Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Italy Codice Cross-Border + Retention
Cross-border transfer of personal data from Italy is governed by GDPR Chapter V + Italian Codice + Italian Garante guidance. (1) GDPR Chapter V Transfer Mechanisms: (a) Adequacy decisions per Commission - Andorra + Argentina + Canada (commercial organisations) + Faroe Islands + Guernsey + Israel + Isle of Man + Japan + Jersey + New Zealand + Republic of Korea + Switzerland + Uruguay + UK + US (Privacy Shield 1.0 Schrems II invalidated 2020 + Privacy Shield 2.0 Data Privacy Framework 2023 valid); (b) Standard Contractual Clauses (SCCs) - 2021 SCCs replace 2010 SCCs + 4 modules + new SCCs require Transfer Impact Assessment per Schrems II; (c) Binding Corporate Rules (BCRs) - Italian Garante BCR approval + EDPB coordination + intragroup transfer mechanism; (d) Code of Conduct + Certification + ad-hoc clauses; (e) derogations per Article 49 - explicit consent + contract necessity + public in
- GDPR Chapter V + adequacy + SCCs + BCRs + per transfer + records
- TIA per Schrems II + supplementary measures + per transfer + records + monitoring
- EU-US DPF + UK Bridge + Swiss DPF + records + recertification
- Italian sector retention + per code + records + schedule + audit
- EU Data Act + Italian implementation + non-personal + records + readiness
- Transfer to non-adequate country without SCCs or BCRs
- TIA absent for SCCs to non-adequate (Schrems II non-compliant)
- EU-US DPF certification not maintained (lapsed)
- Italian sector retention schedules not applied
- EU Data Act readiness not assessed (in-scope but unprepared)
Italy Codice Data Subject Rights
Articles 2-undecies + 2-duodecies + 2-terdecies of Codice Privacy establish Italian-specific data subject rights provisions. (1) Article 2-undecies Limitations on Data Subject Rights: Italian-specific limitations on GDPR Articles 15-22 rights including (a) protection of national security + defence + public security; (b) prevention investigation detection prosecution of criminal offences + including special handling for organised crime + terrorism; (c) protection of independence of the judiciary + judicial proceedings; (d) protection of professional secrecy + including legal professional privilege + medical confidentiality + journalist sources; (e) protection of personal data of others; (f) breach of contract + business confidentiality; (g) journalism + literary expression + artistic expression; (h) statistical archival research + historical archival research. Limitations applied case-by-
- Article 2-undecies + per right + proportionality + records + case-by-case + safeguards
- Article 2-duodecies + deceased persons + heirs + records + procedures + memorialisation
- Article 2-terdecies + 14-year consent + parental verification + records + audit
- GDPR Art 15-22 + Italian language + 30-day + records + complaint pathway
- Identity verification + Italian SPID/CIE/Codice Fiscale + records + audit
- Article 2-undecies limitations not properly justified
- Deceased persons rights overlooked (no procedure for heirs)
- Children consent age 16 applied (Italian Codice 14)
- Italian language responses absent
- Identity verification weak (no Italian-specific verification)
Italy Codice Garante + Enforcement
Articles 140-bis through 184 of Codice Privacy establish the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority) and enforcement framework. (1) Article 140-bis Garante per la Protezione dei Dati Personali: established under the Codice + independent + located in Rome + Chair (currently appointed for 7-year term) + Vice-Chair + Council Members + Plenary Sessions + Secretariat + International Cooperation + Italian language proceedings + Garante decisions published + public record. (2) Article 144 Complaints to the Garante: data subjects may lodge complaints with Garante for (a) violation of Codice Privacy or GDPR; (b) inappropriate processing; (c) data breach affecting individuals; (d) non-cooperation by controller/processor; (e) cross-border violations; (f) sectoral violations. Procedure: (a) written complaint in Italian language; (b) Garante receives + acknowl
- Garante engagement + decisions tracking + records + correspondence
- Article 144 complaint handling + Italian procedure + records + statistics
