IT — Country Profile

Italy

108TOTAL
108OFFICIAL SOURCES
15TOPIC AREAS
Law / Act12
Executive Order22
Policy / Guidance8
National Strategy3
Standard / Framework4
International Agreement5
Working Paper3
Court Case3
Other48
25 MAR 2026 · Working Paper

Inquiry into rules on methodologies for measuring content disseminated by digital platforms (Resolution no. 199/25/CONS)

On 25 March 2026, the Italian Communications Regulatory Authority (AGCOM) adopted Resolution No. 87/26/CONS, concluding the inquiry into audience measurement in the digital ecosystem opened under Resolution No. 199/25/CONS. The inquiry examined methodologies for measuring content distributed by digital platforms and operators whose content is consumed exclusively in digital environments and that are not yet included within a Joint Industry Committee (JIC). The inquiry involved 27 parties acro...

Official materialContent ModerationOfficial source · agcom.it ↗
03 MAR 2026 · Policy / Guidance

Italy proposes governance model on AI and work

" AI and Work: Managing transformation, Multiplying Opportunities " was the theme of today's work which took place at the Tempio di Vibia Sabina e Adriano, headquarters of the Rome Chamber of Commerce, as well as at the INPS and INAIL headquarters at Palazzo Wedekind and Palazzo Brasini, respectively. The Ministry of Labour and Social Policies supported the event in association with the National Social Security Institute and the National Institute for Insurance against Accidents at Work.

Official materialHuman Rights & Ethics ·Labor & WorkforceOfficial source · lavoro.gov.it ↗
24 FEB 2026 · Other

Data Protection Authority and National Labour Inspectorate investigation into Amazon over alleged unlawful worker monitoring and data processing

On 24 February 2026, the Italian Data Protection Authority (GPDP) issued provision no. 107 against Amazon after a joint investigation with the National Labour Inspectorate and the Financial Guard’s Special Privacy and Technological Fraud Unit. The investigation focused on Amazon’s logistics hubs in Passo Corese and Castel San Giovanni, following inspections in February 2026. The GPDP found that managers had recorded sensitive information about employees in a free-text field of the XX platform...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
21 FEB 2026 · International Agreement

Italy, India, Kenya sign landmark AI cooperation agreement to advance development in Africa

Primary source (ict.go.ke) dated 21 February 2026 in IT. See linked source for full text.

Primary legal sourceTrade & Investment ·Logistics & InfrastructureOfficial source · ict.go.ke ↗
17 FEB 2026 · Other

Competition and Market Authority proceedings against Mistral AI addressing unfair commercial practices

On 17 February 2026, the Competition and Market Authority (AGCM) closed its investigation into Mistral AI regarding its AI service “Le Chat” and the risk of so-called “hallucinations,” where AI outputs may be inaccurate or misleading. The investigation, opened in June 2025, examined whether Mistral adequately informed users about this risk. Mistral, a French start-up founded in April 2023, argued that Italian consumer law applied only after it actively promoted the service to Italian users fr...

Official materialConsumer ProtectionOfficial source · agcm.it ↗
29 JAN 2026 · Other

Data Protection Authority investigation into e-Campus Online University over allegations of unlawful biometric data processing

On 29 January 2026, the Data Protection Authority ruled that the processing of biometric data by e-Campus Online University for student attendance verification was unlawful and imposed an administrative fine of EUR 50’000. The case followed a report that the university used a facial recognition system to identify participants and verify attendance during online teaching qualification courses. The Authority found that the consent obtained from students was not freely given, citing an imbalance...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
19 JAN 2026 · Executive Order

Communications Regulatory Authority list of general interest services pursuant to resolution no. 250/25/CONS

On 19 January 2026, the Communications Regulatory Authority (AGCOM) adopted the list of audiovisual and radio media services of general interest distributed online in accordance with resolution no. 250/25/CONS. The list implements the guidelines regarding the prominence of general interest services, which aim to ensure that specific media content remains accessible and visible to the public on digital interfaces. The list is organised into five distinct categories: services provided by the pu...

