Italy
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Italy — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Italy does not make ordinary business data stay in Italy. European rules decide when data may leave Europe, and Italy adds its own rules on top. The answer changes completely when your customer is the Italian state. That means a ministry, a town hall, a hospital or a school. The most sensitive government data has to sit on machines inside Italy, run from Italy.
Data governance in Italy
The eight things that decide how you handle data about people in Italy. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, the law reaches you with no office in Italy. European law applies to any organisation anywhere that offers goods or services to people in Italy. It also applies if you monitor what they do online. There is no size or revenue threshold to duck under. If you have no branch anywhere in Europe, you must appoint a written representative based in Europe. People and regulators can go to that representative instead of chasing you abroad.
- What you have to do here:
- Appoint a representative
There are three layers. Layer 1 is the General Data Protection Regulation, Articles 3 and 27. Layer 2 is Italy's own Personal Data Protection Code, Legislative Decree 196/2003, as rewritten by Legislative Decree 101/2018. It keeps a set of national rules that sit alongside the European ones. They cover employment and workplace monitoring, the age of consent for children, the data of dead people, telecoms traffic data, and a set of crimes. Those national rules apply to anyone who uses or stores data in Italy. That includes foreign companies acting through an Italian office or targeting the Italian market. Layer 3 comes from public-sector buying rules. It is contractual and technical rather than data protection law. A cloud service cannot be sold to an Italian public body at all unless the National Cybersecurity Agency has approved it.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27 — territorial scope and the European representative
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliCodice in materia di protezione dei dati personali (coordinated text of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018)
garanteprivacy.it
Link checked 18 August 2026
Where the data is allowed to live
Yes, for a normal private company, with paperwork, exactly as anywhere else in Europe. Italy has no general law saying personal data must be stored in Italy. The real limits sit in one place. They apply to anything sold to or run by the Italian public sector. Government data is graded ordinary, critical or strategic. The top two grades cannot sit on a public cloud outside Europe. Strategic data must stay on infrastructure inside Italy and be run from Italy.
- What you have to do here:
- Keep the data in the country
Here is each industry, checked 18 August 2026. GOVERNMENT AND PUBLIC SECTOR. Closed for strategic data (data must stay in the country). Europe only for critical data (data can leave only if conditions are met). The Cloud Italia strategy defines strategic data as data whose loss would affect national security. Critical data is data whose loss would damage functions important to society. Ordinary data is everything else. Strategic work goes to a private or hybrid cloud based in Italy and managed from Italy, or to the National Strategic Hub. Critical work must avoid public cloud outside Europe. Ordinary work may use any European-approved public cloud. The National Strategic Hub is designed to be "autonomi da soggetti extra UE", meaning independent of bodies outside Europe. Separately, any cloud service sold to a public body must first be approved by the National Cybersecurity Agency. That runs under its single cloud rules, adopted 27 June 2024. The ordinary approval process has run since August 2024. HEALTH. Conditional in the private sector (data can leave only if conditions are met). Public health bodies are public administrations, so they follow the rules above. So hospital and regional health systems sit on European or Italian infrastructure. Health records also flow into a national system. That is the Electronic Health Record 2.0, built on the National Interoperability Infrastructure and the Health Data Ecosystem. It is governed by the Health Ministry decree of 7 September 2023 and the Health Data Ecosystem decree of 31 December 2024. TELECOMS. Conditional (data can leave only if conditions are met). We found no rule about where data must be stored, checked 18 August 2026. But you must keep records for a long time. Telephone traffic data runs 24 months. Internet traffic data runs 12 months. Unanswered calls run 30 days. A separate 72-month rule covers terrorism and serious crime. BANKING, PAYMENTS, SECURITIES, INSURANCE. Open (data can leave freely). We found no rule requiring data to stay in the country, checked 18 August 2026. The Bank of Italy has confirmed that its earlier bans on outsourcing no longer apply to technology services supporting essential or important functions. The European financial resilience regulation replaced them with a duty to notify, from 17 January 2025. It does not require data to stay in any particular country. DEFENCE AND CRITICAL INFRASTRUCTURE. Conditional and government-controlled (data can leave only if conditions are met). Organisations inside the National Cybersecurity Perimeter must tell the national vetting centre before they buy technology goods, systems or services for their most sensitive assets. The government can attach conditions. ARTIFICIAL INTELLIGENCE. Open (data can leave freely). A clause requiring public-sector artificial intelligence systems to be installed on servers in Italy was in the bill. It was struck out in committee before the law passed. It is not law. MAPPING AND GEOSPATIAL, EDUCATION, E-COMMERCE. We found no rule requiring data to stay in the country, checked 18 August 2026, confidence medium. ONLINE GAMING. Not confirmed. See the unconfirmed list.