- Article 166 sanctions risk + EUR 20M exposure + records + Board awareness
- Article 167/170 criminal risk + Director/Officer + records + counsel
- EDPB coordination + One-Stop-Shop + LSA + records + cross-border
- No Garante engagement (operating below radar)
- Complaint handling slow (no Italian language + procedure)
- Sanctions risk not Board-level (EUR 20M exposure unmanaged)
- Criminal liability not assessed (Article 167/170 exposure)
- EDPB One-Stop-Shop not leveraged (Italian Garante not designated as LSA)
Italy Codice Lawful Basis + Notice
Articles 2-bis and 2-ter and related provisions of the Codice establish Italian-specific lawful processing requirements supplementing GDPR Article 6. (1) Article 2-bis Legal Basis: Italian national rules supplementing GDPR Article 6 lawful processing bases + including (a) Italian statutory authorisations; (b) Italian-specific public interest grounds; (c) Italian compatibility test interpretations; (d) Italian consent requirements + clarifying GDPR consent in Italian commercial + employment + healthcare contexts. (2) Article 2-ter Processing by Public Bodies: special provisions for processing by Italian public bodies + agencies + authorities including (a) public interest as lawful basis; (b) public service performance basis; (c) statutory authorisation requirements; (d) inter-agency data sharing; (e) administrative procedure data + Public Administration data. (3) Notice in Italian Languag
- Article 2-bis + GDPR Art 6 mapping + Italian basis + records + per activity
- Article 2-ter public body + statutory + records + per processing
- Italian notice + Art 13/14 + accessible + records + multilingual where appropriate
- Consent + Italian 14-year age + free/specific/informed + records + audit
- Italian derogations + journalism/research/religion/employment + records
- GDPR Article 6 applied without Italian Article 2-bis specifics
- Public body Article 2-ter overlooked (private-sector approach)
- Notice in English only (not Italian for Italian data subjects)
- Children consent age 16 applied (Italian Codice 14)
- Italian derogations missed (over-compliant or non-compliant)
Italy Codice Scope + GDPR Implementation
Italian Personal Data Protection Code (Codice in materia di protezione dei dati personali) Legislative Decree No. 196 of 30 June 2003 + subsequently amended by Legislative Decree No. 101 of 10 August 2018 to implement and align with EU GDPR Regulation (EU) 2016/679 + plus subsequent decrees. The Codice Privacy supersedes Law No. 675/1996 + builds on Italian Constitutional privacy doctrine + and serves as the comprehensive personal data protection framework in Italy. Constitutional Anchor: Italian Constitution Article 13 (personal liberty) + Article 14 (inviolability of domicile) + Article 15 (freedom and confidentiality of correspondence and communications) + Article 21 (freedom of expression balanced against privacy) + Italian Constitutional Court privacy doctrine (decisions including 38/1973 + 271/2005 + 320/2008) recognising privacy as fundamental right derived from inviolable persona
- Codice Privacy applicability + Italian data processing + records + scope
- GDPR + Codice Privacy compliance + records + dual framework
- Italian constitutional + civil code privacy + records + awareness
- Garante engagement + EDPB + records + correspondence
- Italian-specific derogations + per article + records + impact
- Codice Privacy treated as GDPR-only (Italian specifics ignored)
- Constitutional basis not understood
- Italian Civil Code privacy provisions overlooked
- No Garante engagement
- Italian derogations not implemented (over-restrictive or under-compliant)
Italy Codice Security + DPO
Italian Codice Privacy security framework supplements GDPR Article 32 with Italian-specific obligations. (1) Article 31 Designation of Chief Privacy Officer (CPO) / Data Protection Officer (DPO): mandatory for (a) public authorities and bodies (with sole exemption for courts in judicial capacity); (b) controllers/processors core activities consisting of regular and systematic monitoring of data subjects on a large scale; (c) controllers/processors core activities consisting of large-scale processing of special categories of data + criminal data. Italian-specific clarifications include (a) Italian Garante Decision on DPO 2018; (b) Italian public bodies must appoint DPO from public administration personnel or external; (c) DPO independence + reporting to highest management; (d) sufficient resources + qualifications + access to data + cooperation with Garante; (e) Italian Government DPO por
