GDPR for Italy
GDPR compliance for companies in Italy — Garante enforcement, Codice Privacy rules, and Italy-specific data protection requirements.
Data Protection Authority
Garante per la Protezione dei Dati Personali (Garante)
Key Requirements
- →Italy's Codice della Privacy supplements GDPR with additional national rules
- →Garante has taken high-profile actions against ChatGPT and Replika
- →Employee monitoring restricted under both GDPR and Italian Labour Law (Art. 4)
- →Italian DPO appointment rules are stricter than EU minimum
Italy's Garante per la Protezione dei Dati Personali gained international attention in 2023 when it temporarily banned ChatGPT for alleged GDPR violations — the first EU regulator to take such action against an AI system. This signals Italy's willingness to act aggressively on novel data processing technologies.
The Garante enforces GDPR alongside Italy's Codice della Privacy (Legislative Decree 196/2003, as amended), which predates GDPR and contains national derogations and additions. For companies with Italian operations, both frameworks apply simultaneously.
Employee monitoring in Italy is subject to one of the strictest regimes in Europe. Article 4 of the Italian Workers' Statute (Statuto dei Lavoratori) requires prior agreement with trade unions OR authorization from the labor inspectorate before any monitoring system that could capture employee data is deployed. This applies to email logging, internet access tracking, and badge/access systems. The GDPR layer adds consent and transparency requirements on top.
The Garante has specific guidance on AI and automated decision-making that goes beyond GDPR Article 22. Italian-specific rules require clear disclosure when AI is used in high-stakes decisions (employment, credit, insurance), and the right to human review must be implemented — not just documented.
For SaaS companies operating in Italy, cookie compliance follows the Garante's 2021 cookie guidelines, which require prior consent for analytics cookies, prohibit cookie walls, and mandate a "reject all" option at the same level as "accept all."
Check your GDPR compliance now
Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.
Run free GDPR compliance check →