Sources
- Official sourceDipartimento per la trasformazione digitale / Agenzia per la cybersicurezza nazionaleStrategia Cloud Italia — classification of public-sector data as ordinario, critico and strategico and the hosting model for each
docs.italia.it
“dati e servizi la cui compromissione può avere un impatto sulla sicurezza nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitalePolo Strategico Nazionale — national infrastructure for critical and strategic public data, designed to be independent of non-EU entities
cloud.italia.it
Link checked 18 August 2026
- Official sourceBanca d'ItaliaBanca d'Italia on the Digital Operational Resilience Act — sectoral outsourcing prohibitions replaced by a notification duty from 17 January 2025
bancaditalia.it
“informano tempestivamente l'autorità competente in merito a eventuali accordi contrattuali previsti per l'utilizzo di servizi ICT a supporto di funzioni essenziali o importanti”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 — member states may not impose storage-location rules on non-personal data except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
There are three routes, and they are European rather than Italian. Best case, the country you send to is on Europe's official approved list, and you need nothing extra. Otherwise you sign Europe's standard contract with the receiver. Or you get group-wide internal rules approved by a regulator. With the last two you must also write down an assessment. It must say whether the destination country's surveillance laws would undermine the protection. Italy adds no extra permission step. It does add a crime for getting it badly wrong.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
- What it costs if you get it wrong:
- Criminal liability
You may only send data to approved countries, with contracts as a fallback. We checked the approved list on the Commission's own page on 18 August 2026. It has 17 entries. Andorra, Argentina, Brazil (added 26 January 2026), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States but only for companies self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. Nothing has been withdrawn or suspended. The 2021 standard contractual clauses are still the ones to use. Europe promised new clauses for receivers already directly covered by European law. Those had still not been adopted on 18 August 2026. There are narrow one-off exceptions, such as explicit consent, need to perform a contract, or legal claims. They are not for routine or bulk transfers. Italy adds Article 167(2) of the Personal Data Protection Code. It makes an unlawful transfer of personal data out of Europe a crime rather than an administrative matter.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliPersonal Data Protection Code, Article 167 — criminal offence of unlawful processing, including unlawful transfer abroad
garanteprivacy.it
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Italian data protection authority enforces the rules. It is known as the Garante. It is one of the busiest and boldest regulators in Europe. In 2025 alone it took 807 decisions, of which 506 were corrective or punitive. It ran 130 inspections and collected more than 37 million euros (about 41 million US dollars) in fines. It was the first regulator in the world to order a temporary halt to a major chatbot service. It has since blocked or restricted several artificial intelligence products. A separate agency enforces cybersecurity.
- What it costs if you get it wrong:
- Percentage of global turnover · Order to stop
Parliament elects the Garante's board, which normally has four members. One member, Guido Scorza, resigned on 19 January 2026. That followed a period of political argument over the authority's independence. The authority's own board page records his term as ending on that date. As at 18 August 2026 no replacement had been reported as elected. The remaining three members carry on. The authority has published decisions throughout 2026, including its annual report on 2 July 2026. The board's seven-year term began on 29 July 2020 and runs to 2027. The National Cybersecurity Agency handles cybersecurity, the national cyber perimeter, network and information security rules, and cloud approval for public bodies. It is fully up and running and issues binding decisions. Financial firms answer to the Bank of Italy under the European financial resilience rules. The communications authority supervises telecoms. We rate the Garante aggressive. It goes looking rather than waiting for complaints. It uses orders to stop using data, which hurt more than the fines.
