Italy Data Protection Authority: All What You Need to Know

The Garante per la protezione dei dati personali is Italy's independent data protection authority, established in 1997 and the fourth-largest EU GDPR enforcer by cumulative fine value. Complete 2026 reference covering role, powers, recent enforcement (TIM €27.8M, Enel €26.5M, Vodafone €12.25M), the October 2026 email pixel consent deadline, and how to file complaints.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
7 min read Updated Jul 29, 2026 58 views

The Garante per la protezione dei dati personali is Italy’s independent data protection authority. Established in 1996 as one of Europe’s earliest DPAs, it enforces GDPR, the Italian Codice Privacy (Legislative Decree 196/2003 as amended), and consumer protections against unsolicited marketing. The Garante is among the most active DPAs on telemarketing and email marketing enforcement, with cumulative fines exceeding €300 million and a strict interpretation of ePrivacy Directive rules. Its October 2026 deadline on email tracking pixel consent parallels France’s July 2026 rule.

Garante per la protezione dei dati personali · Established 8 May 1997 under Law 675/1996 (predecessor to the Italian Data Protection Code) · Chaired by Pasquale Stanzione since 2020 · Based at Piazza Venezia 11, 00187 Rome · Independent constitutional authority (autorità amministrativa indipendente) · Enforces GDPR, Codice Privacy (D.Lgs. 196/2003 amended by D.Lgs. 101/2018), Italian ePrivacy transposition, and consumer protection rules on telemarketing and email · Max fine: €20M or 4% of global annual turnover.

1997
Operational since May 1997; one of the earliest DPAs in Europe
4th
Largest EU GDPR enforcer by cumulative fine value
€27.8M
TIM S.p.A. sanction (2020): largest telemarketing GDPR fine to date
28 Oct
2026 deadline: email tracking pixel consent enforcement across Italy

Role and powers

The Garante is a collegiate body of four members elected by the Italian Parliament (two by the Camera dei Deputati and two by the Senato) for a seven-year non-renewable term. It operates independently of the executive and reports annually to Parliament. Its core mandates are:

  • Enforcement. Investigations, corrective orders, and administrative fines up to €20M or 4% of global annual turnover under GDPR Article 83. The Garante’s provvedimenti sanzionatori (sanction decisions) are among the most detailed in the EU, often running to hundreds of pages.
  • Regulatory guidance. Sector codes (health, telecommunications, journalism) and specific provvedimenti (general orders) that carry near-regulatory weight. The 2019 provvedimento on cookies, the 2022 provvedimento on Google Analytics, and the June 2026 recommendation on email pixels are all reference documents across the EU.
  • Individual complaints. The Garante handles reclami (formal complaints) and segnalazioni (informal reports) from data subjects. Investigations can be opened on complaint or at the Garante’s own initiative.
  • Prior consultation. Controllers with high-risk processing must seek prior consultation under GDPR Article 36. The Garante has issued binding opinions on public sector data lakes, biometric access control, and cross-border health data transfers.

Recent enforcement highlights

2020
TIM S.p.A. €27.8M
Unsolicited telemarketing, aggressive commercial calls, unlawful data enrichment. Largest telemarketing-focused GDPR sanction in Europe to date.
2021
Enel Energia €26.5M
Improper use of customer data for marketing purposes, unauthorised profiling, deficient consent management across sales channels.
2020, 2024, 2025
Vodafone Italia €12.25M then €6M
Repeated telemarketing violations and continued unauthorised marketing calls after prior sanctions. Persistent-offender doctrine applied.

Other notable decisions include OpenAI €15M (December 2024, annulled March 2026 on procedural grounds; underlying violations upheld and case returned to the Garante), Deliveroo €2.5M for excessive worker tracking, Foodinho (Glovo) €2.6M for algorithmic worker management without adequate safeguards, and a steady stream of five- and six-figure fines against telemarketing operators, health providers, and public bodies.

