Law note · Italy

GDPR Article 9 Special Categories and Codice Privacy Article 167(2)

cite Regulation (EU) 2016/679, Art. 9; D.Lgs. 196/2003, Art. 167(2) stage In effect since 2018-05-25 reviewed 2026-08-24

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. The Codice Privacy adds no separate biometric-specific statute but does add its own Article 167(2) criminal offense specifically for unlawful Article 9-10 processing, and Provvedimento n. 146/2019's security and consent prescriptions for genetic and health data.

The Garante's Clearview AI decision confirms Italy applies no general publicly-available carve-out: processing publicly posted facial images to build a biometric identification database brought them within Article 9's special-category regime regardless of prior public availability.

What it asks of an app

  • Obtain an explicit General Data Protection Regulation (GDPR) Article 9(2) legal basis before processing biometric, genetic, or health data of a person in Italy, and treat unlawful special-category processing as a Codice Privacy Article 167(2) criminal exposure, not only an administrative one.
  • Do not treat a publicly posted photograph or recording as freely processable for identification purposes; the Garante's Clearview AI decision found no valid legal basis for exactly that.

When LexLint raises it

Declared activities: processes_biometrics, processes_voice, high_risk_decisions

Primary source: GDPR Art. 9(1)
D.Lgs. 196/2003 Art. 167(2) (direct read); Garante Provvedimento n. 50/2022 (Clearview AI, direct read)

← Back to the example  ·  Lint your app →