Sources
- Official sourceGarante per la protezione dei dati personaliRelazione sull'attività 2025 — press summary, published 2 July 2026: 807 decisions, 506 corrective and sanctioning measures, over EUR 37m in fines, 130 inspections, 2,415 breach notifications
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliIl Collegio — board composition; Guido Scorza's term recorded as 29 July 2020 to 19 January 2026
garanteprivacy.it
Link checked 18 August 2026
- Official sourceAgenzia per la Cybersicurezza NazionaleNational Cybersecurity Agency — network and information security supervision
acn.gov.it
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are minimum keeping times and maximum keeping times, and they pull hard against each other. You must keep telephone records 24 months, internet connection records 12 months and unanswered calls 30 days. A separate six-year rule covers terrorism and serious crime. Health records in the national system are erased 30 years after the patient dies. The maximum is much tighter than people expect. The regulator says the technical logs behind staff email may normally be kept for no more than 21 days.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
Minimum keeping times. Article 132 of the Personal Data Protection Code sets 24 months for telephone traffic data. It sets 12 months for internet traffic data, not counting the content of messages. It sets 30 days for unanswered calls. All of this is for criminal investigations. Article 132(5-bis) keeps Article 24 of Law 167/2017 alive. That extends the period to 72 months for terrorism and certain serious crimes. Since the 2021 reform, reading any of it needs a reasoned order from a judge. Ordinary commercial and accounting records are generally kept ten years under the Civil Code. See the unconfirmed list, as we did not re-check this. Health records in the Electronic Health Record are deleted 30 years after death, on an annual cycle. Maximum keeping times. General European law says do not keep personal data longer than you need it. Italy's sharpest specific limit is the Garante's June 2024 guidance on workplace email. It says the technical logs may normally be kept "per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni". That means a few days at most, and never more than 21. In April 2025 the Garante used it against a regional government that had kept 90 days of those logs. When they clash. Where a legal duty to keep runs into a duty to delete, the duty to keep wins for the narrow purpose that requires it. But you must lock the data down and use it for nothing else.
Sources
- Official sourceCamera dei DeputatiChamber of Deputies dossier on Article 132 of the Privacy Code — retention periods and the 72-month counter-terrorism regime
documenti.camera.it
“i dati relativi al traffico telefonico conservati dal fornitore per ventiquattro mesi dalla data della comunicazione”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — workplace email metadata, 21-day ceiling applied against a 90-day retention
garanteprivacy.it
“di norma, per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliFascicolo Sanitario Elettronico — national health record; records erased 30 years after death
garanteprivacy.it
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least three deadlines, and they run at the same time. A personal data breach goes to the Garante within 72 hours. You must tell the people affected without delay where the risk to them is high. If Italy's network security rules cover you, a first warning goes to the national cyber agency within 24 hours. A fuller notice follows within 72 hours and a final report within a month. Organisations inside the national cyber perimeter have far less time. The figure reported is six hours.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline one. General Data Protection Regulation Articles 33 and 34. You have 72 hours to tell the Garante. You must tell the people affected without undue delay where the risk is high. The Garante received 2,415 breach notifications in 2025, up about ten per cent on 2024. Deadline two. The Italian network and information security decree, Legislative Decree 138/2024. It puts the European NIS2 directive into Italian law. Registration opened on 1 December 2024, with an annual renewal window of 1 January to 28 February. Incident reporting duties started on 15 January 2026 under a National Cybersecurity Agency decision. You must send an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within one month. Basic security measures must be in place by 31 October 2026. These dates come from professional commentary, because the agency's own site refused automated fetching. See the unconfirmed list. Deadline three. The National Cybersecurity Perimeter, set up by Decree-Law 105/2019, with decrees 131/2020 and 81/2021 filling in the detail. Named public and private bodies in strategic industries must report incidents very fast. Six hours is the figure in circulation. They must also tell the national vetting centre before buying technology for their most sensitive systems. Deadline four, for financial firms only. The European financial resilience rules. You report to the Bank of Italy through its Infostat channel, not to the cyber agency.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinistero delle Imprese e del Made in ItalyPerimetro di sicurezza nazionale cibernetica — legal basis, designation of entities and pre-purchase notification to the national vetting centre
mimit.gov.it
“dell'intenzione di acquisire beni, sistemi e servizi ICT”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliRelazione sull'attività 2025 — 2,415 data breach notifications received
garanteprivacy.it
Link checked 18 August 2026
- Secondary sourceICT Security MagazineNIS2 and Legislative Decree 138/2024 — the 2026 timetable, determination 379907/2025, 24h/72h/one-month clocks, measures due 31 October 2026
ictsecuritymagazine.com
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five traps. One: staff email logs may normally be kept only 21 days, and a regional government was punished in 2025 for keeping 90. Two: before you install any tool that could monitor employees, you need a union agreement or a labour inspectorate permit. Skipping it is a crime, not a fine. Three: some data offences in Italy carry prison, not just penalties. Four: children can consent at 14 in Italy, not 16. Five: the rule forcing public-sector artificial intelligence onto Italian servers was deleted before the law passed. It is not law.
