Skip to the content
Global Data RulesData governance rules, country by country

Italy

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Italy — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy adds its own rules on top. The answer changes completely when your customer is the Italian state. That means a ministry, a town hall, a hospital or a school. The most sensitive government data has to sit on machines inside Italy, run from Italy.

Data governance in Italy

The eight things that decide how you handle data about people in Italy. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, the law reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy. It also applies if you monitor what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe. People and regulators can go to that representative instead of chasing you abroad.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, for a normal private company, with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real limits sit in one place. They apply to anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic. The top two grades cannot sit on a public cloud outside Europe. Strategic data must stay on infrastructure inside Italy and be run from Italy.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

There are three routes, and they are European rather than Italian. Best case, the country you send to is on Europe's official approved list, and you need nothing extra. Otherwise you sign Europe's standard contract with the receiver. Or you get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment. It must say whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step. It does add a crime for getting it badly wrong.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
What it costs if you get it wrong:
Criminal liability

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Italian data protection authority enforces the rules. It is known as the Garante. It is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive. It ran 130 inspections and collected more than 37 million euros (about 41 million US dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service. It has since blocked or restricted several artificial intelligence products. A separate agency enforces cybersecurity.

What it costs if you get it wrong:
Percentage of global turnover · Order to stop

How long you must keep it — and when to delete it

There are minimum keeping times and maximum keeping times, and they pull hard against each other. You must keep telephone records 24 months, internet connection records 12 months and unanswered calls 30 days. A separate six-year rule covers terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The maximum is much tighter than people expect. The regulator says the technical logs behind staff email may normally be kept for no more than 21 days.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least three deadlines, and they run at the same time. A personal data breach goes to the Garante within 72 hours. You must tell the people affected without delay where the risk to them is high. If Italy's network security rules cover you, a first warning goes to the national cyber agency within 24 hours. A fuller notice follows within 72 hours and a final report within a month. Organisations inside the national cyber perimeter have far less time. The figure reported is six hours.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five traps. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit. Skipping it is a crime, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed. It is not law.

What you have to do here:
Keep logs · Delete data after a period · Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Two firm dates and one open problem. By 31 October 2026, organisations covered by Italy's network security rules must have their basic security measures in place, with evidence. From 12 January 2027, every cloud provider must charge nothing for switching away or pulling your data out. The open problem is the Italian regulator itself. One of four board seats has been empty since January 2026, and Parliament has not filled it.

What you have to do here:
Make switching cloud provider possible · Hold a security certificate · Prove the data stays under local control

What to do: Diarise 31 October 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries8 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24 · Determinazione del Direttore generale ACN n. 21007 del 27 giugno 2024 · Government rules

In forceNo — it stays put

The real Italian rule about keeping data in the country. Public-sector data is graded ordinary, critical or strategic. Strategic data must sit on infrastructure inside Italy and be run from Italy. Critical data may not go on a public cloud outside Europe. No provider may sell cloud to an Italian public body without approval from the national cyber agency.

In force since 1 August 2024

Enforced by National Cybersecurity Agency

How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme

Defence

Breach reporting rules

Official name: Perimetro di sicurezza nazionale cibernetica · Decreto-legge 21 settembre 2019, n. 105, converted by Legge 133/2019; DPCM 131/2020; DPCM 81/2021; DPR 54/2021 · Act of parliament

In forceYes, with paperwork

National-security rules layered on top of everything else. Named public and private bodies in strategic industries must get their technology purchases vetted before buying. They must also report incidents very fast. Being added to the list is an administrative decision, and you cannot appeal your way out of it quickly.

In force since 21 November 2019Enforced from 1 June 2021

Enforced by National Cybersecurity Agency

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules

Official name: Articolo 132 del Codice in materia di protezione dei dati personali; articolo 24 della legge 20 novembre 2017, n. 167 · D.Lgs. 196/2003 art. 132; Legge 167/2017 art. 24; D.L. 132/2021 converted by Legge 178/2021 · Act of parliament

In forceYes, with paperwork

Italian telecoms and internet providers must keep call and connection records for years. Phone records run two years. Internet records run one year. Records run six years where terrorism or serious crime is involved. There is no rule about where those records are stored. The rules say only that they must exist, and that a judge must sign before anyone reads them.

