Law / Italy

Decreto Legislativo 160/2026, Police Biometric AI: Dataset Labelling and Real-Time Remote Identification (Artt. 7-9, 13)

D.Lgs. 9 settembre 2026, n. 160, artt. 7-9 e 13

In force since .

An AI prohibited practices rule binding government bodies.

Obligation class
Biometric, Governance, DPIA
Audit expectation
on_request
Who audits it
Self, Regulator

As of .

What it requires

  • These articles bind the Italian police forces and the judicial authority; they set the conditions on which AI may be used to process biometric data and for remote biometric identification (artt. 7-9 and 13).
  • If you are a police force, label, filter or categorise lawfully acquired biometric datasets only on the four conditions in article 7, comma 1, including that the result is not the sole basis of a decision producing legal effects on natural persons.
  • If you are a police force, use real-time remote biometric identification in public or publicly accessible places only for the purposes in article 8, comma 1, and only to confirm the identity of, or to search in a targeted way for, specifically named persons (art. 8, commi 1 and 2).
  • Compare only against a reference database formed for each use, and do not use a biometric database fed in whole or in part by untargeted scraping, meaning the automated, indiscriminate, large-scale extraction of facial images from the internet or from closed-circuit camera footage with an AI system to create or expand facial-recognition databases, or built in breach of data-protection law (art. 8, comma 3; art. 2, comma 1, lettera l).
  • Obtain the prosecutor's authorisation, granted for a specific event or the strictly necessary time and never for more than fifteen days at a time (art. 8, commi 4 and 5).
  • Stop the use at once, and delete the personal data, results and outputs, if the conditions or time limits are not met or authorisation is refused (art. 8, comma 8).
  • Before use, complete a fundamental-rights impact assessment under Article 27 of Regulation (EU) 2024/1689 and the data-protection impact assessment under Decreto Legislativo 51/2018 (art. 9, comma 1).
  • Record each use automatically in non-modifiable log files and keep them for five years (art. 9, comma 2).
  • After use, notify the Garante, with the prior clearance of the competent judicial authority (art. 9, comma 4).
  • In a criminal proceeding, the public prosecutor asks the judge for preliminary investigations to authorise the use, under article 359-ter of the Codice di Procedura Penale (art. 13).

What it makes you log

Log retention

Five years from the access and the operation, under article 9, comma 2.

Unit
Years
As of
Basis
Fixed
Minimum value
5

Logging duty

Article 9, comma 2 requires each use of a real-time remote biometric identification system to be recorded automatically in non-modifiable log files that must necessarily contain the data in Article 12(3) of the Regulation, and the files are kept for five years. The contents are fixed by reference to the Regulation, not listed in the decree.

Kind
Explicit
As of
Provision
art. 9, comma 2
Trigger
all_systems

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Chapter III of Title I covers AI systems used in police activity for labelling, filtering and categorising biometric data, for real-time remote biometric identification and for after-the-fact facial recognition. Article 7 permits the police forces to label, filter or categorise lawfully acquired biometric datasets on four conditions, among them that the result is not the sole basis of a decision producing legal effects on natural persons.

Article 8 permits real-time remote biometric identification in public or publicly accessible places for the preventive purposes in Article 5(1), first paragraph, point (h)(ii) of the Regulation, and to search for a missing person or for specific victims of kidnapping, human trafficking or sexual exploitation. Use is permitted only to confirm the identity of the specifically targeted persons or for a targeted search for them.

Article 8, comma 3 bans the use of biometric databases fed, in whole or in part, by untargeted scraping, or built in breach of data-protection law. Article 2 defines untargeted scraping as the automated, indiscriminate, large-scale extraction and collection, using an AI system, of facial images from the internet or from closed-circuit camera footage, in order to create or expand facial-recognition databases.

Use requires the prosecutor's authorisation, granted for a specific event or the strictly necessary time and never for more than fifteen days, extendable by reasoned decree for further periods of fifteen days. In urgent cases the request for authorisation must reach the prosecutor without delay and within twenty-four hours of the start of operations, and the prosecutor decides within the following twenty-four hours.

If the conditions and time limits are not met, or authorisation is refused, use stops immediately and the personal data, results and outputs are deleted, except elements lawfully acquired on another legal basis under Decreto Legislativo 51/2018, and results obtained in breach of the article cannot be used.

Article 9, comma 1 requires the controller to complete a fundamental-rights impact assessment under Article 27 of the Regulation, and the data-protection impact assessment under Decreto Legislativo 51/2018, before using such a system. Each use is recorded automatically in non-modifiable log files, which are kept for five years and made accessible only to the competent authorities for checking lawfulness, for internal control and in criminal proceedings.

After use, the controller notifies the Garante, with the prior clearance of the competent judicial authority, which may defer the notification for up to three months, renewable once, where secrecy requires. Article 13 inserts Article 359-ter into the Codice di Procedura Penale (Code of Criminal Procedure), on identification and localisation through AI systems for real-time remote biometric identification.

Under Article 359-ter, in a criminal proceeding the public prosecutor asks the judge for preliminary investigations to authorise the use of such a system. That authorisation names the geographic area and the persons sought, lasts no more than fifteen days, and is extendable by the judge, on the prosecutor's request, for further periods of fifteen days.

When LexLint raises it

When your app profile says your app processes biometric data.

Back to the example  ·  Lint your app