Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Italy Codice Special Categories

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101: Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute

Italian Codice Privacy contains extensive sector-specific provisions for special categories of personal data and specific processing contexts. (1) Article 92 Medical Records: special provisions for healthcare data processing including (a) Italian National Health Service (SSN Servizio Sanitario Nazionale) data; (b) medical records (cartella clinica) creation + maintenance + access; (c) medical confidentiality (segreto professionale + medical privilege); (d) patient consent for treatment + research + insurance; (e) electronic health records (FSE Fascicolo Sanitario Elettronico) Italian national EHR; (f) telemedicine data; (g) clinical research per Italian Medicines Agency (AIFA) + Italian Medical Devices Agency; (h) genetic data per Garante Decision No. 8/2014; (i) biometric data; (j) ASL Local Health Authority data sharing; (k) hospital + nursing home data; (l) GP family doctor data. (2) Article 96 Education Processing: special provisions for educational institutions including (a) student data (anagraphic + academic performance + disciplinary + special educational needs); (b) Italian Ministry of Education + Universities and Research (MIUR) requirements; (c) parental consent for minors; (d) teacher + staff data; (e) electronic register (registro elettronico); (f) school photography + filming + media consent; (g) Italian Adolescents Protection Law 285/1997 alignment; (h) inclusion of students with disabilities. (3) Article 99 Scientific Research Processing: special provisions for scientific research including (a) lawful basis + consent + scientific necessity + GDPR Article 9(2)(j); (b) Italian Code of Ethics for processing of personal data for scientific and statistical research purposes (Allegato A.4 to Codice); (c) ethics committee approval; (d) anonymisation + pseudonymisation requirements; (e) data sharing for research; (f) collaboration with international research consortiums; (g) human subject research ethics; (h) clinical trials + drug research + epidemiology + biobanking. (4) Article 101 Historical Research Processing: special provisions for historical archival research including (a) public interest in historical preservation; (b) Italian National Archives + Regional Archives + State Archives Code (Codice dei Beni Culturali e del Paesaggio); (c) Italian Code of Ethics for processing of personal data for historical research purposes (Allegato A.2 to Codice); (d) journalistic historical research; (e) memorialisation + public commemoration. (5) Workplace Privacy + Worker Monitoring per Italian Workers Statute Article 4: special protections for workers including (a) prohibition of audio + video surveillance of work activities (with limited exceptions for organisational + production + work safety + asset protection requirements); (b) prior union agreement or Italian Labour Inspectorate authorisation required for installation of monitoring devices; (c) information to workers + transparency; (d) Italian Workers Statute Article 5 prohibiting medical examinations except by specific physicians + per worker request; (e) Italian Workers Statute Article 8 prohibiting investigation of worker political union religious opinions; (f) Italian National Labour Inspectorate (Ispettorato Nazionale del Lavoro) enforcement; (g) trade union rights + collective bargaining + privacy. (6) Article 75 Administrative Fines: Italian-specific administrative fine framework supplementing GDPR Article 83 + with Italian procedural rules + Italian Administrative Procedure Code + judicial review at Italian Administrative Courts (TAR Tribunale Amministrativo Regionale + Consiglio di Stato Council of State). (7) Italian Codes of Ethics: 5 Italian Codes of Ethics (Codici di Deontologia) issued by Garante covering (a) journalism (Allegato A.1); (b) historical research (Allegato A.2); (c) statistics (Allegato A.3); (d) scientific research (Allegato A.4); (e) genealogical research (Allegato A.5) + binding ethical guidelines for sectoral processing. Coordinates with GDPR Article 9 + Italian Workers Statute (Legge 300/1970) + Italian Health Code + Italian Medicines Agency (AIFA) + Italian Ministry of Education + Italian National Archives + Italian Codes of Ethics + Italian Constitutional Court jurisprudence + Italian Court of Cassation Labour Section decisions. Italy Codice Special Categories applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 74 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data

FedRAMP Rev 5 · 1 control

  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)
  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

IEEE 7000 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 74 it maps to, and the evidence behind each claim, over MCP and REST.