EnglishItaliano
Italy flag

Italy

Italy Data Privacy Laws: GDPR, Privacy Code & Garante Guide (2026)

By Recording Law Editorial TeamReviewed August 21, 202626 min read
Italy Data Privacy Laws: GDPR, Privacy Code & Garante Guide (2026)

Frequently Asked Questions

Does the GDPR apply directly in Italy, or does Italy have its own separate data privacy law?

Both frameworks apply simultaneously. The GDPR applies directly as EU law and does not require separate national legislation. Italy also maintains its Privacy Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018), which supplements the GDPR in areas where EU law leaves discretion to member states. These include the age of digital consent (set at 14 in Italy), criminal penalties for serious violations, employee monitoring rules, and specific cookie and electronic communications requirements. Law No. 132/2025 adds a further AI-specific layer. All three instruments must be satisfied by organizations processing personal data of individuals in Italy.

Can you go to prison for a data privacy violation in Italy?

Yes. Italy is one of the few EU member states that imposes criminal penalties alongside administrative fines. Article 167 of the Privacy Code provides for imprisonment of six months to three years for unlawful processing carried out with intent to profit or cause harm. Article 167-bis covers unauthorized large-scale dissemination of personal data and carries one to six years. Article 168 punishes false statements to the Garante with six months to three years. Article 170 punishes non-compliance with Garante orders with three months to two years. Criminal and administrative sanctions can both apply to the same conduct, though criminal penalties are reduced where an administrative fine has already been imposed.

What happened with Italy and ChatGPT?

Italy became the first Western country to ban a major AI chatbot when the Garante issued an emergency order on March 30, 2023 temporarily prohibiting OpenAI from processing personal data of individuals in Italy. The Garante cited lack of transparency, no legal basis for training data collection, AI hallucinations presenting false information about real people, and inadequate age verification. The ban lasted approximately one month; OpenAI implemented corrective measures and ChatGPT was restored on April 28, 2023. The Garante concluded its full investigation on December 20, 2024 and imposed a EUR 15 million fine. OpenAI appealed, and on March 19, 2026, a Rome court overturned the fine. The court has not yet published its full reasoning.

How long does a company have to report a data breach to the Italian authorities?

Controllers must notify the Garante within 72 hours of becoming aware of a personal data breach that poses a risk to the rights and freedoms of natural persons. Since July 2021, notifications must be submitted through the Garante''s dedicated electronic portal with a certified email (PEC) and qualified digital signature. Where the breach poses a high risk to affected individuals, the controller must also notify those individuals directly without undue delay. OpenAI''s failure to report a March 2023 breach within 72 hours contributed EUR 320,000 to the 2024 enforcement action against the company.

Can employers monitor employee email and internet activity in Italy?

Only under strict conditions. Article 4 of the Workers'' Statute (Law 300/1970) prohibits employers from using surveillance systems to monitor employee activity without either a trade union agreement or Labour Inspectorate authorization. The Garante''s June 2024 guidelines on email metadata allow retention of email metadata (sender, recipient, timestamps, subject lines) for a maximum of 21 days without triggering Article 4''s full requirements. Retention beyond 21 days requires the union or inspectorate authorization process. The Garante''s first fine under these guidelines, EUR 50,000 against the Lombardy Region in April 2025, concerned email metadata retained for 90 days and browsing logs retained for 12 months.

What is Italy''s national AI law and how does it affect data protection?

Law No. 132/2025, signed September 23, 2025 and in force from October 10, 2025, made Italy the first EU member state to enact dedicated national AI legislation. The law complements the EU AI Act and reinforces GDPR principles in the AI context. Key data protection interactions: AI systems must process personal data lawfully, fairly, and transparently; secondary use of pseudonymized health data for AI research is permitted without renewed consent but requires prior notification to the Garante with a 30-day waiting period; employers must disclose AI system use to employees including data parameters and oversight mechanisms; minors under 14 require parental consent for AI system access and related data processing. The Garante retains all its GDPR enforcement powers without any change.

What are the largest fines the Italian Garante has ever issued?

