Italy
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy layers its own rules on top. But the moment you sell to the Italian state — a ministry, a town hall, a hospital, a school — the picture changes completely. The most sensitive government data has to sit on machines inside Italy, run from Italy.
Eight questions about Italy
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Italy's rules apply to my company?
Yes, it reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy, or that monitors what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe, and people and regulators can go to that representative instead of chasing you abroad.
Layer 1 is the General Data Protection Regulation, Articles 3 and 27. Layer 2 is Italy's own Personal Data Protection Code, Legislative Decree 196/2003 as rewritten by Legislative Decree 101/2018, which keeps a set of national rules that sit alongside the European ones: employment and workplace monitoring, the age of consent for children, the data of deceased people, telecoms traffic data, and a set of criminal offences. Those national rules bite on anyone processing data in Italy, including foreign controllers acting through an Italian establishment or targeting the Italian market. Public-sector procurement adds a third layer that is contractual and technical rather than data-protection law: a cloud service cannot be sold to an Italian public body at all unless the National Cybersecurity Agency has qualified it.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27 — territorial scope and the European representative
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliCodice in materia di protezione dei dati personali (coordinated text of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018)
garanteprivacy.it
Link checked 18 August 2026
Can I store my users' data outside Italy?
For a normal private company, yes — with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real walls are in one place: anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic, and the top two grades cannot sit on a public cloud outside Europe, with strategic data confined to infrastructure inside Italy and operated from Italy.
Sector by sector, checked 18 August 2026. GOVERNMENT AND PUBLIC SECTOR — data must stay in the country for strategic data, data can leave once conditions are met (Europe only) for critical data. The Cloud Italia strategy defines strategic data as data whose compromise would affect national security, critical data as data whose compromise would damage functions important to society, and ordinary data as everything else. Strategic workloads go to a private or hybrid cloud based in Italy with Italian operational management, or to the National Strategic Hub; critical workloads must avoid non-European public cloud; ordinary workloads may use any European-qualified public cloud. The National Strategic Hub is explicitly designed to be "autonomi da soggetti extra UE" — independent of non-European entities. Separately, any cloud service sold to a public administration must first be qualified by the National Cybersecurity Agency under its single cloud regulation, adopted 27 June 2024, with the ordinary qualification regime running from August 2024. HEALTH — data can leave once conditions are met in the private sector, but public health bodies are public administrations and inherit the rules above, so in practice hospital and regional health workloads sit on European or Italian infrastructure. Health records also flow into a national infrastructure: the Electronic Health Record 2.0 built on the National Interoperability Infrastructure and the Health Data Ecosystem, governed by the Health Ministry decree of 7 September 2023 and the Health Data Ecosystem decree of 31 December 2024. TELECOMS — conditional No storage-location rule found, checked 18 August 2026, but a heavy retention floor applies: telephone traffic data 24 months, internet traffic data 12 months, unanswered calls 30 days, and a separate 72-month regime for terrorism and serious crime. BANKING, PAYMENTS, SECURITIES, INSURANCE — open No localisation rule found, checked 18 August 2026. The Bank of Italy has confirmed that its earlier sectoral prohibitions on outsourcing no longer apply to technology services supporting essential or important functions; the European financial resilience regulation replaced them with a notification duty from 17 January 2025 and imposes no data-residency requirement. DEFENCE AND CRITICAL INFRASTRUCTURE — data can leave once conditions are met and government-controlled. Entities inside the National Cybersecurity Perimeter must tell the national vetting centre before they buy technology goods, systems or services for their most sensitive assets, and the government can attach conditions. ARTIFICIAL INTELLIGENCE — open A clause requiring public-sector artificial intelligence systems to be installed on servers located in Italy was in the bill and was struck out in committee before the law passed. It is not law. MAPPING AND GEOSPATIAL, EDUCATION, E-COMMERCE — no localisation rule found, checked 18 August 2026, confidence medium. ONLINE GAMING — not confirmed. See the unconfirmed list.
Sources
- Official sourceDipartimento per la trasformazione digitale / Agenzia per la cybersicurezza nazionaleStrategia Cloud Italia — classification of public-sector data as ordinario, critico and strategico and the hosting model for each
docs.italia.it
“dati e servizi la cui compromissione può avere un impatto sulla sicurezza nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitalePolo Strategico Nazionale — national infrastructure for critical and strategic public data, designed to be independent of non-EU entities
cloud.italia.it
Link checked 18 August 2026
- Official sourceBanca d'ItaliaBanca d'Italia on the Digital Operational Resilience Act — sectoral outsourcing prohibitions replaced by a notification duty from 17 January 2025
bancaditalia.it
“informano tempestivamente l'autorità competente in merito a eventuali accordi contrattuali previsti per l'utilizzo di servizi ICT a supporto di funzioni essenziali o importanti”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 — member states may not impose storage-location rules on non-personal data except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Italy?
Three routes, and they are European rather than Italian. Best case, the destination is on Europe's official approved list and you need nothing extra. Otherwise you sign Europe's standard contract with the recipient, or get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment of whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step, but it does add a criminal offence for getting it badly wrong.
The model is an allowlist with contractual escape hatches. The approved list, verified on the Commission's own page on 18 August 2026, has 17 entries: Andorra, Argentina, Brazil (added 26 January 2026), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States but only for companies self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. Nothing has been withdrawn or suspended. The 2021 standard contractual clauses remain the operative set. The promised new clauses for recipients already directly subject to European law had still not been adopted on 18 August 2026. Narrow one-off exceptions exist — explicit consent, contract necessity, legal claims — but they are not for routine or bulk flows. The Italian addition is Article 167(2) of the Personal Data Protection Code, which makes an unlawful transfer of personal data out of Europe a crime rather than an administrative matter.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliPersonal Data Protection Code, Article 167 — criminal offence of unlawful processing, including unlawful transfer abroad
garanteprivacy.it
Link checked 18 August 2026
Who enforces the rules in Italy, and what can they do?
The Italian data protection authority, known as the Garante, and it is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive, ran 130 inspections and collected more than 37 million euros (about 41 million dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service, and it has since blocked or restricted several artificial intelligence products. Cybersecurity is enforced by a separate agency.
The Garante's board is elected by Parliament and normally has four members. One member, Guido Scorza, resigned on 19 January 2026 after a period of political controversy over the authority's independence; the authority's own board page records his term as ending on that date, and as of 18 August 2026 no replacement had been reported as elected. The remaining three members continue to operate and the authority has continued to publish decisions throughout 2026, including its annual report on 2 July 2026. The board's seven-year term, which began on 29 July 2020, runs to 2027. Cybersecurity, the national cyber perimeter, the network and information security regime and cloud qualification for public bodies sit with the National Cybersecurity Agency, which is fully operational and issuing binding determinations. Financial firms answer to the Bank of Italy under the European financial resilience regime; telecoms are supervised by the communications authority. Rating: aggressive. The Garante goes looking rather than waiting for complaints, and it uses processing-suspension orders, which hurt more than the fines.
Sources
- Official sourceGarante per la protezione dei dati personaliRelazione sull'attività 2025 — press summary, published 2 July 2026: 807 decisions, 506 corrective and sanctioning measures, over EUR 37m in fines, 130 inspections, 2,415 breach notifications
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliIl Collegio — board composition; Guido Scorza's term recorded as 29 July 2020 to 19 January 2026
garanteprivacy.it
Link checked 18 August 2026
- Official sourceAgenzia per la Cybersicurezza NazionaleNational Cybersecurity Agency — network and information security supervision
acn.gov.it
Link checked 18 August 2026
How long do I have to keep the data?
Both directions, and they pull hard against each other. The floors: telephone records must be kept 24 months, internet connection records 12 months, unanswered calls 30 days, and a separate six-year rule applies for terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The ceiling is much tighter than people expect: the regulator says the technical logs behind staff email may normally be kept for no more than 21 days.
Floors. Article 132 of the Personal Data Protection Code sets 24 months for telephone traffic data, 12 months for telematic traffic data excluding message content, and 30 days for unanswered calls, all for criminal-investigation purposes. Article 132(5-bis) preserves Article 24 of Law 167/2017, which extends retention to 72 months for terrorism and certain serious offences. Access to any of it requires a reasoned judicial order following the 2021 reform. Ordinary commercial and accounting records are generally kept ten years under the Civil Code — see the unconfirmed list, this was not re-verified in this run. Health: records in the Electronic Health Record are deleted 30 years after death, on an annual cycle. Ceilings. General European law says do not keep personal data longer than you need it. Italy's sharpest specific ceiling is the Garante's June 2024 guidance on workplace email, which says metadata may normally be retained "per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni". In April 2025 the Garante applied it against a regional government that had kept 90 days of metadata. Conflict. Where a legal duty to keep collides with a duty to delete, the retention duty wins for the narrow purpose that requires it, but the data must be locked down and used for nothing else.
Sources
- Official sourceCamera dei DeputatiChamber of Deputies dossier on Article 132 of the Privacy Code — retention periods and the 72-month counter-terrorism regime
documenti.camera.it
“i dati relativi al traffico telefonico conservati dal fornitore per ventiquattro mesi dalla data della comunicazione”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — workplace email metadata, 21-day ceiling applied against a 90-day retention
garanteprivacy.it
“di norma, per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliFascicolo Sanitario Elettronico — national health record; records erased 30 years after death
garanteprivacy.it
Link checked 18 August 2026
What happens if there is a breach?
Count at least three clocks, and they run at the same time. A personal data breach goes to the Garante within 72 hours, and to the people affected without delay where the risk to them is high. If you are in scope of Italy's network security regime, a first warning goes to the national cyber agency within 24 hours, a fuller notification within 72 hours, and a final report within a month. Organisations inside the national cyber perimeter have a much shorter fuse, reported as six hours.
Clock one: General Data Protection Regulation Articles 33 and 34 — 72 hours to the Garante, and notification to individuals without undue delay where the risk is high. The Garante received 2,415 breach notifications in 2025, up about ten per cent on 2024. Clock two: the Italian network and information security decree, Legislative Decree 138/2024, implementing the European NIS2 directive. Registration opened on 1 December 2024 with an annual renewal window of 1 January to 28 February. Incident notification obligations became operative on 15 January 2026 under a National Cybersecurity Agency determination: early warning within 24 hours of becoming aware, notification within 72 hours, final report within one month. Basic security measures must be in place by 31 October 2026. These dates come from professional commentary because the agency's own site refused automated fetching — see the unconfirmed list. Clock three: the National Cybersecurity Perimeter, set up by Decree-Law 105/2019 with implementing decrees 131/2020 and 81/2021. Designated public and private entities in strategic sectors must report incidents very fast — six hours is the figure in circulation — and must notify the national vetting centre before buying technology for their most sensitive systems. Clock four, for financial firms only: the European financial resilience regime, reported to the Bank of Italy through its Infostat channel rather than to the cyber agency.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinistero delle Imprese e del Made in ItalyPerimetro di sicurezza nazionale cibernetica — legal basis, designation of entities and pre-purchase notification to the national vetting centre
mimit.gov.it
“dell'intenzione di acquisire beni, sistemi e servizi ICT”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliRelazione sull'attività 2025 — 2,415 data breach notifications received
garanteprivacy.it
Link checked 18 August 2026
- Secondary sourceICT Security MagazineNIS2 and Legislative Decree 138/2024 — the 2026 timetable, determination 379907/2025, 24h/72h/one-month clocks, measures due 31 October 2026
ictsecuritymagazine.com
Link checked 18 August 2026
What trips people up in Italy?
Five. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit, and skipping it is a criminal matter, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the widely reported rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed, so citing it is wrong.
1. Workplace email metadata. The Garante's June 2024 guidance limits retention of email system metadata to a few days and normally no more than 21. It applied this in April 2025 against Regione Lombardia, which had kept 90 days. This catches almost every standard corporate email platform in its default configuration. 2. Employee monitoring. Article 4 of the Workers' Statute, Law 300/1970, carried into data protection law by Article 114 of the Personal Data Protection Code, requires a trade-union agreement or an authorisation from the labour inspectorate before installing equipment from which remote monitoring of workers could result. Breach is punishable criminally. A standard data protection impact assessment does not substitute for it. 3. Criminal, not administrative. The Personal Data Protection Code keeps criminal offences: Article 167 for unlawful processing including unlawful transfer of personal data abroad, and Article 167-bis for unlawful communication or dissemination of personal data on a large scale. These attach to individuals, not only to companies. The exact prison terms were not verified in this run — see the unconfirmed list. 4. Children. Italy set the age of valid consent for online services at 14 under Article 2-quinquies, where the European default is 16 and many neighbours chose 13 or 16. Age-gating built to a 16 rule is over-restrictive in Italy; one built to 13 is unlawful. 5. Deceased people. Under Article 2-terdecies, the rights of a dead person's data can be exercised by people with an interest, by family members, or by someone acting to protect them. Most deletion workflows assume rights end at death. In Italy they do not. 6. The artificial intelligence rule that is not a rule. A clause requiring public-sector artificial intelligence systems to be installed on servers in Italy passed the Senate and was struck out in committee in the Chamber. The Chamber's own record marks it "Soppresso". It is not in the law that took effect on 10 October 2025, but it is still repeated as if it were.
Sources
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — email metadata retention, Articles 88 GDPR and 114 of the Italian Code (workplace monitoring)
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliMinori — the age of consent for information society services in Italy
garanteprivacy.it
“In Italy the limit is fissed to 14 years, as established by the art. 2-quinquies of d. lgs. n.196/2003”
Link checked 18 August 2026
- Official sourceCamera dei DeputatiChamber of Deputies record for the artificial intelligence bill — Article 6(2) server-location clause marked Soppresso
documenti.camera.it
“I sistemi di intelligenza artificiale destinati all'uso in ambito pubblico, fatta eccezione per quelli impiegati all'estero nell'ambito di operazioni militari, devono essere installati su server ubicati nel territorio nazionale”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliPersonal Data Protection Code — Articles 2-quinquies, 2-terdecies, 114, 167 and 167-bis
garanteprivacy.it
Link checked 18 August 2026
What is changing soon in Italy?
Two firm dates and one open wound. By 31 October 2026 organisations in Italy's network security regime must have their basic security measures in place and evidenced. From 12 January 2027 every cloud provider must charge nothing for switching away or pulling data out. The open wound is the Italian regulator itself: one of four board seats has been empty since January 2026 and Parliament has not filled it.
Landing in the next twelve months. 31 October 2026: basic security measures deadline under the Italian network and information security decree, after which the national cyber agency shifts from hand-holding to audits and inspections. Around October 2026: the twelve-month window for the government to issue the delegated decrees under the artificial intelligence law, which took effect on 10 October 2025, expires — these decrees will decide much of what the law actually means. 12 January 2027: cloud switching charges and data egress fees must be zero across Europe under the Data Act. 2027: the Garante board's seven-year term ends. Live risk. The EU-US Data Privacy Framework was still in force and valid on 18 August 2026, but on 31 July 2026 Europe's data protection board formally asked the Commission to examine whether it is still sound after a US Supreme Court decision on the independence of the US enforcement agency, and a separate appeal is pending before Europe's top court. If it falls, every transfer relying on it moves to standard contracts overnight. DORMANT SWITCHES — powers already held, usable without consultation. First, golden power: under Decree-Law 21/2012 the government must be notified of contracts for fifth-generation mobile network goods and services and can impose binding conditions, expressly to protect Italian know-how, cybersecurity and data — storage location can be one of those conditions, decided case by case and not published in advance. Second, the National Cybersecurity Perimeter: ministries propose and the cyber agency maintains the list of entities inside it, so an organisation can be pulled into a much stricter regime by administrative act. Third, cloud qualification: the national cyber agency grants, and can withdraw, the qualification without which a provider cannot sell to any Italian public body. Fourth, reclassification: moving a public service from ordinary to critical or strategic changes where its data may sit, with no change in the law at all.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854 — zero switching and egress charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinistero delle Imprese e del Made in ItalyGolden power for fifth-generation mobile networks — notification duty and the government's power to impose conditions
mimit.gov.it
“prescrizioni e condizioni che le Imprese sono tenute a rispettare”
Link checked 18 August 2026
- Official sourceGazzetta Ufficiale della Repubblica ItalianaLegge 23 settembre 2025, n. 132 on artificial intelligence — in force 10 October 2025, with delegated decrees to follow
gazzettaufficiale.it
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board — 31 July 2026 letter asking the Commission to examine the EU-US framework
edpb.europa.eu
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
8 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Regolamento (UE) 2016/679 — Regolamento generale sulla protezione dei dati
Directly binding regulation · Regulation (EU) 2016/679
Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe, and it applies to companies outside Europe that target people in Italy.
Enforced by Italian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Put a transfer safeguard in placeA valid instrument plus a documented assessment of the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a local representativeRequired where the controller has no establishment in Europe.
- Keep records of processing
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a third country.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Data Act — Regolamento (UE) 2023/2854
Directly binding regulation · Regulation (EU) 2023/2854
Not about where data sits, but about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.
Enforced by National Cybersecurity Agency
Transfer model: No restriction
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal measures against non-European government access to non-personal data held in Europe where that would conflict with European law.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854, official text
eur-lex.europa.eu
Link checked 18 August 2026
National rules2 rules
Codice in materia di protezione dei dati personali
Act of parliament · Decreto legislativo 30 giugno 2003, n. 196, as amended by Decreto legislativo 10 agosto 2018, n. 101
Italy's own data protection code, kept alive alongside European law. It is where the national oddities live: children consent at 14, dead people's data still has rights, workplace monitoring has its own rules, and some breaches are crimes.
Enforced by Italian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: Under 14 years oldArticle 2-quinquies. Italy chose 14, not the European default of 16.
- Allow a nomineeArticle 2-terdecies: the rights of a deceased person's data may be exercised by people with an interest, by family members, or by an agent acting to protect them.
- Written vendor contract
What it costs if you get it wrong
- Criminal liabilityArticle 167: unlawful processing, including unlawful transfer of personal data outside Europe. Article 167-bis: unlawful communication or dissemination of personal data on a large scale. Prison, and it can attach to individuals.
- Percentage of global turnover: As under the General Data Protection Regulation — about $22 million
Sources
- Official sourceGarante per la protezione dei dati personaliCodice in materia di protezione dei dati personali — coordinated text published by the Garante
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliMinori — Italy's age of consent for online services is 14
garanteprivacy.it
Link checked 18 August 2026
Legge 23 settembre 2025, n. 132 — Disposizioni e deleghe al Governo in materia di intelligenza artificiale
Act of parliament · Legge 132/2025, Gazzetta Ufficiale n. 223 del 25 settembre 2025 · Artificial intelligence
Italy's national artificial intelligence law, in force since 10 October 2025. Important for what it does NOT contain: a clause forcing public-sector artificial intelligence systems onto servers in Italy was struck out in committee before the vote, yet it is still widely reported as binding Italian law. Most of the detail waits on delegated decrees.
Enforced by National Cybersecurity Agency
Transfer model: No restriction
What it makes you do
- Check your algorithmsHuman-centred, transparent and traceable use, with a human keeping the final say — in healthcare the doctor stays responsible for the decision.
- Tell people what you doDisclosure duties around artificial-intelligence-generated content.
What it costs if you get it wrong
- Criminal liabilityThe law adds criminal provisions, including for harmful deepfakes.
Sources
- Official sourceGazzetta Ufficiale della Repubblica ItalianaLegge 23 settembre 2025, n. 132 — official gazette entry, in force 10 October 2025
gazzettaufficiale.it
Link checked 18 August 2026
- Official sourceCamera dei DeputatiChamber of Deputies record — the server-location clause at Article 6(2) marked Soppresso
documenti.camera.it
“devono essere installati su server ubicati nel territorio nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitaleGovernment announcement of final approval of the Italian artificial intelligence law — ACN and AgID designated
innovazione.gov.it
Link checked 18 August 2026
Industry rules8 rules
Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24
Government rules · Determinazione del Direttore generale ACN n. 21007 del 27 giugno 2024 · Government
The real Italian localisation wall. Public-sector data is graded ordinary, critical or strategic; strategic data must sit on infrastructure inside Italy run from Italy, and critical data may not go on a public cloud outside Europe. No provider may sell cloud to an Italian public body without a qualification from the national cyber agency.
Enforced by National Cybersecurity Agency
Transfer model: Allowlist · Accepted routes: Certification scheme
What it makes you do
- Keep the data in the countryStrategic public data: private or hybrid cloud based in Italy with Italian operational management, or the National Strategic Hub. Critical public data: no non-European public cloud. Ordinary data: any European-qualified public cloud.