Primary legal sourceContent ModerationOfficial source · agcom.it ↗
08 JAN 2026 · Other

Garante issues warning relating to deepfake risks of Grok, ChatGPT, Clothoff and other similar services

Deepfake, il Garante avverte: a rischio diritti e libertà fondamentali Dopo il blocco di Clothoff, l’Autorità richiama l’attenzione sull’uso di Grok e altri servizi analoghi

Official materialDeepfakes ·Data Privacy & Protection ·Online Safety & Child ProtectionOfficial source · garanteprivacy.it ↗
22 DEC 2025 · International Agreement

Competition Authority investigation into Meta's decision to pre-install its AI service on WhatsApp assessing its compliance with Treaty of Functioning of European Union

On 22 December 2025, the Competition Authority ordered Meta to suspend the application of the new business solution terms for WhatsApp insofar as those terms would produce effects in Italy. WhatsApp's business solution terms, introduced on 15 October 2025, restrict access for third-party AI service providers whose primary functionality is AI chatbots or assistants. The Authority concluded the terms are likely to limit production, outlets, or technical development in the AI ​​Chatbot services ...

Primary legal sourceCompetitionOfficial source · agcm.it ↗
18 DEC 2025 · Other

Warning to users of artificial intelligence services regarding deepfakes

On 18 December 2025, the Guarantor for the Protection of Personal Data (GPDP) issued a warning to users of artificial intelligence services regarding the generation of content using third-party voices or images via artificial intelligence technologies (deepfakes). The GPDP noted that such content potentially qualifies as personal data under Article 4(1) of Regulation (EU) 2016/679 (GDPR) and may constitute biometric data where processed for unique identification. The GPDP found that such proc...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
26 NOV 2025 · Other

Italy antitrust watchdog may curb Meta as WhatsApp AI probe widens

According to the Authority, the new WhatsApp Business Solution Terms, introduced on 15 October 2025, and the integration of new Meta AI interaction tools or features into WhatsApp may limit production, market access or technical developments in the AI Chatbot services market.

Official materialAntitrust & CompetitionOfficial source · en.agcm.it ↗
07 OCT 2025 · Other

Communications Authority investigation into Meta over alleged failure to adequately compensate GEDI publishing group

On 10 July 2025, the Italian Communications Authority (AGCOM) issued an order setting the fair compensation Meta must pay for using GEDI publishing group’s journalistic content on Facebook. The decision, adopted under Regulation No. 3/23/CONS after the parties failed to reach an agreement, rejected both sides’ financial proposals and determined compensation based on Meta’s advertising revenues linked to GEDI content, net of redirect traffic benefits. A rate of up to 70% was applied, with the ...

Official materialContent ModerationOfficial source · agcom.it ↗
07 OCT 2025 · Law / Act

Law on protection of minors in digital dimension (Act No. 1136)

On 7 October 2025, the Italian Data Protection Authority (DPA) appeared before the 8th Committee of the Senate on the updated text adopted for Senate Bill No. 1136 on the protection of minors in the digital environment. The revised text allows the activation of social media and video-sharing accounts only for persons over 15 years of age and assigns the DPA the responsibility for verifying and sanctioning infringements in accordance with Articles 56(2), 58(2), and 83 of Regulation (EU) 2016/6...

Primary legal sourceConsumer ProtectionOfficial source · garanteprivacy.it ↗
06 OCT 2025 · Other

Data Protection Authority investigation into CamHub over alleged illegal collection and dissemination of videos

On 6 October 2025, the Italian Data Protection Authority issued a notice against ICF Technology, which manages the CamHub website. The authority stated that the website, currently blocked in Italy, streams sexually explicit videos, including private chat rooms. It also stated that collecting and sharing videos illegally recorded from cameras in private Italian homes violates European and national privacy laws. It warned that reactivating the site without the explicit consent of the data subje...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
01 OCT 2025 · Policy / Guidance

Italian Data Protection Authority source on AI governance

Official source record dated 10 January 2025 for Italy concerning Data Protection Authority investigation into AI/Robotics Venture Strategy 3 over unlawful processing of personal data through ClothOff "deep nude" service. See the linked garanteprivacy.it source for the authoritative text, procedural context, and implementation details.

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
30 SEP 2025 · Executive Order

National Cybersecurity Agency's determination on methods and procedures under Network and Information Security Directive (Resolution 333017/2025)

On 30 September 2025, the determination on compliance with the national competent authority under the Network and Information Security (NIS) Directive entered into force, except for the provision setting out the procedure and deadlines for continuous updating and confirmation of NIS entity and user information. The determination specifies the deadlines, methods, and procedures for the use and access to the Agency's digital platform, as well as additional information that entities must provide...