In force since 1 January 2004Enforced from 30 November 2021

Enforced by Italian Data Protection Authority

How this country controls where data goes: No restriction

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Codice in materia di protezione dei dati personali · Decreto legislativo 30 giugno 2003, n. 196, as amended by Decreto legislativo 10 agosto 2018, n. 101 · Act of parliament

In forceYes, with paperwork

Italy's own data protection code, kept alive alongside European law. This is where the national oddities live. Children consent at 14. Dead people's data still has rights. Workplace monitoring has its own rules. And some breaches are crimes.

In force since 1 January 2004Enforced from 19 September 2018

Enforced by Italian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Artificial intelligence

AI rules

Official name: Legge 23 settembre 2025, n. 132 — Disposizioni e deleghe al Governo in materia di intelligenza artificiale · Legge 132/2025, Gazzetta Ufficiale n. 223 del 25 settembre 2025 · Act of parliament

Partly in forceYes — store it anywhere

Italy's national artificial intelligence law, in force since 10 October 2025. What it leaves out matters. A clause forcing public-sector artificial intelligence systems onto servers in Italy was struck out in committee before the vote. It is still widely reported as binding Italian law. Most of the detail waits on follow-up decrees.

In force since 10 October 2025

Enforced by National Cybersecurity Agency

How this country controls where data goes: No restriction

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Regolamento (UE) 2016/679 — Regolamento generale sulla protezione dei dati · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe. It applies to companies outside Europe that target people in Italy.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by Italian Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules (2027)

Official name: Data Act — Regolamento (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation

In forceYes — store it anywhere

This is about being able to move your data, not about where it sits. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on demands for data held in Europe from governments outside Europe.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by National Cybersecurity Agency

How this country controls where data goes: No restriction

Who you would hear from

  • EU-level coordination and guidance; consistency mechanism for cross-border cases

  • Garante per la protezione dei dati personali

    All personal data processing in Italy, public and private, plus telecoms traffic data and workplace monitoring

    Highly active. It took 807 decisions in 2025, 506 of them corrective or punitive. It collected more than 37 million euros in fines and ran 130 inspections. The board currently has three of four members. Guido Scorza's term is recorded as ending 19 January 2026, and no successor had been reported as elected by 18 August 2026. The board continues to sit and publish.

  • Agenzia per la Cybersicurezza Nazionale

    Cybersecurity, the national cyber perimeter, the network and information security regime, and qualification of cloud services for public bodies

    Fully staffed and issuing binding decisions. It runs the registration platform and the list of approved cloud services.

  • Banca d'Italia

    Banks, payment firms and other supervised intermediaries, including technology outsourcing and incident reporting under the European financial resilience regime

  • Ministero delle Imprese e del Made in Italy

    Telecommunications, digital services and critical technologies inside the national cyber perimeter; technical assessment for golden power decisions

  • Autorità per le Garanzie nelle Comunicazioni

    Electronic communications networks and services, including nuisance-call filtering and online platform duties

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That online gaming concessionaires must keep the gaming platform or player-account data on servers in Italy or the European Economic Area

    We could not read the concession's technical rules. We record this as not established, rather than absent. If you work in online gaming, check before you rely on it.

  • The exact six-hour incident notification deadline for entities inside the National Cybersecurity Perimeter

    The ministry's own page describes the duty to notify but does not state the hours. We could not fetch the text of the decree that sets them. Six hours is the figure in general circulation. Check with the ministry before you rely on it.

  • The exact 2026 network-security deadlines: incident reporting operative from 15 January 2026, basic measures due 31 October 2026, and the ACN determination numbers 164179/2025 and 379907/2025

    So these dates rest on professional commentary rather than the agency's own text. Check with the agency before you rely on them.

  • The exact prison terms attached to Articles 167 and 167-bis of the Italian Personal Data Protection Code

    The Garante's combined text of the Code is a PDF we could not quote article by article. We confirmed that both crimes exist and what they cover. We could not confirm the sentencing ranges.

  • The precise commencement date of the ACN single cloud regulation (recorded here as 1 August 2024)

    The official page says the ordinary approval process starts in August 2024, without giving a day. The decision itself was adopted on 27 June 2024.

  • That a successor to Guido Scorza on the Garante board had still not been elected as at 18 August 2026

    The authority's own board page records his term ending 19 January 2026. It says nothing about the empty seat. The claim that Parliament has not voted rests on a media source, not an official one.

  • The ten-year retention floor for Italian accounting and commercial records under Article 2220 of the Civil Code

    This is well established, but we did not re-check it against an official source. We do not answer from memory. Check the Civil Code before you rely on the period.

  • Whether any mapping or geospatial restriction survives from Italy's older cartography legislation

    We found no current rule, checked 18 August 2026. We could not confirm it either way against an official source. Check before you rely on it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.