The Garante Privacy: Italy's Data Protection Authority and How to Complain

The Garante per la protezione dei dati personali is the independent authority that oversees data protection in Italy. Most people who search for it want one specific answer: how to actually file a reclamo, a formal complaint, and what happens after they do.
Information verified on 20 July 2026. This page provides general legal information and does not constitute legal advice for an individual situation.
Jurisdiction scope: This article covers the Garante per la protezione dei dati personali, the data protection authority for Italy. A complaint about an organisation established mainly in a different EU country may fall to that country's own supervisory authority instead, depending on where the relevant processing decisions are made.
What the Garante is and what it does
The Garante per la protezione dei dati personali is Italy's independent administrative authority for personal data protection. It supervises how public and private organisations collect, use, store, and share personal data, under the GDPR (Regolamento UE 2016/679) and the Codice Privacy (D.Lgs. 196/2003), as amended, not replaced, by D.Lgs. 101/2018, which brought Italian law into line with the GDPR from 19 September 2018.
Its stated tasks include checking that data processing complies with the GDPR and Italian law, prescribing corrective measures to organisations where needed, and examining reclami from the public. It also has genuine investigative and corrective powers: it can order an organisation to change how it processes data, restrict or ban a processing activity, and impose administrative fines.
What it is not is a court that awards money to an individual complainant, and that distinction shapes everything below.
Reclamo, segnalazione, ricorso: three different words, three different tools
The Garante's own materials distinguish several routes an individual can take, and mixing them up is a common source of frustration.
A reclamo is the formal complaint procedure under art. 77 of the GDPR. It is a documented act describing an alleged breach of data protection rules, and filing one obliges the Garante to examine it and, eventually, to tell the complainant the outcome or status of the file. This is the route this article focuses on, because it is what almost everyone searching for "come fare un reclamo al Garante" actually needs.
A segnalazione is a less formal alert or report. It flags a possible issue to the Garante without the same formal examination guarantee a reclamo carries, and it is a lighter-weight option when someone wants to raise a concern without building a full case file.
A ricorso is a separate and narrower procedure, historically used to ask the Garante to resolve certain specific rights disputes directly. Today, most individual matters that once went through a ricorso are handled through the reclamo route described here, so a reclamo is the correct starting point for the overwhelming majority of readers.
Before you file: contact the data controller first
The Garante's own reclamo form asks whether the complainant already raised the issue with the titolare del trattamento (the data controller, meaning the organisation responsible for the data), and if so, what happened.
This is worth doing in practice, for two reasons. Many issues, particularly a request to access, correct, or delete your own data, get resolved once an organisation receives a clear written request. And a documented prior attempt strengthens a reclamo that does proceed, because it shows the organisation had a genuine opportunity to fix the problem first.
Under the GDPR, an organisation that receives a data-subject rights request generally has one month to respond, counted from the date it receives the request. That period can be extended by up to two further months for a complex request, but only if the organisation tells the requester about the extension within the original one-month window. As a worked example: a request received on 3 March 2026 must ordinarily be answered by 3 April 2026, or by 3 June 2026 at the latest if the organisation validly extends and says so before 3 April. If the deadline passes with no response, or the organisation refuses without a valid reason, that documented failure is itself solid grounds for a reclamo.
What a reclamo must contain and how to file it
A reclamo should identify the data controller involved, in enough detail for the Garante to know who is being complained about. It should include the complainant's own identity and contact details. It should set out the facts clearly, including any prior contact already made with the controller and its outcome, and it should point to the specific data protection rule believed to have been breached, where the complainant is able to identify one.
It can be filed three ways: by certified email (PEC) to protocollo@pec.gpdp.it, by registered post to Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, or delivered in person at the same address. Filing is free.
A reclamo, and any power of attorney if one is used (a lawyer or a non-profit body can file on someone's behalf), must be signed, either with an authenticated signature, a digital signature, or an ordinary signature accompanied by a copy of a valid ID document.
What happens after you file
Once received, a reclamo goes through a preliminary review (istruttoria). Depending on what that review finds, it can lead to a full administrative procedure under the powers the GDPR gives the Garante at art. 58: these range from a simple reminder or warning to the organisation, up to an order to bring processing into compliance, a temporary or permanent restriction on processing, or an administrative fine.
There is no fixed number of days by which a reclamo must be fully resolved, and this article will not invent one. The Garante's own activity figures, set out below, are the best available evidence of how much it actually closes in a year.
What the Garante can and cannot do about YOUR money
This is the point most complainants get wrong, so it is worth stating plainly: the Garante cannot order an organisation to pay compensation to the person who complained. Its corrective tools run toward the organisation's practices, and where a fine is imposed, that fine is paid to the State, not to the complainant.
Someone who has suffered real, provable harm, financial loss, distress, or another concrete harm, from a data protection breach has a separate route: art. 82 of the GDPR lets that person bring a civil claim before an ordinary court (a tribunale) against the controller or processor responsible. The two routes can run side by side. A reclamo targets the organisation's compliance and can lead to a Garante order or sanction; a civil claim targets compensation for the individual, and only a judge can award it, after the claimant proves the breach, the harm, and the link between them.