- What you have to do here:
- Keep logs · Delete data after a period · Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. Workplace email logs. The Garante's June 2024 guidance limits how long you keep the technical logs behind email. It says a few days, and normally no more than 21. It applied this in April 2025 against Regione Lombardia, which had kept 90 days. Almost every standard corporate email platform breaks this in its default setup. 2. Employee monitoring. Article 4 of the Workers' Statute, Law 300/1970, carried into data protection law by Article 114 of the Personal Data Protection Code. You need a trade-union agreement, or permission from the labour inspectorate, before installing equipment that could let you monitor workers remotely. Breaking this is a crime. A standard data protection impact assessment is not a substitute. 3. Crimes, not just fines. The Personal Data Protection Code keeps some crimes alive. Article 167 covers unlawful use of data, including unlawfully sending personal data abroad. Article 167-bis covers unlawfully sharing or publishing personal data on a large scale. These attach to individuals, not only to companies. We did not confirm the exact prison terms. See the unconfirmed list. 4. Children. Italy set the age of valid consent for online services at 14, under Article 2-quinquies. The European default is 16, and many neighbours chose 13 or 16. An age check built to a 16 rule is too strict in Italy. One built to 13 is unlawful. 5. Dead people. Under Article 2-terdecies, someone else can exercise the rights over a dead person's data. That can be people with an interest, family members, or someone acting to protect them. Most deletion workflows assume rights end at death. In Italy they do not. 6. The artificial intelligence rule that is not a rule. A clause requiring public-sector artificial intelligence systems to be installed on servers in Italy passed the Senate. It was struck out in committee in the Chamber. The Chamber's own record marks it "Soppresso". It is not in the law that took effect on 10 October 2025. It is still repeated as if it were.
Sources
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — email metadata retention, Articles 88 GDPR and 114 of the Italian Code (workplace monitoring)
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliMinori — the age of consent for information society services in Italy
garanteprivacy.it
“In Italy the limit is fissed to 14 years, as established by the art. 2-quinquies of d. lgs. n.196/2003”
Link checked 18 August 2026
- Official sourceCamera dei DeputatiChamber of Deputies record for the artificial intelligence bill — Article 6(2) server-location clause marked Soppresso
documenti.camera.it
“I sistemi di intelligenza artificiale destinati all'uso in ambito pubblico, fatta eccezione per quelli impiegati all'estero nell'ambito di operazioni militari, devono essere installati su server ubicati nel territorio nazionale”
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliPersonal Data Protection Code — Articles 2-quinquies, 2-terdecies, 114, 167 and 167-bis
garanteprivacy.it
Link checked 18 August 2026
What's changing next
Two firm dates and one open problem. By 31 October 2026, organisations covered by Italy's network security rules must have their basic security measures in place, with evidence. From 12 January 2027, every cloud provider must charge nothing for switching away or pulling your data out. The open problem is the Italian regulator itself. One of four board seats has been empty since January 2026, and Parliament has not filled it.
- What you have to do here:
- Make switching cloud provider possible · Hold a security certificate · Prove the data stays under local control
Landing in the next twelve months. 31 October 2026: the deadline for basic security measures under the Italian network and information security decree. After that the national cyber agency moves from helping to auditing and inspecting. Around October 2026: the twelve-month window for the government to issue the follow-up decrees under the artificial intelligence law expires. That law took effect on 10 October 2025. Those decrees will decide much of what it actually means. 12 January 2027: across Europe, cloud switching charges and charges for pulling your data out must be zero, under the Data Act. 2027: the Garante board's seven-year term ends. Live risk. The EU-US Data Privacy Framework was still in force and valid on 18 August 2026. On 31 July 2026 Europe's data protection board formally asked the Commission to examine whether it is still sound. That followed a United States Supreme Court decision on the independence of the United States enforcement agency. A separate appeal is pending before Europe's top court. If it falls, every transfer relying on it moves to standard contracts overnight. FOUR CHANGES THE GOVERNMENT CAN MAKE WITHOUT CONSULTATION. First, golden power. Under Decree-Law 21/2012 you must notify the government of contracts for fifth-generation mobile network goods and services. It can impose binding conditions, to protect Italian know-how, cybersecurity and data. Where data is stored can be one of those conditions. It is decided case by case and not published in advance. Second, the National Cybersecurity Perimeter. Ministries propose the list of bodies inside it and the cyber agency maintains it. So an organisation can be pulled into much stricter rules by an administrative act. Third, cloud approval. The national cyber agency grants the approval a provider needs to sell to any Italian public body, and it can withdraw it. Fourth, regrading. Moving a public service from ordinary to critical or strategic changes where its data may sit, with no change in the law at all.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854 — zero switching and egress charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinistero delle Imprese e del Made in ItalyGolden power for fifth-generation mobile networks — notification duty and the government's power to impose conditions
mimit.gov.it
“prescrizioni e condizioni che le Imprese sono tenute a rispettare”
Link checked 18 August 2026
- Official sourceGazzetta Ufficiale della Repubblica ItalianaLegge 23 settembre 2025, n. 132 on artificial intelligence — in force 10 October 2025, with delegated decrees to follow
gazzettaufficiale.it
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board — 31 July 2026 letter asking the Commission to examine the EU-US framework
edpb.europa.eu
What to do: Diarise 31 October 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries8 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Regolamento unico per le infrastrutture e i servizi cloud per la PA — Determinazione ACN n. 21007/24 · Determinazione del Direttore generale ACN n. 21007 del 27 giugno 2024 · Government rules
The real Italian rule about keeping data in the country. Public-sector data is graded ordinary, critical or strategic. Strategic data must sit on infrastructure inside Italy and be run from Italy. Critical data may not go on a public cloud outside Europe. No provider may sell cloud to an Italian public body without approval from the national cyber agency.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme
What you have to do
- Keep the data in the countryStrategic public data: a private or hybrid cloud based in Italy and managed from Italy, or the National Strategic Hub. Critical public data: no public cloud outside Europe. Ordinary data: any European-approved public cloud.
