Decreto Legislativo 160/2026, After-the-Fact Facial Recognition Integrated in Video Surveillance (Art. 10)
D.Lgs. 9 settembre 2026, n. 160, art. 10
In force since .
An AI risk obligations rule binding public and private bodies.
- Obligation class
- Biometric, Governance, DPIA, Retention
- Audit expectation
- on_request
- Who audits it
- Self, Regulator
As of .
What it requires
- This article binds the police forces and the Ministry of the Interior as controller, and lets the operators of places and the organisers of events install and maintain the systems at no cost to public finances (art. 10).
- Where judicial police officers start facial recognition on a person sought as a suspect, the public prosecutor must ask the judge for preliminary investigations to authorise it without delay and within forty-eight hours of the start (art. 10, comma 2).
- If the time limits are not observed or authorisation is refused, stop the use and delete the personal data, results and outputs, unless they are the body of the offence (art. 10, comma 2).
- As controller, the Ministry of the Interior must carry out the data-protection impact assessment beforehand and consult the Garante (art. 10, comma 6).
- Keep personal data in the reference database for seven days from collection, then delete it automatically (art. 10, comma 7).
- Allow access only to authorised persons, and record accesses and processing operations automatically in non-modifiable log files kept for five years (art. 10, comma 8).
- Do not base a decision with adverse legal effects on the person concerned solely on facial-recognition results, and do not use the systems in an untargeted way or for generalised or indiscriminate biometric identification (art. 10, commi 10 and 11).
- If you operate a place or organise an event with particular public-order and security needs, you may install and maintain the AI components and biometric technologies at no new or greater cost to public finances, and the systems are then lent free of charge to the questura, which has their complete and exclusive use (art. 10, comma 13).
What it makes you log
Log retention
Five years from the access and the operation, under article 10, comma 8. Separately, personal data in the reference database is kept for seven days and then deleted automatically (comma 7).
- Unit
- Years
- As of
- Basis
- Fixed
- Minimum value
- 5
Logging duty
Article 10, comma 8 requires accesses and processing operations on the integrated systems to be recorded automatically in non-modifiable log files in line with Article 12(3) of the Regulation, kept for five years. The decree does not list the contents.
- Kind
- Explicit
- As of
- Provision
- art. 10, comma 8
- Trigger
- personal_data_processing
What this law does
Article 10 lets video-surveillance systems, wherever a law permits their installation, be integrated with AI components, and the facial-recognition components may be activated only in the cases, on the conditions and in the manner set by commi 2 and 3, after the images are acquired.
To run facial recognition after the fact on a person sought as a suspect, the public prosecutor must ask the judge for preliminary investigations for authorisation without delay and within forty-eight hours of the system's start, and the judge decides by reasoned decree within the following forty-eight hours. If the time limits are not observed or authorisation is refused, use stops immediately and all personal data, results and outputs are deleted unless they are the body of the offence.
No authorisation is required where the technology is used only after the commission of an offence, solely for the initial identification of a potential suspect, on objective and verifiable elements directly connected to the offence. At places or events with particular public-order and security needs, the systems automatically process images of the faces of persons entering without processing biometric data.
After an offence has been committed, activating the facial-recognition technology processes the biometric data of the images in the local database to compare them with the biometric data extracted from images of the suspect's face. The controller of the processing is the Ministry of the Interior, Department of Public Security. The controller must carry out the data-protection impact assessment beforehand and consult the Garante.
Personal data processed through the integrated systems is kept in the reference database for seven days from collection and deleted automatically afterwards. Accesses and processing operations are performed only by authorised persons and recorded automatically in non-modifiable log files, which are kept for five years. No decision producing adverse legal effects on the person concerned may be based solely on the results of facial recognition.
The systems may in no case be used with facial recognition in an untargeted way, without any link to an offence or criminal proceeding, or for generalised or indiscriminate biometric control and identification of persons.
Operators of the places concerned, organisers or promoters of the events concerned, and persons who have the use of the venues may, in agreement with the owners of those places or structures, install and maintain the AI components and biometric technologies at no new or greater cost to public finances. Those systems are then lent free of charge to the questura, which obtains their complete and exclusive use.
When LexLint raises it
When your app profile says your app processes biometric data.