sensitive contexts: justice administration, law enforcement, immigration and border management, and processes touching the democratic process. This is a substantial expansion of the Garante's institutional remit beyond its existing GDPR-based mandate, and it reflects a deliberate legislative choice to route AI Act market-surveillance responsibility for these particularly sensitive domains through the existing data-protection authority rather than creating a wholly new oversight body. As of this cycle, the decree remains at the proposed stage; the Garante's opinion is favourable but the decree has not yet been enacted, and its final text and effective date remain open questions.

Separately, and demonstrating that the Garante is already applying AI Act principles operationally ahead of the implementing decree's enactment, the regulator issued a provvedimento dated 14 May 2026 addressing the use of AI systems in the workplace to analyse workers' emotional or psychological states. This provvedimento explicitly invoked the AI Act's prohibition on emotion-inference systems in the employment context, treating that prohibition as already operative guidance for employers deploying such systems on Italian workers, notwithstanding that the national implementing decree itself remains unenacted.

A third development concerns biometric identification in the criminal-procedure context. The Garante has called for an express prohibition, to be incorporated within a pending reform introducing a new Article 359-ter biometric-identification framework into Italy's criminal-procedure law, on the use of databases obtained through indiscriminate scraping or otherwise assembled in violation of data-protection law. This is advocacy directed at a pending legislative reform rather than a completed instrument, but it signals the Garante's substantive position on how facial-recognition and biometric-identification databases used by law-enforcement bodies should be constrained.

A fourth strand concerns generative AI directly. In a provvedimento dated 3 July 2026, the Garante examined the character.ai generative-AI companion service, noting specifically the existence of a dedicated version of the service for minor users, launched in November 2024. This examination sits at the intersection of algorithmic governance and the treatment of vulnerable users, and is addressed further under the children and vulnerable groups module.

Outlook

The enactment trajectory of the AI Act implementing decree is the central item to watch: a favourable Garante opinion is a meaningful procedural step but does not itself extend the Garante's market-surveillance remit until the decree is formally enacted. In the interim, the workplace-AI provvedimento and the biometric-scraping advocacy both demonstrate that the Garante is willing to apply AI Act-derived principles through its existing enforcement and policy powers, a pattern likely to continue as the decree moves through the remainder of the legislative process.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Algorithmic, Biometric & Surveillance Governance

This module carries the highest density of material developments in Italy's data-protection landscape this cycle, with four distinct threads escalating simultaneously. First, the Garante imposed a EUR 158,000 fine on Character Technologies Inc. on 9 July 2026 for GDPR violations concerning privacy notices and child-protection and age-verification failures, a Confirmed-confidence, Tier-1-sourced primary enforcement action.

Second, the Garante's ruling under Provvedimento 10281021 holds that AI Act transparency obligations for manipulated content become applicable from 2 August 2026, while clarifying that deepfakes are not per se a prohibited practice under the AI Act; at the time of the ruling this obligation was enacted but not yet effective, and it is now understood to be in force given the 2 August 2026 applicability date has since passed. This is a Confirmed-confidence, Tier-1-sourced finding.

Third, the Garante flagged AI Act incompatibilities in a proposed police facial-recognition decree, specifically objecting to a 7-day biometric-data retention period that would apply regardless of whether a crime actually occurred, and called for modifications ahead of a final Council of Ministers vote expected before October 2026. This is a Probable-confidence finding, sourced at Tier 3, and represents an active, unresolved dispute between the regulator and the government over a still-proposed instrument.

Fourth, and most structurally significant, the Court of Rome annulled the Garante's own December 2024 EUR 15 million fine and media-campaign order against OpenAI on 18 March 2026, on one-stop-shop jurisdiction grounds. This is a Confirmed-confidence finding, though sourced at Tier 3, and it represents a significant judicial reversal of the regulator's own enforcement action. Read together, this annulment and the continuing aggressive enforcement against Character.AI signal a meaningful judicial check on Italy's AI-enforcement reach even as the regulator continues pursuing smaller generative-AI operators, an Assessed-confidence key judgment.

Outlook

Watch for the final Council of Ministers vote on the facial-recognition decree, expected before October 2026, and for whether the Garante appeals the Court of Rome's OpenAI annulment or adjusts its jurisdictional approach to future one-stop-shop cases in light of that ruling.

