Law note · Italy
GDPR Articles 33-34, Breach Notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
reviewed 2026-08-24
A controller must notify the Garante within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Italy-specific derogation from this timeline or threshold was identified in the Codice Privacy in this pass.
What it asks of an app
- Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics
Primary source: GDPR Arts. 33-34