Skip to the content
Global Data RulesData governance rules, country by country

Italy

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.

Eight questions about Italy

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Italy's rules apply to my company?

Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Italy?

For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.

High confidenceDepends on your industryGovernmentHealth and social careTelecomsKeep the data in the country

What do I need in place before data leaves Italy?

Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentCriminal liability

Who enforces the rules in Italy, and what can they do?

The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.

High confidenceAggressivePercentage of global turnoverOrder to stop

How long do I have to keep the data?

Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Italy?

Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.

High confidenceKeep logsDelete data after a periodCriminal liabilityChildren's dataEmployee dataGet a parent's consent for children

What is changing soon in Italy?

Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.

Medium confidenceMake switching cloud provider possibleHold a security certificateProve the data stays under local controlApproval each time

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    8 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Regolamento (UE) 2016/679 — Regolamento generale sulla protezione dei dati

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe, and it applies to companies outside Europe that target people in Italy.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by Italian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Data Act — Regolamento (UE) 2023/2854

Directly binding regulation · Regulation (EU) 2023/2854

In forceYes — store it anywhere

Not about where data sits, but about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.

In force since 12 September 2025But only enforceable from 12 January 2027

Enforced by National Cybersecurity Agency

Transfer model: No restriction

High confidence

National rules2 rules

Codice in materia di protezione dei dati personali

Act of parliament · Decreto legislativo 30 giugno 2003, n. 196, as amended by Decreto legislativo 10 agosto 2018, n. 101

In forceYes, with paperwork

Italy's own data protection code, kept alive alongside European law. It is where the national oddities live: children consent at 14, dead people's data still has rights, workplace monitoring has its own rules, and some breaches are crimes.

In force since 1 January 2004But only enforceable from 19 September 2018

Enforced by Italian Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Legge 23 settembre 2025, n. 132 — Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Act of parliament · Legge 132/2025, Gazzetta Ufficiale n. 223 del 25 settembre 2025 · Artificial intelligence

Partly in forceYes — store it anywhere

Italy's national artificial intelligence law, in force since 10 October 2025. Important for what it does NOT contain: a clause forcing public-sector artificial intelligence systems onto servers in Italy was struck out in committee before the vote, yet it is still widely reported as binding Italian law. Most of the detail waits on delegated decrees.

In force since 10 October 2025

Enforced by National Cybersecurity Agency

Transfer model: No restriction

High confidence

Industry rules8 rules

Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24

Government rules · Determinazione del Direttore generale ACN n. 21007 del 27 giugno 2024 · Government

In forceNo — it stays put

The real Italian localisation wall. Public-sector data is graded ordinary, critical or strategic; strategic data must sit on infrastructure inside Italy run from Italy, and critical data may not go on a public cloud outside Europe. No provider may sell cloud to an Italian public body without a qualification from the national cyber agency.

In force since 1 August 2024

Enforced by National Cybersecurity Agency

Transfer model: Allowlist · Accepted routes: Certification scheme

High confidence

Perimetro di sicurezza nazionale cibernetica

Act of parliament · Decreto-legge 21 settembre 2019, n. 105, converted by Legge 133/2019; DPCM 131/2020; DPCM 81/2021; DPR 54/2021 · Defence

In forceYes, with paperwork

A national-security regime layered on top of everything else. Designated public and private bodies in strategic sectors must get their technology purchases vetted before buying, and must report incidents on a very short clock. Being added to the list is an administrative decision you cannot appeal your way out of quickly.

In force since 21 November 2019But only enforceable from 1 June 2021

Enforced by National Cybersecurity Agency

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Medium confidence

Articolo 132 del Codice in materia di protezione dei dati personali; articolo 24 della legge 20 novembre 2017, n. 167

Act of parliament · D.Lgs. 196/2003 art. 132; Legge 167/2017 art. 24; D.L. 132/2021 converted by Legge 178/2021 · Telecoms

In forceYes, with paperwork

Italian telecoms and internet providers must keep call and connection records for years — two years for phone records, one year for internet records, six years where terrorism or serious crime is involved. There is no rule about where those records are stored, only that they exist and that a judge must sign before anyone reads them.

In force since 1 January 2004But only enforceable from 30 November 2021

Enforced by Italian Data Protection Authority

Transfer model: No restriction

High confidence

Who you would hear from

  • EU-level coordination and guidance; consistency mechanism for cross-border cases

  • Garante per la protezione dei dati personali

    All personal data processing in Italy, public and private, plus telecoms traffic data and workplace monitoring

    Highly active: 807 decisions in 2025, 506 of them corrective or punitive, more than EUR 37m in fines, 130 inspections. Board is currently three of four members — Guido Scorza's term is recorded as ending 19 January 2026 and no successor had been reported as elected by 18 August 2026. The board continues to sit and publish.

  • Agenzia per la Cybersicurezza Nazionale

    Cybersecurity, the national cyber perimeter, the network and information security regime, and qualification of cloud services for public bodies

    Fully staffed and issuing binding determinations; runs the registration platform and the cloud qualification catalogue. Its website blocks automated fetching, which makes independent verification of its deadlines harder than it should be.

  • Banca d'Italia

    Banks, payment firms and other supervised intermediaries, including technology outsourcing and incident reporting under the European financial resilience regime

  • Ministero delle Imprese e del Made in Italy

    Telecommunications, digital services and critical technologies inside the national cyber perimeter; technical assessment for golden power decisions

  • Autorità per le Garanzie nelle Comunicazioni

    Electronic communications networks and services, including nuisance-call filtering and online platform duties

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That online gaming concessionaires must keep the gaming platform or player-account data on servers in Italy or the European Economic Area

    The customs and monopolies agency's own tender FAQ refused automated fetching (HTTP 403), so the concession's technical rules could not be read. Treated as not established rather than as absent.

  • The exact six-hour incident notification deadline for entities inside the National Cybersecurity Perimeter

    The ministry's own page describes the notification duty but does not state the hours, and the implementing decree text was not fetched. Six hours is the figure in general circulation.

  • The exact 2026 network-security deadlines: incident reporting operative from 15 January 2026, basic measures due 31 October 2026, and the ACN determination numbers 164179/2025 and 379907/2025

    The National Cybersecurity Agency's site returns HTTP 403 to automated fetching, so these rest on professional commentary rather than the agency's own text.

  • The exact prison terms attached to Articles 167 and 167-bis of the Italian Personal Data Protection Code

    The Garante's coordinated text of the Code is a PDF that could not be quoted article by article in this run. The existence and subject matter of both offences is confirmed; the sentencing ranges are not.

  • The precise commencement date of the ACN single cloud regulation (recorded here as 1 August 2024)

    The official page says the ordinary qualification regime enters into force in August 2024 without giving a day; the determination was adopted 27 June 2024.

  • That a successor to Guido Scorza on the Garante board had still not been elected as at 18 August 2026

    The authority's own board page records his term ending 19 January 2026 but does not comment on the vacancy. The claim that Parliament has not voted rests on a media source.

  • The ten-year retention floor for Italian accounting and commercial records under Article 2220 of the Civil Code

    Well established but not re-verified against an official source during this run, in line with the rule against answering from memory.

  • Whether any mapping or geospatial restriction survives from Italy's older cartography legislation

    No current rule found, checked 18 August 2026. Searched but not confirmed either way against an official source.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.