Sources and claims (5)
  1. ConfirmedGarante Privacy — The Garante fined a platform in the Glovo group EUR 2.6 million for using algorithms that caused discrimination among riders.observed
  2. ConfirmedGarante Privacy — In fining Character Technologies Inc. EUR 158,000, the Garante found deficiencies in the information provided to users and that the DPIA and EU-representative designation were carried out belatedly.observed
  3. ProbableGarante Privacy — Italy's AI Act implementing decree designates the Garante as the market-surveillance authority for high-risk AI systems used in justice, law-enforcement, immigration, border-management and democratic-process contexts.observed
  4. ConfirmedGarante Privacy — The Garante fined Clearview AI EUR 20 million and banned its use of biometric data and monitoring of Italian data subjects.observed
  5. ProbableGarante Privacy — Italy's draft police-use-of-AI decree permits real-time remote biometric identification only to confirm identity or conduct a targeted search for specifically identified or identifiable persons in relation to the threat to be prevented or the search to be conducted, consistent with AI Act Art.5(1)(h) and (2); the Garante has requested strengthened guarantees on biometric database quality.observed

#

Age-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.

Primary frameworkGDPR Art.8 + Codice Privacy Art.2-quinquies
Traffic-light rationale — AmberAge-of-consent framework is clear and enforced, but recurrent age-verification failures (Character.AI, TikTok precedent) show implementation gaps at platform level.

Sub-modules (5)

Age VerificationAmber

Character.AI was ordered to guarantee correctly functioning age-verification systems, a 'cooling-off' mechanism against repeat registration by blocked minors, and default-private profiles for minors.

Claims (1):

  • The Garante required Character Technologies to guarantee correctly functioning age-verification systems, ensure effective 'cooling-off' mechanisms preventing renewed registration attempts by blocked minors, and set minors' profiles to private by default.

Minor Profiling BansAmber

The Garante blocked TikTok's processing where the platform could not verify user age, holding that consent/contract from under-14s is invalid and thus devoid of any legal basis for further processing including profiling.

Claims (1):

  • The Garante held that where a platform cannot verify a user's age, any consent or contract entered into by an under-14 user is invalid, leaving any associated processing (including for commercial/profiling purposes) devoid of a legal basis.

Education SettingsGreen

School information notices must be easily comprehensible to minors and are subject to Garante prior review for AI-based educational platforms.

Claims (1):

  • The Garante issued a favourable opinion on a Ministry of Education AI-service scheme and accompanying guidelines for introducing AI in schools, requiring information notices to be easily comprehensible to minors.

Dependent AdultsRed

No dedicated dependent-adults (elderly/incapacitated persons) data-protection regime distinct from general GDPR safeguards was located in this research cycle.

Absence provenance: No dedicated dependent-adults data-protection guidance or enforcement item surfaced in this pass.. Searched: Garante privacy anziani incapaci tutela dati personali 2026.

Category narrative57 words

The Italian digital age of consent is 14 (Codice Privacy Art.2-quinquies), below which parental/guardian consent is required for information-society services; below-14 consent is invalid absent parental authorisation, as applied in TikTok and social-media minor-image cases. Age-verification and default-privacy settings for minors were central to the 2026 Character.AI sanction. No dedicated dependent-adults (elderly/incapacitated) regime was identified this cycle.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

The Garante's provvedimento dated 3 July 2026 examined the generative-AI companion service character.ai, with particular attention to a dedicated version of the service designed for minor users, which had been launched in November 2024. This examination places Italy's data-protection regulator among those actively scrutinising generative-AI companion services for their treatment of under-18 users, a category of service that raises distinct concerns given the emotionally engaging, conversational nature of the product and the potential for minors to form parasocial attachments to an AI companion without adult-level capacity to assess the risks of doing so.

The existence of a dedicated minors-facing version of the service, launched nearly two years before the Garante's examination, indicates the provider had already made a deliberate product decision to serve the under-18 demographic, which in turn sharpens the regulatory question of what safeguards, age-verification mechanisms, and data-processing limitations were in place for that minors-specific product tier. The sources reviewed this cycle establish that the Garante examined the service and its minors-specific version, but do not specify the provvedimento's ultimate findings, remedial requirements, or sanctions, if any, arising from that examination.

This generative-AI/minors matter should be read alongside the broader algorithmic-governance developments this cycle, particularly the workplace-AI emotion-inference provvedimento, as both reflect the Garante applying heightened scrutiny to AI systems that engage with, infer from, or affect the psychological and emotional states of individuals, whether workers or, in this case, minor users of a generative-AI product.