- Hold a security certificateA cloud service cannot be sold to an Italian public body unless the National Cybersecurity Agency has approved it.
- Prove the data stays under local controlThe National Strategic Hub is designed to run independently of bodies outside the European Union, with encryption controlled inside Italy.
What it costs if you get it wrong
- Loss of your licenceLoss or refusal of qualification bars the provider from the entire Italian public-sector market.
Sources
- Official sourceDipartimento per la trasformazione digitaleIl percorso di qualificazione dei servizi cloud della PA — qualification by the National Cybersecurity Agency is mandatory; single cloud regulation adopted 27 June 2024
cloud.italia.it
“destinati alle pubbliche amministrazioni devono ottenere, per questi servizi, la qualificazione rilasciata dall'Agenzia per la Cybersicurezza Nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitale / Agenzia per la cybersicurezza nazionaleStrategia Cloud Italia — the ordinario / critico / strategico classification and the hosting model for each
docs.italia.it
Link checked 18 August 2026
- Official sourceAgenzia per la Cybersicurezza NazionaleRegolamento cloud — full text published by the National Cybersecurity Agency
acn.gov.it
Link checked 18 August 2026
Breach reporting rules
Official name: Perimetro di sicurezza nazionale cibernetica · Decreto-legge 21 settembre 2019, n. 105, converted by Legge 133/2019; DPCM 131/2020; DPCM 81/2021; DPR 54/2021 · Act of parliament
National-security rules layered on top of everything else. Named public and private bodies in strategic industries must get their technology purchases vetted before buying. They must also report incidents very fast. Being added to the list is an administrative decision, and you cannot appeal your way out of it quickly.
Enforced by National Cybersecurity Agency
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Report cyber incidents — within 6 hoursSix hours is the figure in general circulation for the most serious incidents. We did not confirm it against the decree text.
- Register or notifyMinistries place bodies inside the perimeter. The National Cybersecurity Agency maintains the list.
- Independent auditBefore buying technology goods, systems or services for the most sensitive assets, you must tell the national evaluation and certification centre. It can impose conditions or test the product.
What it costs if you get it wrong
- Fixed maximum fineAdministrative penalties for failure to notify a procurement or an incident.
- Criminal liabilityProviding false information to obstruct the vetting process.
Sources
- Official sourceMinistero delle Imprese e del Made in ItalyPerimetro di sicurezza cibernetica nazionale — legal basis, designation and pre-purchase notification to the CVCN
mimit.gov.it
“assicurare un livello elevato di sicurezza delle reti, dei sistemi informativi e dei servizi informatici”
Link checked 18 August 2026
Telecoms rules
Official name: Articolo 132 del Codice in materia di protezione dei dati personali; articolo 24 della legge 20 novembre 2017, n. 167 · D.Lgs. 196/2003 art. 132; Legge 167/2017 art. 24; D.L. 132/2021 converted by Legge 178/2021 · Act of parliament
Italian telecoms and internet providers must keep call and connection records for years. Phone records run two years. Internet records run one year. Records run six years where terrorism or serious crime is involved. There is no rule about where those records are stored. The rules say only that they must exist, and that a judge must sign before anyone reads them.
