Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Italy Codice ePrivacy

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132: Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)

Articles 121-132 of Codice Privacy implement EU ePrivacy Directive (2002/58/EC + 2009/136/EC) and provide Italian-specific electronic communications privacy rules. (1) Article 121 Electronic Communications Services: definitions + scope + applicability + interaction with EU electronic communications regulatory framework + Italian Communications Code + AGCOM Authority for Communications Guarantees + Italian sector regulator + integration with EU Electronic Communications Code. (2) Article 122 Cookies and Similar Technologies: cookie consent + opt-in for non-essential cookies + Italian Garante Cookie Guidelines (last updated 2021 + 2024) - including (a) cookie banner requirements - immediately visible + clear + free choice between accept reject or granular control + dark pattern prohibition; (b) categorisation of cookies - strictly necessary (no consent) + functionality (consent recommended) + analytics (consent except first-party aggregate) + marketing/profiling (consent mandatory); (c) cookie wall (cookies or pay) generally prohibited by Italian Garante; (d) Google Analytics 4 Italian Garante guidance on cross-border transfer; (e) similar technologies (web beacons + fingerprinting + SDKs + local storage) treated as cookies; (f) consent withdrawal as easy as giving; (g) cookie policy + cookie list + retention periods. (3) Article 130 Unsolicited Communications (Direct Marketing): special protections for direct marketing electronic communications including (a) opt-in consent for marketing emails + SMS + push notifications + automatic call systems + fax; (b) soft opt-in for existing customers similar products/services + opt-out mechanism in each marketing communication; (c) Italian National Public Opposition Register (Registro Pubblico delle Opposizioni) - free database where individuals + businesses can register their phone numbers + postal addresses to opt-out of marketing - managed by Italian Communications Ministry + AGCOM + businesses must verify against register before marketing campaigns + penalties for non-compliance; (d) Italian Telemarketing Code of Conduct issued by Garante + AssoTel + Italian National Consumers + Mobile Network Operators. (4) Article 132 Traffic and Location Data Retention: Italian-specific data retention rules supplementing GDPR + EU ePrivacy + including (a) traffic data retention for investigative purposes per Italian Data Retention Act (Legge sul Data Retention) + retention period 6 years for serious crimes; (b) location data + cell tower data + retention for investigation of terrorism + organised crime + serious crimes; (c) Italian Court of Cassation + EU Court of Justice (CJEU) data retention jurisprudence including Tele2 Sverige + La Quadrature du Net + balancing privacy + national security; (d) Italian Public Prosecutor + Judge access procedures + judicial oversight; (e) Italian Anti-Mafia + Anti-Terrorism legislation. (5) ePrivacy Future + EU ePrivacy Regulation: replacement of 2002/58/EC by ePrivacy Regulation (in development) + Italian implementation expected. (6) Cross-Border Electronic Communications: EU cross-border electronic communications subject to GDPR + ePrivacy + Italian-specific rules where applicable. Coordinates with EU ePrivacy Directive 2002/58/EC + 2009/136/EC + EU ePrivacy Regulation (in development) + EU Electronic Communications Code + Italian Communications Code + AGCOM + Garante Cookie Guidelines + Italian Public Opposition Register + Italian Data Retention Act + CJEU Tele2 Sverige + La Quadrature du Net + Italian Court of Cassation + Italian Anti-Mafia + Anti-Terrorism + EU NIS2 + Italian ACN. Italy Codice ePrivacy applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 49 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

FDA 21 CFR Part 11 · 3 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

ISO/IEC 27011:2024 · 3 controls

  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

ISO/IEC 27400:2022 · 2 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • ASD37-27 Outbound data loss prevention (Very Good)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

  • RUSPD-4 Special Categories, Biometric Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.