Outlook

Further detail on the character.ai provvedimento's findings and any resulting remedial measures would clarify whether Italy is moving toward a more prescriptive standard for minors-facing generative-AI products specifically. Given the Garante's demonstrated pattern of proactive AI-system scrutiny this cycle, further provvedimenti addressing other generative-AI companion or chatbot services with minor-facing product tiers should be considered a plausible continuation of this line of regulatory attention.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Children & Vulnerable Groups

The Garante's Character Technologies enforcement action carries a binding children's-data-protection dimension this cycle. Alongside the EUR 158,000 fine imposed 9 July 2026, the corrective-measures order requires Character Technologies to guarantee age-verification systems, implement cooling-off mechanisms preventing minor re-registration after account closure, and set default-private minor profiles, with compliance to be reported to the Garante within 120 days. This is a Confirmed-confidence, Tier-1-sourced finding with a binding compliance deadline, marking a tightening trajectory for this module.

The specificity of the corrective measures, particularly the cooling-off mechanism preventing re-registration and the default-private setting for minor profiles, indicates the Garante is moving beyond generic GDPR privacy-notice failures toward prescriptive, child-specific design requirements for generative-AI platforms likely to be used by minors. The 120-day reporting deadline gives a concrete compliance-verification point in the near term.

Outlook

Watch for Character Technologies' 120-day compliance report to the Garante, due in approximately early November 2026 based on the 9 July 2026 order date, which will indicate whether the prescribed age-verification and cooling-off measures were implemented as ordered.

Sources and claims (4)
  1. ConfirmedGarante Privacy — The Garante required Character Technologies to guarantee correctly functioning age-verification systems, ensure effective 'cooling-off' mechanisms preventing renewed registration attempts by blocked minors, and set minors' profiles to private by default.observed
  2. ConfirmedGarante Privacy — Under Art.2-quinquies of the Codice, implementing Art.8(1) GDPR, a minor who has reached 14 years of age may validly consent to processing of their personal data in relation to information-society services; below that age, consent must be given by whoever exercises parental responsibility.observed
  3. ConfirmedGarante Privacy / Agenda Digitale — The Garante held that where a platform cannot verify a user's age, any consent or contract entered into by an under-14 user is invalid, leaving any associated processing (including for commercial/profiling purposes) devoid of a legal basis.observed
  4. ConfirmedGarante Privacy — The Garante issued a favourable opinion on a Ministry of Education AI-service scheme and accompanying guidelines for introducing AI in schools, requiring information notices to be easily comprehensible to minors.observed

#

High-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.

Primary frameworkGDPR Arts. 58, 77-84, 83 + Codice Privacy Artt. 152, 154-bis, 166 + Reg. Garante 1/2019 and 2/2019
Traffic-light rationale — GreenHigh-volume, well-documented, and materially consequential enforcement activity with a functioning judicial-review channel; funding/headcount transparency is comparatively thin in public sources.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Garante exercises full Art.58(2) GDPR corrective powers; internal Reg.1/2019 was amended in March 2026 to delegate certain time-barred/low-impact corrective measures to departmental directors, excluding journalistic, political/union, high-turnover, and major-public-body cases.

Claims (1):

  • A March 2026 amendment to Garante Regulation 1/2019 delegates adoption of certain Art.58(2)(b) corrective measures to departmental directors for time-barred or fully-remedied conduct, expressly excluding journalistic-sector, political/union-rights, high-turnover (>EUR 500,000) and major public-body cases from the delegation.

Enforcement Activity IndexGreen

In 2025 the Garante adopted 807 collegial decisions and handled 4,288 complaints and 145,846 reports; 2026 saw multiple 7-figure fines (Poste Italiane/PostePay, Lusha) alongside smaller sanctions (Piaggio, Altroconsumo, Character.AI).

Claims (1):

  • In 2025 the Garante adopted 807 collegial decisions, responded to 4,288 complaints and 145,846 reports, and issued 65 opinions on regulatory and administrative measures spanning public-administration digitalisation, healthcare, tax and justice.

Regulator Funding And CapacityAmber

Public information on current-year Garante staffing/budget levels is limited in this research pass; historically the Authority has supplemented its inspection capacity with seconded Guardia di Finanza personnel.