Primary legal sourceNational StrategyOfficial source · acn.gov.it ↗
17 SEP 2025 · Standard / Framework

Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI

Primary source (pcpd.org.hk) dated 17 September 2025 in IT. See linked source for full text.

Official materialData Privacy & Protection ·Generative AI ·SandboxOfficial source · pcpd.org.hk ↗
20 AUG 2025 · Other

Data Protection Authority investigation into dissemination of private audio involving unlawful processing of personal data

On 20 August 2025, the Italian Data Protection Authority issued Provision No. 479, imposing urgent measures under Article 58(2)(f) of the General Data Protection Regulation (GDPR) to address the unlawful dissemination of a private audio recording on the YouTube channel “Falsissimo” and its subsequent circulation on Instagram. The action followed a complaint under Article 77 GDPR seeking removal and de-indexing of the content across multiple platforms, including YouTube, TikTok, Instagram, Fac...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
30 JUL 2025 · Other

Italy Competition Authority investigates into Meta's integration of Meta AI in WhatsApp

Da marzo 2025 Meta, in posizione dominante nel mercato dei servizi di comunicazione via app, ha deciso di pre-installare il proprio servizio di intelligenza artificiale sull’app Whatsapp. In tal modo Meta potrebbe “imporre” ai propri utenti l’utilizzo dei propri servizi di chatbot e assistenza AI

Official materialAntitrust & Competition ·Generative AIOfficial source · agcm.it ↗
10 JUL 2025 · Court Case

Lawsuit relating to the compatibility of Italian Copyright compensation rules for digital platforms with European Union's copyright directive (Regional Administrative Court for Lazio v Meta Platforms Ireland) (Case No. C-797/23)

On 10 July 2025, the Advocate General of the Court of Justice of European Union issued an opinion on the Italian implementation of Article 15 of Directive (EU) 2019/790 on Copyright in the Digital Single Market. The Directive grants press publishers exclusive rights for the online use of their publications by information society service providers (ISSPs) including Meta Platforms Ireland. The Advocate General found that Italy’s obligations requiring ISSPs to negotiate with publishers, disclose...

Court recordContent ModerationOfficial source · curia.europa.eu ↗
19 MAY 2025 · Other

Garante fines AI company Replika's developer $5.6 million

VEDI ANCHE Provvedimento del 10 aprile 2025 Provvedimento del 22 giugno 2023 Comunicato stampa del 3 febbraio 2023 Provvedimento del 2 febbraio 2023

Official materialData Privacy & Protection ·Online Safety & Child ProtectionOfficial source · garanteprivacy.it ↗
18 APR 2025 · Other

Non-discriminatory digital services taxes in United States - Italy joint leaders' statement to strengthen strategic alliance across security, economic, and technological issues

On 18 April 2025, the United States and Italy adopted a joint statement to strengthen strategic alliance across security, economic, and technological issues. The statement applies to digital technology firms engaged in cross-border trade and investment between the two regions. The statement affirmed the need for a non-discriminatory environment in the taxation of digital services, aimed at maintaining favourable conditions for investment by technology companies.

Official materialNational StrategyOfficial source · whitehouse.gov ↗
18 APR 2025 · Executive Order

Data protection provision in Communications Regulatory Authority's Regulation for the Protection of Minors in the Digital Environment (Resolution no. 96/25/CONS)

On 18 April 2025, the Italian Communications Regulatory Authority (AGCOM) adopted Resolution 96/25/CONS, implementing Law No. 159/2023. The Resolution stipulates that platforms offering content in Italy are obligated to verify the age of users using certified third parties, through a two-step process involving identification and authentication. Verification may be conducted via applications such as digital identity wallets and must be applied per session. The Resolution delineates the respons...

Primary legal sourceNational StrategyOfficial source · agcom.it ↗
11 APR 2025 · Other

Competition Authority investigation against Google over alleged unfair commercial practices

On 4 November 2025, the Italian Competition Authority (AGCM) accepted Google's commitments and closed proceeding PS12714. Under the ruling, Google must revise the consent request circulated under Article 5(2) of Regulation (EU) 2022/1925, provide clearer information regarding the implications of consent on the use of personal data across its services, as well as allowing users to give consent only to specific services. Google must also send the updated request to new, passive, and active user...

