Law / Italy

Italy

privacy

Italy's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Codice in materia di protezione dei dati personali (Personal Data Protection Code, "Codice Privacy"), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses, the Garante's Article 166 sanctioning procedure, and sector-specific prescriptions for genetic, health, and biometric data.

The Garante is one of the EU's most active biometrics regulators, evidenced by its EUR 20 million Clearview AI fine, and one of the most active generative-AI regulators, evidenced by its ChatGPT suspension and ongoing OpenAI enforcement.

22 instruments named 7 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

cite Garante Provvedimento n. 146 del 5 giugno 2019 stage In effect since 2019-06-05 source Garante Provvedimento n. 146/2019 (direct read)

The Garante's Provvedimento n. 146/2019 imposes specific security measures for genetic data (documented physical-access controls, encrypted or pseudonymized storage, controlled transmission), consent requirements for genetic testing and for processing genetic data to protect a third party's health, and a research-retention rule limiting secondary use of health data to cases where equivalent research cannot be done on data from consenting subjects.

The Garante's leading biometric enforcement action is Provvedimento n. 50 del 10 febbraio 2022 against Clearview AI: a EUR 20 million fine, an EU-wide processing ban on Italy-related facial-recognition data, and an order to delete data and designate an EU representative, for scraping and processing facial images with no valid legal basis.

No dedicated Garante decision or guidance on voiceprints specifically, or on employer fingerprint or facial-recognition timekeeping, was located in this pass; these are genuine gaps, not confirmed absences, since the Garante's own thematic search pages could not be queried through this session's tooling.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify the Garante within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Italy-specific derogation from this timeline or threshold was identified in the Codice Privacy in this pass.

What it asks of an app

Comprehensive regime

Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment

cite Decreto Legislativo 30 giugno 2003, n. 196, as amended by Decreto Legislativo 10 agosto 2018, n. 101 stage In effect since 2018-09-19 source normattiva.it, D.Lgs. 196/2003 idF D.Lgs. 101/2018 (direct read, article by article)

Italy gives the General Data Protection Regulation (GDPR) domestic effect through the Codice in materia di protezione dei dati personali (Personal Data Protection Code), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018, in force from 19 September 2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses for unlawful processing (Artt.

167, 167-bis, 167-ter, 168, 170, 171; Art. 169 was abrogated outright by the 2018 decree), the Garante's own Article 166 sanctioning procedure, and sector-specific security and consent prescriptions for genetic, health, and biometric data. All confirmed by reading the articles directly at normattiva.it.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier of up to EUR 20 million or 4% of global turnover. No Italy-specific derogation from this EU-wide framework was identified.

What it asks of an app

Data subject rights

GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement

cite Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023 stage In effect since 2018-05-25 source Garante notice of violation, 29 January 2024 (direct read)

Individuals in Italy have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. The Garante's ChatGPT/OpenAI matter is Italy's leading automated-processing enforcement episode: a provisional order suspending OpenAI's processing of Italian users' personal data on 30 March 2023, and a formal notice of violation on 29 January 2024.

A further EUR 15 million fine (December 2024) and the Court of Rome's annulment of that fine on a one-stop-shop competence ground (18 March 2026, once OpenAI's Irish establishment shifted lead-authority jurisdiction to Ireland's DPC) were not independently re-verified this session and are carried from the derivation package's own sourcing rather than confirmed here.

What it asks of an app

Enforcement supervision

GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis)

cite Regulation (EU) 2016/679, Art. 82; Codice di procedura civile, Art. 840-bis (as reformed by Legge 12 aprile 2019, n. 31) stage In effect since 2018-05-25 source GDPR Art. 82

The Garante is Italy's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines under the Codice Privacy Article 166 procedure.

GDPR Article 82 arms an individual with a direct private right of action, and Italy additionally has a general class-action mechanism, Codice di procedura civile Article 840-bis (azione di classe), in force since 19 May 2021, confirmed by a direct read of the article: it covers homogeneous individual rights against enterprises or public-service managers, brought by an individual class member or a registered nonprofit organization.

The article does not name data protection specifically, and this session could not establish whether it has actually been used for a GDPR claim.

What it asks of an app

Sensitive categories

GDPR Article 9 Special Categories and Codice Privacy Article 167(2)

cite Regulation (EU) 2016/679, Art. 9; D.Lgs. 196/2003, Art. 167(2) stage In effect since 2018-05-25 source GDPR Art. 9(1)

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. The Codice Privacy adds no separate biometric-specific statute but does add its own Article 167(2) criminal offense specifically for unlawful Article 9-10 processing, and Provvedimento n. 146/2019's security and consent prescriptions for genetic and health data.

The Garante's Clearview AI decision confirms Italy applies no general publicly-available carve-out: processing publicly posted facial images to build a biometric identification database brought them within Article 9's special-category regime regardless of prior public availability.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.