Italy
The Garante Privacy: Italy's Data Protection Authority and How to Complain
Independently fact-checked against primary sources (last audited July 20, 2026). · 10 primary sources cited on this page. How we verify our legal content

The Garante per la protezione dei dati personali is the independent authority that oversees data protection in Italy. Most people who search for it want one specific answer: how to actually file a reclamo, a formal complaint, and what happens after they do.
Information verified on 20 July 2026. This page provides general legal information and does not constitute legal advice for an individual situation.
Jurisdiction scope: This article covers the Garante per la protezione dei dati personali, the data protection authority for Italy. A complaint about an organisation established mainly in a different EU country may fall to that country's own supervisory authority instead, depending on where the relevant processing decisions are made.
What the Garante is and what it does
The Garante per la protezione dei dati personali is Italy's independent administrative authority for personal data protection. It supervises how public and private organisations collect, use, store, and share personal data, under the GDPR (Regolamento UE 2016/679) and the Codice Privacy (D.Lgs. 196/2003), as amended, not replaced, by D.Lgs. 101/2018, which brought Italian law into line with the GDPR from 19 September 2018.
Its stated tasks include checking that data processing complies with the GDPR and Italian law, prescribing corrective measures to organisations where needed, and examining reclami from the public. It also has genuine investigative and corrective powers: it can order an organisation to change how it processes data, restrict or ban a processing activity, and impose administrative fines.
What it is not is a court that awards money to an individual complainant, and that distinction shapes everything below.
Reclamo, segnalazione, ricorso: three different words, three different tools
The Garante's own materials distinguish several routes an individual can take, and mixing them up is a common source of frustration.
A reclamo is the formal complaint procedure under art. 77 of the GDPR. It is a documented act describing an alleged breach of data protection rules, and filing one obliges the Garante to examine it and, eventually, to tell the complainant the outcome or status of the file. This is the route this article focuses on, because it is what almost everyone searching for "come fare un reclamo al Garante" actually needs.
A segnalazione is a less formal alert or report. It flags a possible issue to the Garante without the same formal examination guarantee a reclamo carries, and it is a lighter-weight option when someone wants to raise a concern without building a full case file.
A ricorso is a separate and narrower procedure, historically used to ask the Garante to resolve certain specific rights disputes directly. Today, most individual matters that once went through a ricorso are handled through the reclamo route described here, so a reclamo is the correct starting point for the overwhelming majority of readers.
Before you file: contact the data controller first
The Garante's own reclamo form asks whether the complainant already raised the issue with the titolare del trattamento (the data controller, meaning the organisation responsible for the data), and if so, what happened.
This is worth doing in practice, for two reasons. Many issues, particularly a request to access, correct, or delete your own data, get resolved once an organisation receives a clear written request. And a documented prior attempt strengthens a reclamo that does proceed, because it shows the organisation had a genuine opportunity to fix the problem first.
Under the GDPR, an organisation that receives a data-subject rights request generally has one month to respond, counted from the date it receives the request. That period can be extended by up to two further months for a complex request, but only if the organisation tells the requester about the extension within the original one-month window. As a worked example: a request received on 3 March 2026 must ordinarily be answered by 3 April 2026, or by 3 June 2026 at the latest if the organisation validly extends and says so before 3 April. If the deadline passes with no response, or the organisation refuses without a valid reason, that documented failure is itself solid grounds for a reclamo.
What a reclamo must contain and how to file it
A reclamo should identify the data controller involved, in enough detail for the Garante to know who is being complained about. It should include the complainant's own identity and contact details. It should set out the facts clearly, including any prior contact already made with the controller and its outcome, and it should point to the specific data protection rule believed to have been breached, where the complainant is able to identify one.
It can be filed three ways: by certified email (PEC) to protocollo@pec.gpdp.it, by registered post to Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, or delivered in person at the same address. Filing is free.
A reclamo, and any power of attorney if one is used (a lawyer or a non-profit body can file on someone's behalf), must be signed, either with an authenticated signature, a digital signature, or an ordinary signature accompanied by a copy of a valid ID document.