- Hold a security certificateA cloud service cannot be sold to an Italian public body unless the National Cybersecurity Agency has qualified it.
- Prove the data stays under local controlThe National Strategic Hub is designed to be autonomous from non-EU entities, with encryption controlled domestically.
What it costs if you get it wrong
- Loss of your licenceLoss or refusal of qualification bars the provider from the entire Italian public-sector market.
Sources
- Official sourceDipartimento per la trasformazione digitaleIl percorso di qualificazione dei servizi cloud della PA — qualification by the National Cybersecurity Agency is mandatory; single cloud regulation adopted 27 June 2024
cloud.italia.it
“destinati alle pubbliche amministrazioni devono ottenere, per questi servizi, la qualificazione rilasciata dall'Agenzia per la Cybersicurezza Nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitale / Agenzia per la cybersicurezza nazionaleStrategia Cloud Italia — the ordinario / critico / strategico classification and the hosting model for each
docs.italia.it
Link checked 18 August 2026
- Official sourceAgenzia per la Cybersicurezza NazionaleRegolamento cloud — full text published by the National Cybersecurity Agency
acn.gov.it
Link checked 18 August 2026
Perimetro di sicurezza nazionale cibernetica
Act of parliament · Decreto-legge 21 settembre 2019, n. 105, converted by Legge 133/2019; DPCM 131/2020; DPCM 81/2021; DPR 54/2021 · Defence
A national-security regime layered on top of everything else. Designated public and private bodies in strategic sectors must get their technology purchases vetted before buying, and must report incidents on a very short clock. Being added to the list is an administrative decision you cannot appeal your way out of quickly.
Enforced by National Cybersecurity Agency
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Report cyber incidents — within 6 hoursSix hours is the figure in general circulation for the most serious incident category; not verified against the decree text in this run.
- Register or notifyEntities are placed inside the perimeter by ministries; the National Cybersecurity Agency maintains the list.
- Independent auditBefore buying technology goods, systems or services for the most sensitive assets, the entity must notify the national evaluation and certification centre, which can impose conditions or test the product.
What it costs if you get it wrong
- Fixed maximum fineAdministrative penalties for failure to notify a procurement or an incident.
- Criminal liabilityProviding false information to obstruct the vetting process.
Sources
- Official sourceMinistero delle Imprese e del Made in ItalyPerimetro di sicurezza cibernetica nazionale — legal basis, designation and pre-purchase notification to the CVCN
mimit.gov.it
“assicurare un livello elevato di sicurezza delle reti, dei sistemi informativi e dei servizi informatici”
Link checked 18 August 2026
Articolo 132 del Codice in materia di protezione dei dati personali; articolo 24 della legge 20 novembre 2017, n. 167
Act of parliament · D.Lgs. 196/2003 art. 132; Legge 167/2017 art. 24; D.L. 132/2021 converted by Legge 178/2021 · Telecoms
Italian telecoms and internet providers must keep call and connection records for years — two years for phone records, one year for internet records, six years where terrorism or serious crime is involved. There is no rule about where those records are stored, only that they exist and that a judge must sign before anyone reads them.
Enforced by Italian Data Protection Authority
Transfer model: No restriction
What it makes you do
- Keep data for a minimum period — 2 yearsTelephone traffic data 24 months; internet traffic data 12 months; unanswered calls 30 days.
- Keep data for a minimum period — 6 yearsSix years for terrorism and certain serious offences, under Article 24 of Law 167/2017, preserved by Article 132(5-bis).
- Secure the dataAccess requires a reasoned order from a judge; a prosecutor may act in urgency and must have it confirmed within 48 hours.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to secure traffic data.
Sources
- Official sourceCamera dei DeputatiCamera dei Deputati dossier — Article 132 retention periods and the 72-month counter-terrorism carve-out
documenti.camera.it
“È fatta salva la disciplina di cui all'articolo 24 della legge 20 novembre 2017, n. 167”
Link checked 18 August 2026
Documento di indirizzo — Programmi e servizi informatici di gestione della posta elettronica nel contesto lavorativo
Regulator guideline · Garante, documento di indirizzo 6 giugno 2024; applied in Provvedimento n. 243 del 29 aprile 2025
Italy's sharpest retention ceiling, and the one that catches almost every foreign employer. The logs behind staff email may normally be kept for at most 21 days. A regional government was punished in April 2025 for keeping 90.