Official materialNational StrategyOfficial source · agcm.it ↗
08 APR 2025 · Other

Data Protection Authority investigation into Lusha Systems over alleged unauthorised processing of contact data

On 8 April 2025, the Italian Data Protection Authority announced an investigation into Lusha Systems over the unauthorised processing of contact data. The investigation focuses on concerns that it collects and sells personal contact details, including email addresses and phone numbers, of individuals residing in Italy, including institutional figures, without appropriate consent. The Authority has requested Lusha to clarify, within twenty days, the volume and source of data processed, the met...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
31 MAR 2025 · Executive Order

Communications Regulatory Authority enforcement against rebranded copyright-infringing website

On 31 March 2025, the Italian Communications Regulatory Authority (AGCOM) issued Determination No. 54/25/DDA ordering the blocking of the website ilgeniodellostreaming.delivery. The website was found to be a rebranded version of ilgeniodellostreaming.press, which had previously been blocked for distributing copyrighted content owned by Vision Distribution S.p.A. Following a complaint submitted by FAPAV on behalf of the rights holder, AGCOM confirmed that the domain name had been changed to ci...

Primary legal sourceContent ModerationOfficial source · agcom.it ↗
01 MAR 2025 · Other

GPDP investigation into InfoCert over alleged data breach

On 3 January 2025, the Italian Data Protection Authority (GPDP) announced an investigation into InfoCert following a data breach notification made by the company in December 2024. GPDP highlighted that the breach, affecting an external supplier’s information technology systems, may have compromised the confidentiality of a large amount of personal data. InfoCert has been given 10 days to submit documents detailing its relationship with the external supplier and to provide information on the p...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
20 FEB 2025 · Executive Order

Authority for Communications guidelines on prominence of audiovisual and radio media services of general interest (Resolution 390/24/CONS)

On 20 February 2025, the Authority for Communications Guarantees (AGCOM) extended the deadline for publishing a list of entities subject to AGCOM guidelines on the prominence of audiovisual and radio media services of general interest. The guidelines impose obligations to enhance the prominence of audio-visual and radio media services of general interest on user interfaces. Due to a high number of requests (1'163) and the need for further review of over 300 incomplete submissions, the deadlin...

Primary legal sourceContent ModerationOfficial source · agcom.it ↗
14 FEB 2025 · Other

Data Protection Authority investigation into users of spyware from Paragon Solutions and similar systems over alleged privacy violations

On 14 February 2025, the Data Protection Authority (DPA) issued a warning to users of the “Graphite” spyware systems provided by Paragon Solutions, or similar systems, and to those using information collected through these software. The DPA noted that the use of these tools outside of uses permitted by the law violates the Privacy Code and could result in administrative fines of up to EUR 20 million or 4% of company turnover. Such activities are only lawful when conducted for purposes strictl...

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
30 JAN 2025 · Other

Garante blocks DeepSeek

Il Garante per la protezione dei dati personali ha disposto, in via d’urgenza e con effetto immediato, la limitazione del trattamento dei dati degli utenti italiani nei confronti di Hangzhou DeepSeek Artificial Intelligence e di Beijing DeepSeek Artificial Intelligence, le società cinesi che forniscono il servizio di chatbot DeepSeek.

Official materialData Privacy & ProtectionOfficial source · garanteprivacy.it ↗
29 JAN 2025 · Other

Garante seeks information from DeepSeek on data protection

IA: il Garante privacy chiede informazioni a DeepSeek Possibile rischio per i dati di milioni di persone in Italia

Official materialData Privacy & ProtectionOfficial source · garanteprivacy.it ↗
10 JAN 2025 · Policy / Guidance

Italian Data Protection Authority source on deepfake-related enforcement and policy

Official source record dated 1 October 2025 for Italy concerning Italian DPA temporarily restricts deepfake nude app ClothOff from processing of Italian personal data. See the linked garanteprivacy.it source for the authoritative text, procedural context, and implementation details.