The largest fine in Italian data protection history is the EUR 79.1 million sanction against Enel Energia in February 2024 for systematic telemarketing supply chain failures. Other major fines include: EUR 31.8 million against Intesa Sanpaolo in March 2026 for an insider data breach; EUR 20 million against Clearview AI in February 2022 for unlawful facial recognition data collection; EUR 17.6 million against Intesa Sanpaolo for unlawful customer profiling during a corporate restructuring; EUR 15 million against OpenAI in December 2024 (overturned by a Rome court in March 2026); and EUR 5 million against Luka Inc. (Replika) in May 2025 for AI chatbot GDPR violations.

Does Italy allow transfers of personal data to the United States?

Yes, subject to the EU-US Data Privacy Framework. Following the European Commission''s adequacy decision and its upholding by the EU General Court in September 2025, transfers to US organizations certified under the Framework are permitted. For US recipients not certified under the Framework, transfers require Standard Contractual Clauses supplemented by a Transfer Impact Assessment. The Garante''s 2022 ruling against Google Analytics use in Italy was based on inadequate transfer safeguards under the old regime before the Framework was established.

Updates

Added Garante provvedimento no. 426 of 11 June 2026 (doc. web 10266034): a 12,000-euro fine against the Citta Metropolitana di Sassari for over-permissioned access to personnel records, a data-protection-by-design failure under GDPR Articles 5, 6, 9, 10, and 25.

Expanded from 3,850 to approximately 6,200 words. Added: Italy Law No. 132/2025 (AI law signed September 23, 2025, in force October 10, 2025); Replika/Luka EUR 5M fine (May 2025); Intesa Sanpaolo EUR 31.8M insider breach fine (March 2026) and separate EUR 17.6M profiling fine; Clothoff deepnude app ban (October 2025); Lombardy Region EUR 50,000 email metadata fine (April 2025); Garante EUR 420,000 workplace social media fine (2025); EU AI Act milestone timeline (Feb 2025, Aug 2025, Aug 2026); EU-US Data Privacy Framework General Court ruling (September 2025); UK adequacy extension to 2031; Brazil adequacy draft; ePrivacy Regulation withdrawal (February 2025); updated OpenAI saga through Rome court reversal (March 2026); constitutional basis section; penalties comparison table; business compliance section; Google Analytics 2022 ruling. Removed link to orsingher.com as internal citation; all EDPB and normattiva.it sources preserved.

Initial publication. Covered GDPR framework, Privacy Code (D.Lgs. 196/2003), Garante structure and powers, breach notification, criminal penalties, enforcement actions through December 2024 (Enel EUR 79.1M, OpenAI EUR 15M, Clearview EUR 20M, TikTok), international transfers, NIS2 transposition.

Sources and References

  1. Legislative Decree No. 196/2003 (Italian Privacy Code)(normattiva.it).gov
  2. Legislative Decree No. 101/2018 (GDPR Harmonization)(normattiva.it).gov
  3. Garante per la protezione dei dati personali - Official Website(garanteprivacy.it).gov
  4. EU General Data Protection Regulation (GDPR) Full Text(eur-lex.europa.eu).gov
  5. EU AI Act (Regulation EU 2024/1689) Full Text(eur-lex.europa.eu).gov
  6. EDPB: Italian SA Fines Clearview AI EUR 20 Million(edpb.europa.eu).gov
  7. Italy Fines OpenAI EUR 15 Million - Euronews(euronews.com)
  8. EDPB: Italian DPA Imposes Limitation on TikTok(edpb.europa.eu).gov
  9. Legislative Decree 138/2024 (NIS2 Transposition)(normattiva.it).gov
  10. Enel Energia Fine - Orsingher Analysis(orsingher.com)
  11. EDPB: Italian SA Fines Replika Maker Luka Inc. EUR 5 Million(edpb.europa.eu).gov
  12. Norton Rose Fulbright: Italy Enacts Law No. 132/2025 on AI(nortonrosefulbright.com)
  13. Cleary Gottlieb: Italy Adopts First National AI Law in Europe(clearygottlieb.com)
  14. EDPB: Italian SA Bans Use of Google Analytics(edpb.europa.eu).gov
  15. DLA Piper: Italy Garante Issues First GDPR Fine Over Employees Email Metadata(privacymatters.dlapiper.com)
  16. Intesa Sanpaolo EUR 31.8 Million Fine - Captain Compliance(captaincompliance.com)
  17. Garante, provvedimento n. 426 dell'11 giugno 2026 (doc. web 10266034), Citta Metropolitana di Sassari(garanteprivacy.it).gov
Share: