Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Italy Codice Cross-Border + Retention

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) ItalyCodice-CrossBorder-Transfer-Adequacy-SCCs-BCRs-Retention-ItalianSectorRules-EUDataAct: Italy Codice Cross-Border Transfer + EU Adequacy + Standard Contractual Clauses + Binding Corporate Rules + EU Data Act + Italian Sector Retention Rules + Schrems II + Transfer Impact Assessment

Cross-border transfer of personal data from Italy is governed by GDPR Chapter V + Italian Codice + Italian Garante guidance. (1) GDPR Chapter V Transfer Mechanisms: (a) Adequacy decisions per Commission - Andorra + Argentina + Canada (commercial organisations) + Faroe Islands + Guernsey + Israel + Isle of Man + Japan + Jersey + New Zealand + Republic of Korea + Switzerland + Uruguay + UK + US (Privacy Shield 1.0 Schrems II invalidated 2020 + Privacy Shield 2.0 Data Privacy Framework 2023 valid); (b) Standard Contractual Clauses (SCCs) - 2021 SCCs replace 2010 SCCs + 4 modules + new SCCs require Transfer Impact Assessment per Schrems II; (c) Binding Corporate Rules (BCRs) - Italian Garante BCR approval + EDPB coordination + intragroup transfer mechanism; (d) Code of Conduct + Certification + ad-hoc clauses; (e) derogations per Article 49 - explicit consent + contract necessity + public interest + vital interests + legal claims. (2) Schrems II Post-2020 Requirements: per CJEU C-311/18 Schrems II decision invalidating EU-US Privacy Shield + transfer impact assessment (TIA) required for SCCs to non-adequate countries + assess (a) the law and practices of the recipient country; (b) whether protections are essentially equivalent to EU/EEA; (c) supplementary measures including encryption + pseudonymisation + organisational + contractual; (d) ongoing monitoring of recipient country legal developments. (3) EU-US Data Privacy Framework (DPF) 2023: replacement of Privacy Shield + EU adequacy decision 10 July 2023 + US DPF + UK DPF Extension + Swiss DPF + ongoing monitoring + Schrems III legal challenge pending. (4) Italian-Specific Cross-Border Considerations: (a) Italian Garante review of transfer mechanisms; (b) Italian Constitutional Court jurisprudence on cross-border surveillance + access; (c) Italian-specific sector restrictions (e.g. Italian healthcare data + Italian financial data with Italian Banking Code restrictions + Italian national security + classified information); (d) Italian Government access requests + judicial cooperation. (5) EU Data Act (Regulation EU 2023/2854) effective 12 September 2025: Italian implementation + access to non-personal data + data sharing between businesses + government + non-personal industrial data + IoT data + cloud computing data portability. (6) Retention per Italian Sector Rules: Italian-specific retention periods supplementing GDPR Article 5(1)(e) + including (a) Italian Civil Code 10-year general statute of limitations for contracts; (b) Italian Tax Code 10-year retention for tax records; (c) Italian Labour Code retention for HR records; (d) Italian Bank Code retention for banking records; (e) Italian Health Code retention for medical records (typically lifetime + after death); (f) Italian Anti-Money Laundering retention (5+ years); (g) Italian Code of Civil Procedure retention for litigation records; (h) Italian sectoral retention schedules. (7) Italian Government Access: Italian Public Prosecutor + Judge access procedures + judicial oversight + Italian Anti-Mafia + Anti-Terrorism legislation + cross-border MLAT requests. Coordinates with GDPR Chapter V + 2021 SCCs + EDPB Schrems II Recommendations + EU-US Data Privacy Framework + UK Bridge + Swiss-US Framework + Italian Garante guidance + Italian Constitutional Court + Italian Court of Cassation + Italian Civil + Tax + Labour + Bank + Health Codes + EU Data Act + EU NIS2 + DORA + EU AI Act. Italy Codice Cross-Border + Retention applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.