Absence provenance: Current-year (2025/2026) headcount/budget figures were not located; only a historical (2008) administrative report referencing Guardia di Finanza secondment surfaced.. Searched: Garante privacy organico personale bilancio 2025 relazione annuale risorse.

Collective Redress And Class ActionsAmber

No GDPR-specific Italian collective-redress case was located in this cycle; general azione di classe mechanisms under the Codice del Consumo remain the available collective-litigation route.

Absence provenance: No 2026 GDPR-specific class-action decision surfaced in this research pass.. Searched: Garante privacy azione di classe class action GDPR Italia 2026.

Private Right Of ActionGreen

Data subjects may oppose Garante sanction orders before the ordinary judiciary within 30 days (60 if residing abroad) under Art.152 Codice/Art.10 D.Lgs.150/2011 and Art.78 GDPR.

Claims (1):

  • A Garante sanction order may be opposed before the ordinary courts, via petition filed within 30 days of notification (60 days if the appellant resides abroad), under Art.152 of the Codice, Art.10 of D.Lgs.150/2011 and Art.78 GDPR.

Recent Developments 180DGreen

Within the last 180 days: the Garante fined Character.AI (3 July 2026), gave a conditioned favourable opinion on the national AI Act implementing decree (29 July 2026) while flagging biometric-safeguard gaps, sanctioned Piaggio (EUR 460k) and Altroconsumo (EUR 280k), sanctioned Città Metropolitana di Sassari for a data breach, and presented its 2025 Annual Report to Parliament (2 July 2026).

Claims (1):

  • On 29 July 2026 the Garante gave a favourable opinion on the AI Act national implementing decree while asking for clarified human-oversight rules, clearer research/experimentation responsibilities, its own involvement in the Italian AI regulatory sandbox, and strengthened guarantees on biometric-database quality.
Category narrative116 words

The Garante wields full GDPR Art.58 corrective powers (warnings, orders, bans, fines up to EUR 20M/4% global turnover) and delegated internal procedures (Reg. 1/2019) for time-barred/low-impact cases. 2025 activity: 807 collegial decisions, 4,288 complaints and 145,846 reports handled, and 65 opinions issued on regulatory/administrative measures. Recent months show sustained high-value enforcement (Poste Italiane/PostePay EUR 12.5M, Character.AI EUR 158k, Lusha EUR 2M, Piaggio EUR 460k, Altroconsumo EUR 280k) and judicial pushback (a March 2026 sanction order was suspended by the Tribunale di Roma). No dedicated GDPR-based class-action/collective-redress statistic was identified distinct from the general Italian collective-action (azione di classe) mechanism under Art.140-bis Codice del Consumo; individual judicial opposition to Garante orders is available under Art.152 Codice/Art.78 GDPR.

Periodic update · new data 2026-09-28

Enforcement & Redress

Italy's enforcement and redress picture this cycle is defined by two concrete sanctions and one significant forward-looking programme. The Garante sanctioned Poste Italiane and its PostePay division in Provvedimento n. 237 of 17 April 2026, for unlawful monitoring of applications installed on users' Android devices, a matter addressed in detail under the controller/processor duties module. Separately, the Garante's 29 July 2026 newsletter recorded a EUR 280,000 fine against Altroconsumo Edizioni for a marketing-related violation, a finding that rests on a single source this cycle and should be treated as provisional pending corroboration.

Beyond these two concluded matters, the Garante's inspection plan for the second half of 2026 represents a significant expansion of its forward enforcement pipeline: at least 35 inspections are planned for the August-to-December window, with sectoral scope expanding to include geomarketing, neuromarketing, dynamic pricing, DPO-supplier relationships, municipalities, local health authorities, and AI systems generally. This expanded inspection programme, considered alongside the two concrete sanctions already recorded this cycle, indicates the Garante is sustaining an active enforcement tempo across a widening set of sectors rather than concentrating attention on a narrow set of repeat targets.

The combination of concrete sanctions with an expanding forward inspection programme is itself the significant structural fact for this module this cycle: it indicates the Garante's enforcement posture is both active in the present and set to broaden further in scope over the remainder of 2026.

