Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Italy's Personal Data Protection Code (Codice in materia di protezione dei dati personali, Legislative Decree No. 196/2003) was substantially amended by Legislative Decree No. 101/2018 to align with the GDPR. The Garante per la protezione dei dati personali (Italian Data Protection Authority) oversees enforcement. The Code retains significant national provisions alongside the GDPR, including rules on health data, employment data, journalistic processing, video surveillance, and marketing. The Garante is one of the most experienced DPAs in Europe, established in 1997.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Part I, Title I — General Principles
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2-bis | Legal Basis for Processing |
| Art. 2-quater | Rules of Ethics |
| Art. 2-ter | Processing by Public Bodies |
Part I, Title II — Data Subject Rights
| Code | Title |
|---|---|
| Art. 2-duodecies | Rights Regarding Deceased Persons |
| Art. 2-terdecies | Minors' Rights |
| Art. 2-undecies | Limitations on Data Subject Rights |
Part I, Title V — Security of Data and Systems
| Code | Title |
|---|---|
| Art. 31 | Designation of Chief Privacy Officer |
| Art. 32 | Entry into Force |
| Art. 33 | Criminal Offences |
| Art. 34 | Notification of Personal Information Breach |
Part II — Specific Processing Sectors
| Code | Title |
|---|---|
| Art. 101 | Processing for Historical Research |
| Art. 75 | Administrative Fines |
| Art. 92 | Medical Records |
| Art. 96 | Processing in Education |
| Art. 99 | Processing for Scientific Research |
Part II, Title X — Electronic Communications
| Code | Title |
|---|---|
| Art. 121 | Electronic Communications Services |
| Art. 122 | Cookies and Similar Technologies |
| Art. 130 | Unsolicited Communications |
| Art. 132 | Traffic Data Retention |
Part III — Remedies, Sanctions and Garante
| Code | Title |
|---|---|
| Art. 140-bis | Garante per la Protezione dei Dati Personali |
| Art. 144 | Complaints to the Garante |
| Art. 166 | Administrative Sanctions |
| Art. 167 | Criminal Offences |
| Art. 170 | Failure to Comply with Garante Orders |
Maps to 533 other frameworks
Frequently Asked Questions
What is Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)?
Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) is a compliance framework from Italy with 6 domains and 25 controls. Italy's Personal Data Protection Code (Codice in materia di protezione dei dati personali, Legislative Decree No. 196/2003) was substantially amended by Legislative Decree No. 101/2018 to align with the GDPR. The Garante per la protezione dei dati personali (Italian Data Protection Authority) oversees enforcement. The Code retains significant national provisions alongside the GDPR, including rules on health data, employment data, journalistic processing, video surveillance, and marketing. The Garante is one of the most experienced DPAs in Europe, established in 1997. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) have?
Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) has 25 controls organised across 6 domains. The largest domains are Part II — Specific Processing Sectors (5 controls), Part III — Remedies, Sanctions and Garante (5 controls), Part I, Title I — General Principles (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) map to?
Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) maps to 533 other compliance frameworks. The top mapping partners are Chile Personal Data Protection Law (Law No. 21.719) (32% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (32% coverage), Angola Personal Data Protection Law (Law No. 22/11) (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) compliance?
Start your Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required