Enforced by Italian Data Protection Authority
Transfer model: No restriction
What it makes you do
- Delete data after a periodEmail system metadata normally kept a few days, in no case more than 21 days, unless the employer goes through the trade-union agreement or labour-inspectorate route.
- Keep logsKeeping longer turns an IT housekeeping function into remote monitoring of workers, which needs a union agreement or a permit.
What it costs if you get it wrong
- Fixed maximum fineApplied in April 2025 against a regional government that retained 90 days of metadata.
- Criminal liabilityInstalling monitoring-capable tools without a union agreement or labour-inspectorate authorisation is a criminal matter under the Workers' Statute.
Sources
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — Regione Lombardia, email metadata and browsing logs
garanteprivacy.it
“di norma, per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni”
Link checked 18 August 2026
Decreto legislativo 4 settembre 2024, n. 138 — recepimento della direttiva NIS2
Act of parliament · D.Lgs. 138/2024; ACN determinazione n. 164179 del 14 aprile 2025; ACN determinazione n. 379907/2025
Italy's cybersecurity regime for essential and important organisations. The law started in October 2024 but the duties arrive in stages: incident reporting became real on 15 January 2026 and the security measures must be in place by 31 October 2026. It says nothing about where data is stored.
Enforced by National Cybersecurity Agency
Transfer model: No restriction
What it makes you do
- Register or notifyRegistration on the agency's platform, with an annual renewal window of 1 January to 28 February. Over 20,000 organisations identified.
- Report cyber incidents — within 24 hours, from 15 January 2026Early warning within 24 hours, notification within 72 hours, final report within one month.
- Secure the data — from 31 October 2026Basic security measures must be implemented and evidenced by 31 October 2026; 37 measures for important entities, 43 for essential ones.
What it costs if you get it wrong
- Percentage of global turnoverFailure to implement measures or to notify incidents.
Sources
- Official sourceAgenzia per la Cybersicurezza NazionaleACN — basic security measures and notification specifications under the Italian NIS2 decree
acn.gov.it
Link checked 18 August 2026
- Secondary sourceICT Security MagazineNIS2 and D.Lgs. 138/2024 — the Italian phase-in timetable and determination numbers
ictsecuritymagazine.com
Link checked 18 August 2026
Fascicolo Sanitario Elettronico 2.0 — decreto del Ministero della salute 7 settembre 2023; Ecosistema Dati Sanitari — decreto 31 dicembre 2024
Government rules · D.M. Salute 7 settembre 2023; D.M. 31 dicembre 2024; art. 12 D.L. 179/2012 · Health and social care
Italian health records are pulled into a national state-run system rather than left with each hospital. Insurers, employers and expert witnesses are locked out by design. Records are deleted 30 years after the patient dies, and public health bodies must follow the public-sector cloud rules on top.
Enforced by Italian Data Protection Authority
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryHealth records flow into state-run national infrastructure — the National Interoperability Infrastructure and the Health Data Ecosystem. Public health bodies are public administrations, so they also inherit the public-sector cloud rules, which keep critical data off non-European public cloud.
- Delete data after a period — 30 yearsRecords are erased 30 years after the patient's death, on an annual cycle.
- Let people objectPatients may block the record being populated and may obscure individual documents; the fact that something has been obscured is itself hidden.
What it costs if you get it wrong
- Percentage of global turnoverHealth data is sensitive data, so the higher European penalty tier applies.
- Order to stopThe Garante has repeatedly ordered changes to regional health systems.
Sources
- Official sourceGarante per la protezione dei dati personaliFascicolo Sanitario Elettronico — the Garante's topic page on FSE 2.0, the Health Data Ecosystem, access rules and retention
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliParere on the Health Ministry's Ecosistema Dati Sanitari decree, 26 September 2024
garanteprivacy.it
Golden power — poteri speciali su reti 5G e servizi cloud
Act of parliament · Decreto-legge 15 marzo 2012, n. 21, artt. 1-bis e 2; Decreto-legge 105/2019 · Telecoms
The dormant switch. Contracts for fifth-generation mobile networks and related technology must be notified to the government, which can attach binding conditions to protect Italian data and cybersecurity. Nothing in the law says data must stay in Italy, but a condition in your contract can say exactly that, with no consultation and no advance warning.