Official materialData Privacy & Protection ·Generative AIOfficial source · garanteprivacy.it ↗
01 JAN 2025 · Law / Act

2025 Budget Law amending digital services tax (Law no. 207 of 2024)

On 1 January 2025, the Budget Law amending digital services tax (DST) entered into force. The law removes the EUR 5.5 million threshold for digital services revenue. The law now applies to entities with over EUR 750 million in revenue (group or standalone), including both resident and non-resident companies. The law covers digital services provided to Italian users, including intermediation, advertising, and data transmission. The law also introduces a revised payment schedule, requiring an a...

Primary legal sourceNational StrategyOfficial source · gazzettaufficiale.it ↗
23 DEC 2024 · Standard / Framework

G7 Digital & Tech Working Group finalises reporting framework for advanced AI systems

An essential step toward the global promotion, development, and ethical application of AI

Official materialData Privacy & Protection ·CybersecurityOfficial source · innovazione.gov.it ↗
27 NOV 2024 · International Agreement

GPDP investigation into agreements between GEDI Gruppo Editoriale SpA and OpenAI

On 27 November 2024, the Italian Data Protection Authority (GPDP) issued an interim ruling to GEDI Gruppo Editoriale SpA and its subsidiaries pertaining to their agreement with OpenAI. The agreement relates to sharing editorial content, including personal data, for artificial intelligence (AI) training and service improvement. The GPDP identified potential violations of the General Data Protection Regulation, specifically pertaining to the legal basis for processing sensitive data, inadequate...

Primary legal sourceNational StrategyOfficial source · garanteprivacy.it ↗
27 NOV 2024 · Court Case

Italian Garante issues interim ruling on GEDI Gruppo x OpenAI deal

NELLA riunione odierna, alla quale hanno preso parte il prof. Pasquale Stanzione, presidente, il dott. Agostino Ghiglia e l’avv. Guido Scorza, componenti, e il cons. Fabio Mattei, segretario generale;

Court recordData Privacy & Protection ·Generative AIOfficial source · garanteprivacy.it ↗
22 NOV 2024 · Other

Data Protection Authority investigation into Foodinho for alleged privacy violations and using algorithms for identity verification of delivery drivers

On 22 November 2024, the Italian Data Protection Authority issued a EUR.5 million fine against Foodinho, a food delivery application, for unlawfully processing the personal data of delivery riders registered in the digital platform. In addition, the Authority ordered the company to stop using biometric data of its riders, such as facial recognition for identity verification, and to stop sharing the riders' geolocation data with third-party companies without their knowledge and authorisation.

Official materialNational StrategyOfficial source · garanteprivacy.it ↗
16 OCT 2024 · Executive Order

Legislative Decree No. 138 transposing NIS 2

On 16 October 2024, Legislative Decree No. 138, transposing into national legislation the Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), entered into force. The decree includes measures to ensure the security and resilience of the critical infrastructure. The National Cybersecurity Agency (ACN) is designated as the responsible authority for overseeing the implementation process, enforcing obligations and collaborating with the...

Primary legal sourceNational StrategyOfficial source · gazzettaufficiale.it ↗
15 SEP 2024 · Executive Order

AGCOM Resolution 283/24/CONS on procedural guidelines for recognising trusted flaggers under the Digital Services Act

On 15 September 2024, the Italian Communications Regulatory Authority’s Resolution on the procedural guidelines for recognising trusted flaggers under the Digital Services Act enters into force. The Act applies to digital services, specifically online platforms and intermediary services that facilitate the storage and dissemination of information and assigns trusted flaggers to identify and report illegal content to online platforms. The Regulation sets out the process for recognising the qua...

Primary legal sourceContent ModerationOfficial source · agcom.it ↗
15 SEP 2024 · Executive Order

AGCOM Resolution 282/24/CONS on certification procedure of bodies for the out-of-court dispute resolution between online platform providers and recipients under Digital Services Act

On 15 September 2024, the Italian Communications Regulatory Authority’s Resolution on the certification procedure of bodies for the out-of-court dispute resolution between online platform providers and recipients under the Digital Services Act (Resolution 282/24/CONS) enters into force. The Regulation applies to out-of-court dispute resolution bodies handling disputes between service recipients and online platform providers, requiring them to demonstrate impartiality, independence, and expert...

Primary legal sourceContent ModerationOfficial source · agcom.it ↗