- Article 31 DPO + RPD + public bodies + records + qualifications + reporting line
- Article 34 breach notification + 72-hour Garante + ACN coord + records + drills
- DPIA + Italian threshold + methodology + records + per high-risk activity
- ROPA + Italian language + Garante template + records + comprehensive
- Joint controllers + processors + Italian SCC + records + subcontractor flow-down
- DPO appointed but not Italian-specific (no Garante registration)
- Breach notification not coordinated with ACN
- DPIA threshold list not consulted (Italian-specific triggers missed)
- ROPA in English only (Italian language required)
- Processor contracts not Italian-specific (no Italian SCC or governing law)
Italy Codice Special Categories
Italian Codice Privacy contains extensive sector-specific provisions for special categories of personal data and specific processing contexts. (1) Article 92 Medical Records: special provisions for healthcare data processing including (a) Italian National Health Service (SSN Servizio Sanitario Nazionale) data; (b) medical records (cartella clinica) creation + maintenance + access; (c) medical confidentiality (segreto professionale + medical privilege); (d) patient consent for treatment + research + insurance; (e) electronic health records (FSE Fascicolo Sanitario Elettronico) Italian national EHR; (f) telemedicine data; (g) clinical research per Italian Medicines Agency (AIFA) + Italian Medical Devices Agency; (h) genetic data per Garante Decision No. 8/2014; (i) biometric data; (j) ASL Local Health Authority data sharing; (k) hospital + nursing home data; (l) GP family doctor data. (2)
- Article 92 medical records + SSN + FSE + cartella clinica + records + audit
- Article 96 education + MIUR + student data + parental consent + records + audit
- Article 99 scientific research + ethics + anonymisation + records + ethics committee
- Article 101 historical research + Italian archives + records + ethics committee
- Workers Statute Art 4 + trade union + Labour Inspectorate + records + worker info
- Medical records GDPR-only (no Italian Health Code + SSN integration)
- Education sector GDPR-only (no MIUR or parental consent)
- Scientific research without Italian Code of Ethics
- Historical research without Italian archives integration
- Worker monitoring without trade union agreement (Article 4 violation)
Italy Codice ePrivacy
Articles 121-132 of Codice Privacy implement EU ePrivacy Directive (2002/58/EC + 2009/136/EC) and provide Italian-specific electronic communications privacy rules. (1) Article 121 Electronic Communications Services: definitions + scope + applicability + interaction with EU electronic communications regulatory framework + Italian Communications Code + AGCOM Authority for Communications Guarantees + Italian sector regulator + integration with EU Electronic Communications Code. (2) Article 122 Cookies and Similar Technologies: cookie consent + opt-in for non-essential cookies + Italian Garante Cookie Guidelines (last updated 2021 + 2024) - including (a) cookie banner requirements - immediately visible + clear + free choice between accept reject or granular control + dark pattern prohibition; (b) categorisation of cookies - strictly necessary (no consent) + functionality (consent recommended
- Article 122 cookie banner + Italian Garante guidelines + records + audit
- Article 130 direct marketing + soft opt-in + Public Opposition Register + records
- Article 132 traffic data + 6-year + anti-terror + records + judicial procedures
- Public Opposition Register verification + records + campaign-level check
- ePrivacy future + Italian implementation + records + tracking
- Cookie banner non-compliant with Italian Garante (cookie wall + dark patterns)
- Soft opt-in misapplied (no existing customer relationship)
- Public Opposition Register not checked before marketing
- Traffic data retention non-compliant with 6-year rule
- ePrivacy future not tracked (Italian transition unprepared)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.