Enforced by Italian Data Protection Authority
How this country controls where data goes: No restriction
What you have to do
- Keep data for a minimum period — 2 yearsTelephone traffic data 24 months; internet traffic data 12 months; unanswered calls 30 days.
- Keep data for a minimum period — 6 yearsSix years for terrorism and certain serious offences, under Article 24 of Law 167/2017, preserved by Article 132(5-bis).
- Secure the dataReading the records needs a reasoned order from a judge. A prosecutor may act in an emergency, and must have the order confirmed within 48 hours.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to secure traffic data.
Sources
- Official sourceCamera dei DeputatiCamera dei Deputati dossier — Article 132 retention periods and the 72-month counter-terrorism carve-out
documenti.camera.it
“È fatta salva la disciplina di cui all'articolo 24 della legge 20 novembre 2017, n. 167”
Link checked 18 August 2026
Government data rules
Official name: Documento di indirizzo — Programmi e servizi informatici di gestione della posta elettronica nel contesto lavorativo · Garante, documento di indirizzo 6 giugno 2024; applied in Provvedimento n. 243 del 29 aprile 2025 · Regulator guideline
Italy's tightest limit on how long you can keep data, and the one that catches almost every foreign employer. The technical logs behind staff email may normally be kept for at most 21 days. A regional government was punished in April 2025 for keeping 90.
Enforced by Italian Data Protection Authority
How this country controls where data goes: No restriction
What you have to do
- Delete data after a periodKeep the technical logs behind email for a few days, and never more than 21 days. The only way round it is a trade-union agreement or permission from the labour inspectorate.
- Keep logsKeeping them longer turns routine IT housekeeping into remote monitoring of workers. That needs a union agreement or a permit.
What it costs if you get it wrong
- Fixed maximum fineApplied in April 2025 against a regional government that retained 90 days of metadata.
- Criminal liabilityInstalling monitoring-capable tools without a union agreement or labour-inspectorate authorisation is a criminal matter under the Workers' Statute.
Sources
- Official sourceGarante per la protezione dei dati personaliProvvedimento n. 243 del 29 aprile 2025 — Regione Lombardia, email metadata and browsing logs
garanteprivacy.it
“di norma, per un periodo limitato a pochi giorni, comunque non superiore ai 21 giorni”
Link checked 18 August 2026
Cyber security rules
Official name: Decreto legislativo 4 settembre 2024, n. 138 — recepimento della direttiva NIS2 · D.Lgs. 138/2024; ACN determinazione n. 164179 del 14 aprile 2025; ACN determinazione n. 379907/2025 · Act of parliament
Italy's cybersecurity rules for essential and important organisations. The law started in October 2024, but the duties arrive in stages. Incident reporting became real on 15 January 2026. The security measures must be in place by 31 October 2026. The law says nothing about where data is stored.
Enforced by National Cybersecurity Agency
How this country controls where data goes: No restriction
What you have to do
- Register or notifyRegistration on the agency's platform, with an annual renewal window of 1 January to 28 February. Over 20,000 organisations identified.
- Report cyber incidents — within 24 hours, from 15 January 2026Early warning within 24 hours, notification within 72 hours, final report within one month.
- Secure the data — from 31 October 2026Basic security measures must be in place, with evidence, by 31 October 2026. There are 37 measures for important bodies and 43 for essential ones.
What it costs if you get it wrong
- Percentage of global turnoverFailure to implement measures or to notify incidents.
Sources
- Official sourceAgenzia per la Cybersicurezza NazionaleACN — basic security measures and notification specifications under the Italian NIS2 decree
acn.gov.it
Link checked 18 August 2026
- Secondary sourceICT Security MagazineNIS2 and D.Lgs. 138/2024 — the Italian phase-in timetable and determination numbers
ictsecuritymagazine.com
Link checked 18 August 2026
Health and social care data must stay in the country
Official name: Fascicolo Sanitario Elettronico 2.0 — decreto del Ministero della salute 7 settembre 2023; Ecosistema Dati Sanitari — decreto 31 dicembre 2024 · D.M. Salute 7 settembre 2023; D.M. 31 dicembre 2024; art. 12 D.L. 179/2012 · Government rules
Italian health records go into a national state-run system rather than staying with each hospital. Insurers, employers and expert witnesses are shut out by design. Records are deleted 30 years after the patient dies. Public health bodies must also follow the public-sector cloud rules.
Enforced by Italian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryHealth records flow into state-run national systems: the National Interoperability Infrastructure and the Health Data Ecosystem. Public health bodies are public administrations, so the public-sector cloud rules also apply to them. Those rules keep critical data off public cloud outside Europe.
- Delete data after a period — 30 yearsRecords are erased 30 years after the patient's death, on an annual cycle.
- Let people objectPatients may stop the record being filled in, and may hide individual documents. The fact that something has been hidden is itself hidden.
What it costs if you get it wrong
- Percentage of global turnoverHealth data is sensitive data, so the higher European penalty tier applies.
- Order to stopThe Garante has repeatedly ordered changes to regional health systems.
Sources
- Official sourceGarante per la protezione dei dati personaliFascicolo Sanitario Elettronico — the Garante's topic page on FSE 2.0, the Health Data Ecosystem, access rules and retention
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliParere on the Health Ministry's Ecosistema Dati Sanitari decree, 26 September 2024
garanteprivacy.it
Cyber security rules (Telecoms)
Official name: Golden power — poteri speciali su reti 5G e servizi cloud · Decreto-legge 15 marzo 2012, n. 21, artt. 1-bis e 2; Decreto-legge 105/2019 · Act of parliament
A power the government already holds and can use at any time. You must notify contracts for fifth-generation mobile networks and related technology. The government can attach binding conditions to protect Italian data and cybersecurity. Nothing in the law says data must stay in Italy. But a condition in your contract can say exactly that, with no consultation and no warning.
Enforced by Ministry of Enterprise and Made in Italy
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyYou must notify the Prime Minister's Office of contracts for goods and services used in fifth-generation broadband networks. That covers designing, building, maintaining or running them. Name the suppliers and components.
- Keep the data in the countryThis is not automatic. The government may attach binding conditions to a contract you notify, to protect Italian know-how, cybersecurity and data. Where data is stored can be one of them. It is decided case by case and not published in advance.
What it costs if you get it wrong
- Fixed maximum fineFailure to notify, or breach of imposed conditions.
- Order to stopThe government can veto the transaction outright.
Sources
- Official sourceMinistero delle Imprese e del Made in ItalyGolden Power (5G) — notification duty and the government's power to impose prescriptions and conditions
mimit.gov.it
“prescrizioni e condizioni che le Imprese sono tenute a rispettare”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Regolamento (UE) 2022/2554 (DORA) e comunicazioni Banca d'Italia · Regulation (EU) 2022/2554; Banca d'Italia comunicazione dicembre 2024; Circolare 285, 51st update 3 February 2026 · Directly binding regulation
Italian banks, insurers, payment firms and investment firms do not have to keep data in the country. Banca d'Italia has confirmed that its old bans on outsourcing no longer apply. Since 17 January 2025 the European financial resilience rules apply instead. They make you disclose where data sits. They do not say where it must sit.
Enforced by Bank of Italy
How this country controls where data goes: No restriction
What you have to do
- Written vendor contractContracts with technology suppliers must say where data is held and used. They must give audit and access rights. They must include an exit plan.
- Register or notifyFinancial firms must promptly tell the supervisor about contracts for technology services that support essential or important functions.
- Report cyber incidentsReport serious technology incidents to Banca d'Italia through its Infostat channel. Use the European timetable, not the national cyber agency's.
What it costs if you get it wrong
- Loss of your licenceSupervisory measures against the regulated entity.
Sources
- Official sourceBanca d'ItaliaBanca d'Italia — Regolamento DORA: application from 17 January 2025 and the replacement of sectoral outsourcing prohibitions
bancaditalia.it
“Ai sensi dell'articolo 64 del Regolamento DORA, le previsioni in esso contenute si applicano a decorrere dal 17 gennaio 2025”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector
eur-lex.europa.eu
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Codice in materia di protezione dei dati personali · Decreto legislativo 30 giugno 2003, n. 196, as amended by Decreto legislativo 10 agosto 2018, n. 101 · Act of parliament
Italy's own data protection code, kept alive alongside European law. This is where the national oddities live. Children consent at 14. Dead people's data still has rights. Workplace monitoring has its own rules. And some breaches are crimes.
Enforced by Italian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: Under 14 years oldArticle 2-quinquies. Italy chose 14, not the European default of 16.
- Allow a nomineeArticle 2-terdecies. Someone else can exercise the rights over a dead person's data: people with an interest, family members, or an agent acting to protect them.
- Written vendor contract
What it costs if you get it wrong
- Criminal liabilityArticle 167: unlawful processing, including unlawful transfer of personal data outside Europe. Article 167-bis: unlawful communication or dissemination of personal data on a large scale. Prison, and it can attach to individuals.