What happens after you file
Once received, a reclamo goes through a preliminary review (istruttoria). Depending on what that review finds, it can lead to a full administrative procedure under the powers the GDPR gives the Garante at art. 58: these range from a simple reminder or warning to the organisation, up to an order to bring processing into compliance, a temporary or permanent restriction on processing, or an administrative fine.
There is no fixed number of days by which a reclamo must be fully resolved, and this article will not invent one. The Garante's own activity figures, set out below, are the best available evidence of how much it actually closes in a year.
What the Garante can and cannot do about YOUR money
This is the point most complainants get wrong, so it is worth stating plainly: the Garante cannot order an organisation to pay compensation to the person who complained. Its corrective tools run toward the organisation's practices, and where a fine is imposed, that fine is paid to the State, not to the complainant.
Someone who has suffered real, provable harm, financial loss, distress, or another concrete harm, from a data protection breach has a separate route: art. 82 of the GDPR lets that person bring a civil claim before an ordinary court (a tribunale) against the controller or processor responsible. The two routes can run side by side. A reclamo targets the organisation's compliance and can lead to a Garante order or sanction; a civil claim targets compensation for the individual, and only a judge can award it, after the claimant proves the breach, the harm, and the link between them.
The GDPR fine ceilings, and what they mean in practice
Where the Garante does move to a sanction, the GDPR sets the outer limits. For the most serious infringements, fines can reach 20 million euro or 4 percent of an organisation's total worldwide annual turnover, whichever figure is higher; less severe categories of infringement are capped lower.
To make that concrete: for an organisation with 50 million euro in worldwide annual turnover, 4 percent works out at 2 million euro, so the flat 20 million euro figure is the higher of the two and is therefore the one that applies. The percentage overtakes the flat figure only once worldwide turnover passes roughly 500 million euro. For most companies, in other words, the 20 million euro number is the real ceiling, and it is the larger multinationals whose exposure is set by the percentage instead. Most individual complaints, about an unanswered access request or an unwanted marketing call, are nowhere near either ceiling, since the Garante scales the sanction to the actual breach, not to the statutory maximum.
Is the Garante actually active? The 2025 numbers
Some readers reasonably wonder whether a reclamo goes anywhere at all. The Garante's own 2025 activity report, presented in mid-2026, gives a documented answer: 807 provvedimenti collegiali adopted over the year, 506 provvedimenti correttivi e sanzionatori among them, and more than 37 million euro in sanctions recorded. It answered 4.288 reclami and resolved 145.846 segnalazioni, carried out 130 ispezioni, registered 2.415 data breach notifications (up about 10 percent on 2024), and referred 65 matters to the criminal justice authorities.
Those figures describe the Authority's overall workload across every subject matter it covers, not a promise about any specific complaint's outcome, timeline, or size of any resulting sanction. Treat them as context for how active the Garante genuinely is, not as a forecast for an individual case.
Related Italy privacy topics
Complaints frequently arise from a specific situation, such as a camera that reaches beyond its owner's own property; our companion guide to home security cameras in Italy covers exactly where that boundary sits and what art. 615-bis c.p. adds on top of the GDPR question. For the wider framework Italian data protection sits inside, see our overview of Italy's data privacy laws. For the fuller range of Italy coverage on this site, see the Italy hub.
Frequently Asked Questions
How do I file a reclamo with the Garante?
By certified email (PEC) to protocollo@pec.gpdp.it, by registered post to Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, or delivered in person at the same address. Filing is free, and the reclamo should identify the data controller, your own details, the facts, and the rule you believe was breached.
Does the Garante pay me money if my reclamo succeeds?
No. The Garante can order an organisation to comply and, in serious cases, impose a fine, but that fine goes to the State, not the complainant. Getting compensation for real harm requires a separate civil claim before a court under GDPR art. 82.
What is the difference between a reclamo, a segnalazione, and a ricorso?
A reclamo is the formal art. 77 GDPR complaint, and filing one obliges the Garante to examine it. A segnalazione is a lighter, less formal alert. A ricorso is a separate, narrower procedure that most individual matters no longer use, since the reclamo route now covers them.
Do I have to contact the company before filing a reclamo?
