Law note · Italy

Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment

cite Decreto Legislativo 30 giugno 2003, n. 196, as amended by Decreto Legislativo 10 agosto 2018, n. 101 stage In effect since 2018-09-19 reviewed 2026-08-24

Italy gives the General Data Protection Regulation (GDPR) domestic effect through the Codice in materia di protezione dei dati personali (Personal Data Protection Code), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018, in force from 19 September 2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses for unlawful processing (Artt.

167, 167-bis, 167-ter, 168, 170, 171; Art. 169 was abrogated outright by the 2018 decree), the Garante's own Article 166 sanctioning procedure, and sector-specific security and consent prescriptions for genetic, health, and biometric data. All confirmed by reading the articles directly at normattiva.it.

What it asks of an app

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Italy, following the Codice Privacy's institutional and procedural rules.
  • Expect a Codice Privacy Titolo III criminal offense (Artt. 167, 167-bis, 167-ter, 168, 170, 171) to attach to unlawful processing, on top of GDPR's own administrative-fine exposure.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot

Primary source: normattiva.it, D.Lgs. 196/2003 idF D.Lgs. 101/2018 (direct read, article by article)

← Back to the example  ·  Lint your app →