- Percentage of global turnover: As under the General Data Protection Regulation — about $22 million
Sources
- Official sourceGarante per la protezione dei dati personaliCodice in materia di protezione dei dati personali — coordinated text published by the Garante
garanteprivacy.it
Link checked 18 August 2026
- Official sourceGarante per la protezione dei dati personaliMinori — Italy's age of consent for online services is 14
garanteprivacy.it
Link checked 18 August 2026
AI rules
Official name: Legge 23 settembre 2025, n. 132 — Disposizioni e deleghe al Governo in materia di intelligenza artificiale · Legge 132/2025, Gazzetta Ufficiale n. 223 del 25 settembre 2025 · Act of parliament
Italy's national artificial intelligence law, in force since 10 October 2025. What it leaves out matters. A clause forcing public-sector artificial intelligence systems onto servers in Italy was struck out in committee before the vote. It is still widely reported as binding Italian law. Most of the detail waits on follow-up decrees.
Enforced by National Cybersecurity Agency
How this country controls where data goes: No restriction
What you have to do
- Check your algorithmsUse must put people first and be open and traceable. A human keeps the final say. In healthcare the doctor stays responsible for the decision.
- Tell people what you doYou must disclose content generated by artificial intelligence.
What it costs if you get it wrong
- Criminal liabilityThe law adds criminal provisions, including for harmful deepfakes.
Sources
- Official sourceGazzetta Ufficiale della Repubblica ItalianaLegge 23 settembre 2025, n. 132 — official gazette entry, in force 10 October 2025
gazzettaufficiale.it
Link checked 18 August 2026
- Official sourceCamera dei DeputatiChamber of Deputies record — the server-location clause at Article 6(2) marked Soppresso
documenti.camera.it
“devono essere installati su server ubicati nel territorio nazionale”
Link checked 18 August 2026
- Official sourceDipartimento per la trasformazione digitaleGovernment announcement of final approval of the Italian artificial intelligence law — ACN and AgID designated
innovazione.gov.it
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Regolamento (UE) 2016/679 — Regolamento generale sulla protezione dei dati · Regulation (EU) 2016/679 · Directly binding regulation
Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe. It applies to companies outside Europe that target people in Italy.
Enforced by Italian Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Put a transfer safeguard in placeYou need a valid route out, plus a written assessment of the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a representativeRequired where the company has no office in Europe.
- Keep records of how you use data
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a third country.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Data Act — Regolamento (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation
This is about being able to move your data, not about where it sits. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on demands for data held in Europe from governments outside Europe.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by National Cybersecurity Agency
How this country controls where data goes: No restriction
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and charges for pulling your data out must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal steps. They must block governments outside Europe from getting non-personal data held in Europe, where that would conflict with European law.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854, official text
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That online gaming concessionaires must keep the gaming platform or player-account data on servers in Italy or the European Economic Area
We could not read the concession's technical rules. We record this as not established, rather than absent. If you work in online gaming, check before you rely on it.
The exact six-hour incident notification deadline for entities inside the National Cybersecurity Perimeter
The ministry's own page describes the duty to notify but does not state the hours. We could not fetch the text of the decree that sets them. Six hours is the figure in general circulation. Check with the ministry before you rely on it.
The exact 2026 network-security deadlines: incident reporting operative from 15 January 2026, basic measures due 31 October 2026, and the ACN determination numbers 164179/2025 and 379907/2025
So these dates rest on professional commentary rather than the agency's own text. Check with the agency before you rely on them.
The exact prison terms attached to Articles 167 and 167-bis of the Italian Personal Data Protection Code
The Garante's combined text of the Code is a PDF we could not quote article by article. We confirmed that both crimes exist and what they cover. We could not confirm the sentencing ranges.
The precise commencement date of the ACN single cloud regulation (recorded here as 1 August 2024)
The official page says the ordinary approval process starts in August 2024, without giving a day. The decision itself was adopted on 27 June 2024.
That a successor to Guido Scorza on the Garante board had still not been elected as at 18 August 2026
The authority's own board page records his term ending 19 January 2026. It says nothing about the empty seat. The claim that Parliament has not voted rests on a media source, not an official one.
The ten-year retention floor for Italian accounting and commercial records under Article 2220 of the Civil Code
This is well established, but we did not re-check it against an official source. We do not answer from memory. Check the Civil Code before you rely on the period.
Whether any mapping or geospatial restriction survives from Italy's older cartography legislation
We found no current rule, checked 18 August 2026. We could not confirm it either way against an official source. Check before you rely on it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.