Law note · Italy
GDPR Article 9 Special Categories and Codice Privacy Article 167(2)
General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. The Codice Privacy adds no separate biometric-specific statute but does add its own Article 167(2) criminal offense specifically for unlawful Article 9-10 processing, and Provvedimento n. 146/2019's security and consent prescriptions for genetic and health data.
The Garante's Clearview AI decision confirms Italy applies no general publicly-available carve-out: processing publicly posted facial images to build a biometric identification database brought them within Article 9's special-category regime regardless of prior public availability.
What it asks of an app
- Obtain an explicit General Data Protection Regulation (GDPR) Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Italy, and treat unlawful special-category processing as a Codice Privacy Article 167(2) criminal exposure, not only an administrative one.
- Do not treat a publicly posted photograph or recording as freely processable for identification purposes; the Garante's Clearview AI decision found no valid legal basis for exactly that.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, high_risk_decisions
Primary source: GDPR Art. 9(1)
D.Lgs. 196/2003 Art. 167(2) (direct read); Garante Provvedimento n. 50/2022 (Clearview AI, direct read)