It is not an absolute legal bar, but the Garante's own reclamo form asks whether you already contacted the data controller and what happened, so doing that first and documenting it strengthens the reclamo.
How long does the Garante take to resolve a complaint?
There is no fixed statutory deadline for closing a reclamo. The Garante's 2025 activity report shows it answered 4.288 reclami and adopted 807 provvedimenti collegiali that year, which shows genuine activity, but it is not a promise about how quickly any single case will move.
What are the maximum GDPR fines the Garante can impose?
Up to 20 million euro or 4 percent of an organisation's worldwide annual turnover, whichever is higher, for the most serious infringements, with lower ceilings for less severe categories. Most individual complaints result in far smaller sanctions, scaled to the actual breach.
Is the Garante the same as a court?
No. It is an independent administrative authority with investigative and corrective powers, including fines paid to the State. It cannot award compensation to an individual. A claim for money damages goes to an ordinary court under GDPR art. 82 instead.
What can I complain to the Garante about?
Any suspected breach of the GDPR or the Codice Privacy by a data controller or processor, from an unanswered access request to an unlawfully placed camera. Our guide to home security cameras in Italy covers one common example.
Updates
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
General Data Protection Regulation (GDPR)
Art. 77Right to lodge a complaint with a supervisory authorityIn forcecited in 6 of our articles
1. Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. 2. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 15 court opinionsMost recently applied by a court: 2025
Leading cases:
- Österreichische Datenschutzbehörde v F R (Court of Justice of the European Union 2025, C-416/23)
- Nemzeti Adatvédelmi és Információszabadság Hatóság v UC (Court of Justice of the European Union 2024, C-169/23)
- Österreichische Datenschutzbehörde v WK (Court of Justice of the European Union 2024, C-33/22)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to File a Data Protection Complaint (Beschwerde) with Austria's DSB, Italian Privacy Law: An Overview
Art. 82Right to compensation and liabilityIn forcecited in 2 of our articles
1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered. 2. Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller. 3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage. 4. Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject. 5.
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 21 court opinionsMost recently applied by a court: 2025
Leading cases:
- AT and BT v PS GbR and Others (Court of Justice of the European Union 2024, C-590/22)
- GP v juris GmbH (Court of Justice of the European Union 2024, C-741/21)
- BL v MediaMarktSaturn Hagen-Iserlohn GmbH (Court of Justice of the European Union 2024, C-687/21)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Art. 83General conditions for imposing administrative finesIn forcecited in 9 of our articles
1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. 2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; (b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
Official text (excerpt) · last checked 2026-08-12 · Read the full text in our law library · Verify at eur-lex.europa.eu
Cited in 13 court opinionsMost recently applied by a court: 2026
Leading cases:
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin (Court of Justice of the European Union 2023, C-807/21)
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija (Court of Justice of the European Union 2023, C-683/21)
- Criminal proceedings against ILVA A/S (Court of Justice of the European Union 2025, C-383/23)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: GDPR in Italy: How the Codice Privacy and the Garante Fit Together, GDPR DPO Requirements: Do You Need a Data Protection Officer? (2026), Italy Recording Laws 2025: One-Party Consent, Penalties and GDPR
Search our record of EU legislation — GDPR, ePrivacy, AI Act and more, from EUR-Lex →
Sources and References
- Garante per la protezione dei dati personali, Compiti(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Reclami(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Modello di reclamo(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Segnalazioni e reclami(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Relazione sull’attività 2025, sintesi per la stampa(garanteprivacy.it).gov
- Regolamento (UE) 2016/679 (GDPR), art. 77 (Diritto di proporre reclamo all’autorità di controllo)(eur-lex.europa.eu).gov
- Regolamento (UE) 2016/679 (GDPR), art. 82 (Diritto al risarcimento e responsabilità)(eur-lex.europa.eu).gov
- Regolamento (UE) 2016/679 (GDPR), art. 83 (Condizioni generali per infliggere sanzioni amministrative pecuniarie)(eur-lex.europa.eu).gov
- Decreto Legislativo 30 giugno 2003, n. 196, Codice in materia di protezione dei dati personali(normattiva.it).gov
- Decreto Legislativo 10 agosto 2018, n. 101(normattiva.it).gov