Enforced by Ministry of Enterprise and Made in Italy
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyCompanies must notify the Prime Minister's Office of contracts for goods and services used to design, build, maintain or run fifth-generation broadband networks, naming suppliers and components.
- Keep the data in the countryNot automatic. The government may attach binding conditions to a notified contract, expressly to protect Italian know-how, cybersecurity and data. Storage location can be one of them, decided case by case and not published in advance.
What it costs if you get it wrong
- Fixed maximum fineFailure to notify, or breach of imposed conditions.
- Order to stopThe government can veto the transaction outright.
Sources
- Official sourceMinistero delle Imprese e del Made in ItalyGolden Power (5G) — notification duty and the government's power to impose prescriptions and conditions
mimit.gov.it
“prescrizioni e condizioni che le Imprese sono tenute a rispettare”
Link checked 18 August 2026
Regolamento (UE) 2022/2554 (DORA) e comunicazioni Banca d'Italia
Directly binding regulation · Regulation (EU) 2022/2554; Banca d'Italia comunicazione dicembre 2024; Circolare 285, 51st update 3 February 2026 · Finance
Italian banks, insurers, payment firms and investment firms have no data localisation duty. Banca d'Italia has confirmed its old sectoral outsourcing prohibitions no longer apply; since 17 January 2025 the European financial resilience rules govern instead, and they require disclosure of where data sits, not that it sit anywhere in particular.
Enforced by Bank of Italy
Transfer model: No restriction
What it makes you do
- Written vendor contractContracts with technology suppliers must state where data is processed and stored, give audit and access rights, and include an exit plan.
- Register or notifyFinancial entities must promptly inform the supervisor of contracts for technology services supporting essential or important functions.
- Report cyber incidentsSerious technology incidents reported to Banca d'Italia through its Infostat channel, on the European timetable rather than the national cyber agency's.
What it costs if you get it wrong
- Loss of your licenceSupervisory measures against the regulated entity.
Sources
- Official sourceBanca d'ItaliaBanca d'Italia — Regolamento DORA: application from 17 January 2025 and the replacement of sectoral outsourcing prohibitions
bancaditalia.it
“Ai sensi dell'articolo 64 del Regolamento DORA, le previsioni in esso contenute si applicano a decorrere dal 17 gennaio 2025”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That online gaming concessionaires must keep the gaming platform or player-account data on servers in Italy or the European Economic Area
The customs and monopolies agency's own tender FAQ refused automated fetching (HTTP 403), so the concession's technical rules could not be read. Treated as not established rather than as absent.
The exact six-hour incident notification deadline for entities inside the National Cybersecurity Perimeter
The ministry's own page describes the notification duty but does not state the hours, and the implementing decree text was not fetched. Six hours is the figure in general circulation.
The exact 2026 network-security deadlines: incident reporting operative from 15 January 2026, basic measures due 31 October 2026, and the ACN determination numbers 164179/2025 and 379907/2025
The National Cybersecurity Agency's site returns HTTP 403 to automated fetching, so these rest on professional commentary rather than the agency's own text.
The exact prison terms attached to Articles 167 and 167-bis of the Italian Personal Data Protection Code
The Garante's coordinated text of the Code is a PDF that could not be quoted article by article in this run. The existence and subject matter of both offences is confirmed; the sentencing ranges are not.
The precise commencement date of the ACN single cloud regulation (recorded here as 1 August 2024)
The official page says the ordinary qualification regime enters into force in August 2024 without giving a day; the determination was adopted 27 June 2024.
That a successor to Guido Scorza on the Garante board had still not been elected as at 18 August 2026
The authority's own board page records his term ending 19 January 2026 but does not comment on the vacancy. The claim that Parliament has not voted rests on a media source.
The ten-year retention floor for Italian accounting and commercial records under Article 2220 of the Civil Code
Well established but not re-verified against an official source during this run, in line with the rule against answering from memory.
Whether any mapping or geospatial restriction survives from Italy's older cartography legislation
No current rule found, checked 18 August 2026. Searched but not confirmed either way against an official source.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.