Outlook

The 35-plus inspections planned for August-December 2026 should be watched closely, both for their outcomes and for whether the sectoral pattern (municipalities, ASL, geomarketing, neuromarketing, dynamic pricing, DPO-supplier relationships, AI systems) proves predictive of where the Garante's next concrete sanctions land. Corroboration of the Altroconsumo Edizioni fine through a primary Garante publication remains an open item for a future cycle.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Enforcement & Redress

Italy's enforcement and redress landscape this cycle is marked by both continued aggressive fining activity and a significant judicial check on the regulator's own reach. The Character Technologies fine of EUR 158,000, imposed 9 July 2026, is a Confirmed-confidence, Tier-1-sourced primary enforcement action. Separately, reporting indicates Intesa Sanpaolo was fined EUR 31.8 million in March 2026 for an insider data breach; however, this figure is sourced only from a Tier-4 secondary compilation and could not be corroborated against a Garante primary provvedimento this cycle, and is accordingly reported at Uncertain confidence with attribution limited to the secondary source rather than presented as an established fact.

The most structurally significant development is the Court of Rome's annulment, on 18 March 2026, of the Garante's own December 2024 EUR 15 million fine and media-campaign order against OpenAI, on one-stop-shop jurisdiction grounds. This is a Confirmed-confidence finding, sourced at Tier 3, and represents a meaningful check on the scope of the Garante's enforcement jurisdiction in cross-border AI cases. Separately, the Garante is confirmed, at Probable confidence from a Tier-4 source, to act as competent authority for AI Act enforcement in areas overlapping data protection, particularly for high-risk AI systems processing personal data, expanding its effective enforcement remit even as the OpenAI annulment narrows its jurisdictional reach in one specific respect.

Outlook

Watch for primary-source corroboration of the reported Intesa Sanpaolo fine, which remains an open evidentiary gap, and for whether the Garante's expanded AI Act competent-authority role generates new enforcement activity distinguishable from its existing GDPR enforcement programme.

Sources and claims (4)
  1. ConfirmedGarante Privacy — A March 2026 amendment to Garante Regulation 1/2019 delegates adoption of certain Art.58(2)(b) corrective measures to departmental directors for time-barred or fully-remedied conduct, expressly excluding journalistic-sector, political/union-rights, high-turnover (>EUR 500,000) and major public-body cases from the delegation.observed
  2. ConfirmedGarante Privacy — In 2025 the Garante adopted 807 collegial decisions, responded to 4,288 complaints and 145,846 reports, and issued 65 opinions on regulatory and administrative measures spanning public-administration digitalisation, healthcare, tax and justice.observed
  3. ConfirmedGarante Privacy — A Garante sanction order may be opposed before the ordinary courts, via petition filed within 30 days of notification (60 days if the appellant resides abroad), under Art.152 of the Codice, Art.10 of D.Lgs.150/2011 and Art.78 GDPR.observed
  4. ConfirmedGarante Privacy — On 29 July 2026 the Garante gave a favourable opinion on the AI Act national implementing decree while asking for clarified human-oversight rules, clearer research/experimentation responsibilities, its own involvement in the Italian AI regulatory sandbox, and strengthened guarantees on biometric-database quality.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct91.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Italy
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 36 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressprivate right of action

Self-audit

All 10 modules populated with T1 Garante primary-source claims (provvedimenti, pareri, linee guida, comunicati stampa, Codice Privacy text) as the backbone. T3 secondary reporting (DataGuidance, IAPP) used only to corroborate fine quantum/dates where the Garante's own document was paywalled or summarised. Weakest-coverage sub-modules (marked amber/red with absent_field_provenance): pseudonymisation/anonymisation-specific guidance, EU-level adequacy_received/adequacy_granted (structurally an EU competence, not an Italy-specific act), clean_rooms_and_dcr, genetic_data 2026-specific enforcement, dependent_adults, regulator_funding_and_capacity (current-year), and collective_redress_and_class_actions.

Unresolved questions (5):

  • What is the Garante's current (2025/2026) headcount and budget allocation, and has Guardia di Finanza secondment continued at historical levels?
  • Has any Italian court applied the general azione di classe (Codice del Consumo Art.140-bis) mechanism specifically to a GDPR/Codice Privacy breach in 2025-2026?
  • Does the Garante have dedicated guidance on data clean rooms / data-collaboration rooms for adtech, or does it treat these solely under general joint-controller/Art.26 principles?
  • What is the final, enacted text and effective date of the AI Act national implementing decree following the Garante's July 2026 conditioned favourable opinion?
  • Is there a dedicated Italian regime for dependent/vulnerable adults (elderly, mentally incapacitated) distinct from general GDPR safeguards?

Escalate to primary-source review: yes