GDPR in Italy: How the Codice Privacy and the Garante Fit Together

GDPR does not work differently in Italy than anywhere else in the European Union. Regolamento (UE) 2016/679 applies directly, exactly as written, to any organisation processing the personal data of people in Italy. What changes from one member state to the next is the layer of national law sitting underneath it, and in Italy that layer is genuinely active.
This page is not a general introduction to GDPR. For the mechanics of the Regulation itself, lawful bases, data subject rights, the accountability principle, see our GDPR explainer and the wider Italy data privacy overview. What follows is the Italy specific layer: how the Codice Privacy relates to the Regulation, what the Garante actually does, and the handful of rules that exist only because Italy chose to add them.
Information verified on 21 July 2026. This page provides general legal information and does not constitute legal advice for an individual situation.
GDPR direct effect, and a Codice Privacy that was amended, not replaced
Reg. UE 2016/679, the GDPR, applies directly in every EU member state without needing to be transposed into national law. Italy already had its own data protection statute, the Codice in materia di protezione dei dati personali (D.Lgs. 196/2003), which predates the GDPR by more than a decade.
Rather than repeal it, Italy amended it. D.Lgs. 10 agosto 2018, n. 101 rewrote large parts of the Codice Privacy, in force from 19 September 2018, to align it with the Regulation rather than duplicate or contradict it. Art. 2 of the Codice Privacy, as it now reads, states its own purpose plainly: it exists «per l'adeguamento dell'ordinamento nazionale alle disposizioni del regolamento», to adapt Italian law to the Regulation.
The result is two texts that interlock rather than compete. The GDPR supplies the substance: the lawful bases, the rights, the accountability duties, the enforcement ceilings. The Codice Privacy supplies the domestic detail the Regulation deliberately leaves to member states: who enforces it, the age at which a minor can consent, what happens to a deceased person's data, and a handful of sector rules the Regulation does not reach at all.
The Garante, briefly, and where the full procedure lives
The Garante per la protezione dei dati personali is the authority behind both texts in Italy. It supervises compliance, investigates, and can order an organisation to change how it processes data or pay an administrative fine.
If you are looking specifically for how to file a reclamo, a formal complaint, our companion page on the Garante covers the procedure, the deadlines, and what the authority can and cannot do for an individual complainant, in full. This page assumes that background and focuses instead on what is distinctly Italian in the substantive rules.
Scenario: the data of someone who has died
GDPR itself has nothing to say about a deceased person's data. The question is left to member states, and Italy answered it in art. 2-terdecies of the Codice Privacy.
Take a concrete case. A woman dies, and her adult son wants access to her cloud photo storage and wants a social media account closed. Under art. 2-terdecies, the rights the GDPR gives a living person, access, rectification, erasure and the rest, at artt. 15 to 22 of the Regulation, can be exercised after death by someone with their own interest in the matter, by someone acting to protect the deceased as their mandatario, or for protected family reasons.
The deceased can block this in advance, but only narrowly. The prohibition has to be an express written declaration given to the data controller, and it only applies to the direct offer of information society services, not to data generally. Even where a valid prohibition exists, it cannot be used to defeat a third party's own property rights arising from the death, or someone's right to defend themselves in court, and the declaration is revocable at any time.
Scenario: a minor and an app that wants their data
GDPR sets a default age of 16 for a minor to validly consent to their own data being processed for an information society service, art. 8 of the Regulation, but lets each member state lower it to any point down to 13. Italy set its own figure at 14, in art. 2-quinquies of the Codice Privacy.
A concrete example makes the line clear. A 13 year old downloads a social app and taps «accetto» during signup. Under Italian law that consent is not valid on its own: processing based on it is only lawful if a person exercising responsabilità genitoriale, parental responsibility, gave it instead. A 15 year old doing the identical thing can validly consent themselves, because they have already crossed Italy's threshold.
The same article adds a practical duty on the service. Where it targets minors directly, the information about the processing has to be written in language a minor can actually understand: clear, simple and complete, not the standard adult facing privacy policy.
Scenario: an employer wants to watch its workers
This is where GDPR meets a much older Italian statute, and readers often assume clearing one clears the other. It does not.
Art. 4 of the Statuto dei Lavoratori (L. 300/1970) governs impianti audiovisivi e altri strumenti di controllo, video systems and any other tool capable of monitoring workers remotely, even where surveillance is not the tool's main purpose. Installing one for organisational, production, safety or asset protection reasons requires an accordo collettivo with the works council first. Failing an agreement, the employer needs authorisation from the local Ispettorato Nazionale del Lavoro instead. Two categories sit outside this requirement: tools a worker uses to actually do their job, and ordinary access or attendance recorders.
A worked example: a warehouse installs CCTV covering its loading bay, which incidentally frames the packing stations where staff work. That needs the art. 4 procedure, agreement or Ispettorato authorisation, before it goes live. A separate badge reader logging when staff enter the building sits inside the carve out and does not need it.
Clearing art. 4 is only step one. The same article says the information collected can be used for employment purposes only where the worker was given adeguata informazione, adequate notice, of how the tools work and how monitoring happens, and only nel rispetto of the Codice Privacy. In practice that means a GDPR compliant informativa on top of the labour law authorisation, not instead of it. An employer with a lawfully authorised camera that never told staff it existed has not satisfied the Codice Privacy side of the rule.