The GDPR fine ceilings, and what they mean in practice
Where the Garante does move to a sanction, the GDPR sets the outer limits. For the most serious infringements, fines can reach 20 million euro or 4 percent of an organisation's total worldwide annual turnover, whichever figure is higher; less severe categories of infringement are capped lower.
To make that concrete: for an organisation with 50 million euro in worldwide annual turnover, 4 percent works out at 2 million euro, so the flat 20 million euro figure is the higher of the two and is therefore the one that applies. The percentage overtakes the flat figure only once worldwide turnover passes roughly 500 million euro. For most companies, in other words, the 20 million euro number is the real ceiling, and it is the larger multinationals whose exposure is set by the percentage instead. Most individual complaints, about an unanswered access request or an unwanted marketing call, are nowhere near either ceiling, since the Garante scales the sanction to the actual breach, not to the statutory maximum.
Is the Garante actually active? The 2025 numbers
Some readers reasonably wonder whether a reclamo goes anywhere at all. The Garante's own 2025 activity report, presented in mid-2026, gives a documented answer: 807 provvedimenti collegiali adopted over the year, 506 provvedimenti correttivi e sanzionatori among them, and more than 37 million euro in sanctions recorded. It answered 4.288 reclami and resolved 145.846 segnalazioni, carried out 130 ispezioni, registered 2.415 data breach notifications (up about 10 percent on 2024), and referred 65 matters to the criminal justice authorities.
Those figures describe the Authority's overall workload across every subject matter it covers, not a promise about any specific complaint's outcome, timeline, or size of any resulting sanction. Treat them as context for how active the Garante genuinely is, not as a forecast for an individual case.
Related Italy privacy topics
Complaints frequently arise from a specific situation, such as a camera that reaches beyond its owner's own property; our companion guide to home security cameras in Italy covers exactly where that boundary sits and what art. 615-bis c.p. adds on top of the GDPR question. For the wider framework Italian data protection sits inside, see our overview of Italy's data privacy laws. For the fuller range of Italy coverage on this site, see the Italy hub.
Frequently Asked Questions
How do I file a reclamo with the Garante?
By certified email (PEC) to protocollo@pec.gpdp.it, by registered post to Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, or delivered in person at the same address. Filing is free, and the reclamo should identify the data controller, your own details, the facts, and the rule you believe was breached.
Does the Garante pay me money if my reclamo succeeds?
No. The Garante can order an organisation to comply and, in serious cases, impose a fine, but that fine goes to the State, not the complainant. Getting compensation for real harm requires a separate civil claim before a court under GDPR art. 82.
What is the difference between a reclamo, a segnalazione, and a ricorso?
A reclamo is the formal art. 77 GDPR complaint, and filing one obliges the Garante to examine it. A segnalazione is a lighter, less formal alert. A ricorso is a separate, narrower procedure that most individual matters no longer use, since the reclamo route now covers them.
Do I have to contact the company before filing a reclamo?
It is not an absolute legal bar, but the Garante's own reclamo form asks whether you already contacted the data controller and what happened, so doing that first and documenting it strengthens the reclamo.
How long does the Garante take to resolve a complaint?
There is no fixed statutory deadline for closing a reclamo. The Garante's 2025 activity report shows it answered 4.288 reclami and adopted 807 provvedimenti collegiali that year, which shows genuine activity, but it is not a promise about how quickly any single case will move.
What are the maximum GDPR fines the Garante can impose?
Up to 20 million euro or 4 percent of an organisation's worldwide annual turnover, whichever is higher, for the most serious infringements, with lower ceilings for less severe categories. Most individual complaints result in far smaller sanctions, scaled to the actual breach.
Is the Garante the same as a court?
No. It is an independent administrative authority with investigative and corrective powers, including fines paid to the State. It cannot award compensation to an individual. A claim for money damages goes to an ordinary court under GDPR art. 82 instead.
What can I complain to the Garante about?
Any suspected breach of the GDPR or the Codice Privacy by a data controller or processor, from an unanswered access request to an unlawfully placed camera. Our guide to home security cameras in Italy covers one common example.
Sources and References
- Garante per la protezione dei dati personali, Compiti(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Reclami(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Modello di reclamo(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Segnalazioni e reclami(garanteprivacy.it).gov
- Garante per la protezione dei dati personali, Relazione sull’attività 2025, sintesi per la stampa(garanteprivacy.it).gov
- Regolamento (UE) 2016/679 (GDPR), art. 77 (Diritto di proporre reclamo all’autorità di controllo)(eur-lex.europa.eu).gov
- Regolamento (UE) 2016/679 (GDPR), art. 82 (Diritto al risarcimento e responsabilità)(eur-lex.europa.eu).gov
- Regolamento (UE) 2016/679 (GDPR), art. 83 (Condizioni generali per infliggere sanzioni amministrative pecuniarie)(eur-lex.europa.eu).gov
- Decreto Legislativo 30 giugno 2003, n. 196, Codice in materia di protezione dei dati personali(normattiva.it).gov
- Decreto Legislativo 10 agosto 2018, n. 101(normattiva.it).gov