Compliance Node Overview
Italy's Personal Data Protection Code (Codice in materia di protezione dei dati personali - Codice Privacy, Legislative Decree No. 196 of 30 June 2003, as substantially amended and restructured by Legislative Decree No. 101 of 10 August 2018 to align with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679)) is Italy's primary national data protection legislation. The GDPR is directly applicable Italian law by virtue of Italy's EU membership; D.Lgs. 101/2018 aligned the Codice Privacy with GDPR by repealing incompatible provisions and adding national derogations and specifications. Enforcement: Garante per la protezione dei dati personali (Il Garante) is Italy's independent data protection supervisory authority, established in 1996. Il Garante is Italy's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Il Garante is one of the most active enforcement authorities in the EU and internationally, including the temporary blocking of ChatGPT in Italy from 30 March 2023 to 28 April 2023 over GDPR compliance concerns regarding transparency, legal basis, age verification, and data accuracy. Key Italian national provisions: (1) Age of digital consent: Italy has set the age of consent for information society services at 14 years (GDPR Art. 8 allows member states to set between 13 and 16 years); data subjects under 14 require parental or guardian consent; (2) Codici Deontologici (deontological codes): Italy maintains a system of sector-specific deontological codes adopted by Il Garante that carry the force of law and provide specific rules for particular sectors including journalism and information activities, medical and health activities, scientific and biomedical research, statistical and scientific research, and private investigators; deontological codes are binding on entities operating in the relevant sector; (3) Employment context: specific national provisions on employment data processing, including employee monitoring (Art. 4 Statuto dei Lavoratori - Workers' Statute, Law No. 300/1970 as amended by Jobs Act 2015), trade union activity, and health surveillance; (4) Public interest and research: specific provisions for processing in the public interest, scientific research, statistics, and archiving, including Ethics Committee requirements for health data research; (5) Criminal data: the Codice Privacy restricts processing of personal data relating to criminal convictions and offences by private entities. Fines: GDPR administrative fines apply in Italy - up to EUR 20 million or 4% of global annual turnover for the most serious violations. Il Garante has imposed major GDPR fines including against Enel Energia, TIM, Vodafone, and Meta. Italy's data protection enforcement is among the most active in the EU.
Pillar: Cybersecurity · Authority: Garante per la protezione dei dati personali (Il Garante, Italy) · Version: 1.0.0 · Last updated:
Primary source: https://www.garanteprivacy.it/
SHA-256 integrity: 16cf72df137aa15af31aff995279b89c1c9d11b427ffc5e80d85cb09cd138ad6
Primary Citations — 6 traced to source
- Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, Italy, as amended by D.Lgs. 101/2018) - Italy's national GDPR implementation law; Codici Deontologici (sector deontological codes adopted by Il Garante) carry force of law for journalism, healthcare, research, and private investigation sectors; age of digital consent 14 years; criminal data restrictions for private entities
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Italy; fines up to EUR 20 million or 4% of global annual turnover; Il Garante is Italy's lead supervisory authority and EDPB member; 72-hour breach notification under Art. 33; DPIA under Art. 35 for high-risk processing
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access