A few more places the Codice Privacy still speaks for itself
Two further rules round out the genuinely Italian layer. Special categories of data, genetic, biometric and health data, get an extra safeguard under art. 2-septies: the Garante has to issue and periodically update «misure di garanzia», specific safeguards for processing these categories, revisited at least every two years and put out for public consultation first.
Art. 2-quaterdecies adds an organisational rule of its own: a data controller or processor can formally assign specific data processing tasks to named individuals acting under its authority, a mechanism the Regulation does not spell out itself.
None of this changes the fine ceilings GDPR sets. Where the Garante does move to a sanction, art. 83 of the Regulation still caps it at 20 million euro or 4 percent of an organisation's worldwide annual turnover, whichever is higher, for the most serious infringements, exactly as it would anywhere else in the Union.
Where an Italian reader actually goes
For the reclamo procedure itself, see the Garante companion page. For the mechanics of GDPR generally, lawful bases, the rights catalogue, the accountability principle, see our GDPR explainer, and for the broader country picture see the Italy data privacy overview.
Two adjacent topics worth knowing about: home security cameras in Italy, where the private, non employment version of the camera question lives, and recording conversations in Italy, a related but distinct question about capturing, rather than storing, someone else's information. For the fuller range of Italy privacy coverage, see the Italy privacy law section.
Frequently Asked Questions
Does GDPR apply differently in Italy than in other EU countries?
No. Regolamento (UE) 2016/679 applies directly and identically across the European Union. What differs is the national layer underneath it: in Italy, the Codice Privacy (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018), which supplies the enforcement authority, a handful of derogations the Regulation leaves to member states, and rules on matters GDPR does not address at all, such as a deceased person's data.
Is the Codice Privacy still in force alongside GDPR?
Yes. It was amended, not repealed, by D.Lgs. 101/2018, in force from 19 September 2018. Its own art. 2 now states that its purpose is to adapt Italian law to the Regulation, not to duplicate or override it.
At what age can a minor consent to an app processing their own data in Italy?
14. Art. 2-quinquies of the Codice Privacy set Italy's threshold at 14, below the GDPR default of 16. Below that age, only a person exercising parental responsibility can validly consent to processing tied to an information society service offered directly to the child.
What happens to someone's personal data after they die?
GDPR does not cover it. Under art. 2-terdecies of the Codice Privacy, rights such as access, rectification and erasure can be exercised after death by someone with their own interest in the matter, by a mandatario acting to protect the deceased, or for protected family reasons, unless the deceased left an express written prohibition limited to information society services.
Can my employer install cameras or monitoring software at work?
Only after clearing two separate requirements. Art. 4 of the Statuto dei Lavoratori requires either a collective agreement with the works council or authorisation from the Ispettorato Nazionale del Lavoro before installing a tool capable of monitoring workers remotely. Separately, the Codice Privacy requires the employer to give workers adequate notice before any data it collects can actually be used against them.
How do I complain to the Garante about a GDPR breach in Italy?
By filing a reclamo, a formal complaint under GDPR art. 77. The procedure, where to send it, what it must contain and what the Garante can and cannot do for an individual complainant, is covered in full on our companion page about the Garante.
What are the maximum GDPR fines in Italy?
The same ceilings that apply across the EU: up to 20 million euro or 4 percent of an organisation's worldwide annual turnover, whichever is higher, for the most serious infringements, with lower caps for less severe categories. The Garante enforces these domestically.
Where can I read about how GDPR works in general, not just in Italy?
Our GDPR explainer covers the Regulation's mechanics directly, lawful bases, the rights catalogue and the accountability principle, without the Italy specific layer this page focuses on.
Sources and References
- Regolamento (UE) 2016/679 (GDPR)(eur-lex.europa.eu).gov
- Decreto Legislativo 30 giugno 2003, n. 196, Codice in materia di protezione dei dati personali(normattiva.it).gov
- Decreto Legislativo 10 agosto 2018, n. 101 (adeguamento del Codice Privacy al Regolamento UE 2016/679)(normattiva.it).gov
- art. 2-quinquies Codice Privacy, Consenso del minore in relazione ai servizi della società dell'informazione(normattiva.it).gov
- art. 2-terdecies Codice Privacy, Diritti riguardanti le persone decedute(normattiva.it).gov
- art. 2-septies Codice Privacy, Misure di garanzia per il trattamento dei dati genetici, biometrici e relativi alla salute(normattiva.it).gov
- art. 4, Legge 20 maggio 1970, n. 300 (Statuto dei Lavoratori), Impianti audiovisivi e altri strumenti di controllo(normattiva.it).gov
- Regolamento (UE) 2016/679 (GDPR), art. 8 (Condizioni applicabili al consenso dei minori)(eur-lex.europa.eu).gov
- Regolamento (UE) 2016/679 (GDPR), art. 83 (Condizioni generali per infliggere sanzioni amministrative pecuniarie)(eur-lex.europa.eu).gov
- Garante per la protezione dei dati personali, Compiti(garanteprivacy.it).gov
- Italy's data privacy laws overview(recordinglaw.com)
- What is GDPR?(recordinglaw.com)