2026 enforcement priorities

Email pixel consent: hard deadline 28 October 2026. The Garante published its consultation on tracking pixels in marketing email in April 2026 and finalised the recommendation in June. From 28 October, marketing pixels in email require prior explicit consent from Italian recipients, on the same legal footing as web cookies under Italian Article 122 of the Codice Privacy. The recommendation parallels France’s CNIL July 2026 deadline and is expected to be adopted with modifications by other member state DPAs through 2027. Beyond email pixels, the Garante’s 2026 priorities include AI-based worker management, generative AI training data lawfulness (the OpenAI case is the reference), biometric authentication, and telemarketing enforcement in cooperation with AGCOM (the Italian communications authority).

How to file a complaint

  • Submit a reclamo (formal complaint) via the Garante’s online portal at garanteprivacy.it or by certified email (PEC) to protocollo@pec.gpdp.it. Postal submissions go to Piazza Venezia 11, 00187 Roma.
  • A reclamo requires prior contact with the data controller: the complainant must have sent a formal data subject request or grievance and either received an unsatisfactory response or none within 30 days.
  • A segnalazione (informal report) does not require prior controller contact and can be used to alert the Garante to systemic issues, even if the reporter is not personally affected.
  • Complaints from non-Italian residents against Italian-established controllers are accepted directly. Cross-border cases involving controllers established in another EU member state are handled through the GDPR one-stop-shop mechanism.
  • The Garante publishes decisions on garanteprivacy.it (in Italian, with English translations for the highest-profile cases) and on the European Data Protection Board’s cross-border decision register.

Common misconceptions

“Telemarketing rules cover phone only.” No. The Garante applies the same strict opt-in standard to email, SMS, and automated calls. Every TIM, Vodafone, and Enel sanction has covered mixed-channel campaigns including marketing email.

“Consent obtained in another EU country transfers to Italy.” Partially. GDPR consent is portable across member states, but the Codice Privacy adds Italian-specific requirements (particularly on telemarketing and the Registro pubblico delle opposizioni). The Garante has fined foreign controllers for relying on generic EU consent that did not meet Italian granularity requirements.

“Legitimate interest covers marketing after purchase.” The Garante’s interpretation of the soft opt-in exception under Article 130(4) of the Codice Privacy is narrower than the UK PECR reading. Only similar products or services, only for a limited time after purchase, and only if the recipient was informed at collection and given an easy opt-out. Cross-selling to a different product category does not qualify.

“The Registro pubblico delle opposizioni is only for phone.” No. The Registro was extended to postal and email marketing in 2018 and covers over 30 million Italian consumer records. Failing to cross-check against the register before an email campaign is a per-se violation of the Codice Privacy.

Frequently asked questions

How is the Garante different from other Italian regulators?

The Garante has exclusive competence over personal data protection. Related consumer topics are shared with AGCM (Antitrust Authority), AGCOM (communications and media), and IVASS (insurance). On unsolicited telemarketing the Garante and AGCOM coordinate closely; on price advertising and consumer deception AGCM leads.

What is the Registro pubblico delle opposizioni?

An opt-out register maintained by the Ministry of Enterprise. Consumers can register their landline, mobile, and email to opt out of unsolicited marketing. Every sender operating in Italy must cross-check its list against the register before each campaign or face per-message fines. As of 2026 the register holds over 30 million entries.

Does the Garante enforce GDPR against foreign senders?

Yes. Article 3(2) of GDPR applies extraterritorially, and the Codice Privacy’s marketing rules apply to any commercial email accessed from Italy. The OpenAI case (December 2024) is the reference for foreign-controller extraterritorial enforcement: the Garante ordered US-based OpenAI to modify its data practices for Italian users on penalty of continued service suspension.

How does the Garante coordinate with other EU DPAs?

Through the EDPB (European Data Protection Board), the Garante participates in the one-stop-shop for cross-border cases, cooperates on coordinated enforcement actions like CEF 2026 (transparency), and issues joint opinions on major regulatory questions. Chair Pasquale Stanzione has served on the EDPB executive since 2022.

Where can I find English-language Garante decisions?

The Garante publishes English summaries of major decisions at garanteprivacy.it/en. The full text of decisions remains in Italian. The European Data Protection Board’s cross-border decisions register (edpb.europa.eu) also carries Garante decisions when they concern cross-border processing.

Where to go next

Sending marketing email into Italy? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate Garante complaints. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.


About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.