Decreto Legislativo 160/2026, Police Biometric AI: Dataset Labelling and Real-Time Remote Identification (Artt. 7-9, 13)
D.Lgs. 9 settembre 2026, n. 160, artt. 7-9 e 13
In force since .
An AI prohibited practices rule binding government bodies.
- Obligation class
- Biometric, Governance, DPIA
- Audit expectation
- on_request
- Who audits it
- Self, Regulator
As of .
What it requires
- These articles bind the Italian police forces and the judicial authority; they set the conditions on which AI may be used to process biometric data and for remote biometric identification (artt. 7-9 and 13).
- If you are a police force, label, filter or categorise lawfully acquired biometric datasets only on the four conditions in article 7, comma 1, including that the result is not the sole basis of a decision producing legal effects on natural persons.
- If you are a police force, use real-time remote biometric identification in public or publicly accessible places only for the purposes in article 8, comma 1, and only to confirm the identity of, or to search in a targeted way for, specifically named persons (art. 8, commi 1 and 2).
- Compare only against a reference database formed for each use, and do not use a biometric database fed in whole or in part by untargeted scraping, meaning the automated, indiscriminate, large-scale extraction of facial images from the internet or from closed-circuit camera footage with an AI system to create or expand facial-recognition databases, or built in breach of data-protection law (art. 8, comma 3; art. 2, comma 1, lettera l).
- Obtain the prosecutor's authorisation, granted for a specific event or the strictly necessary time and never for more than fifteen days at a time (art. 8, commi 4 and 5).
- Stop the use at once, and delete the personal data, results and outputs, if the conditions or time limits are not met or authorisation is refused (art. 8, comma 8).
- Before use, complete a fundamental-rights impact assessment under Article 27 of Regulation (EU) 2024/1689 and the data-protection impact assessment under Decreto Legislativo 51/2018 (art. 9, comma 1).
- Record each use automatically in non-modifiable log files and keep them for five years (art. 9, comma 2).
- After use, notify the Garante, with the prior clearance of the competent judicial authority (art. 9, comma 4).
- In a criminal proceeding, the public prosecutor asks the judge for preliminary investigations to authorise the use, under article 359-ter of the Codice di Procedura Penale (art. 13).
What it makes you log
Log retention
Five years from the access and the operation, under article 9, comma 2.
- Unit
- Years
- As of
- Basis
- Fixed
- Minimum value
- 5
Logging duty
Article 9, comma 2 requires each use of a real-time remote biometric identification system to be recorded automatically in non-modifiable log files that must necessarily contain the data in Article 12(3) of the Regulation, and the files are kept for five years. The contents are fixed by reference to the Regulation, not listed in the decree.
- Kind
- Explicit
- As of
- Provision
- art. 9, comma 2
- Trigger
- all_systems
What this law does
Chapter III of Title I covers AI systems used in police activity for labelling, filtering and categorising biometric data, for real-time remote biometric identification and for after-the-fact facial recognition. Article 7 permits the police forces to label, filter or categorise lawfully acquired biometric datasets on four conditions, among them that the result is not the sole basis of a decision producing legal effects on natural persons.
Article 8 permits real-time remote biometric identification in public or publicly accessible places for the preventive purposes in Article 5(1), first paragraph, point (h)(ii) of the Regulation, and to search for a missing person or for specific victims of kidnapping, human trafficking or sexual exploitation. Use is permitted only to confirm the identity of the specifically targeted persons or for a targeted search for them.
Article 8, comma 3 bans the use of biometric databases fed, in whole or in part, by untargeted scraping, or built in breach of data-protection law. Article 2 defines untargeted scraping as the automated, indiscriminate, large-scale extraction and collection, using an AI system, of facial images from the internet or from closed-circuit camera footage, in order to create or expand facial-recognition databases.
Use requires the prosecutor's authorisation, granted for a specific event or the strictly necessary time and never for more than fifteen days, extendable by reasoned decree for further periods of fifteen days. In urgent cases the request for authorisation must reach the prosecutor without delay and within twenty-four hours of the start of operations, and the prosecutor decides within the following twenty-four hours.
If the conditions and time limits are not met, or authorisation is refused, use stops immediately and the personal data, results and outputs are deleted, except elements lawfully acquired on another legal basis under Decreto Legislativo 51/2018, and results obtained in breach of the article cannot be used.
Article 9, comma 1 requires the controller to complete a fundamental-rights impact assessment under Article 27 of the Regulation, and the data-protection impact assessment under Decreto Legislativo 51/2018, before using such a system. Each use is recorded automatically in non-modifiable log files, which are kept for five years and made accessible only to the competent authorities for checking lawfulness, for internal control and in criminal proceedings.
After use, the controller notifies the Garante, with the prior clearance of the competent judicial authority, which may defer the notification for up to three months, renewable once, where secrecy requires. Article 13 inserts Article 359-ter into the Codice di Procedura Penale (Code of Criminal Procedure), on identification and localisation through AI systems for real-time remote biometric identification.
Under Article 359-ter, in a criminal proceeding the public prosecutor asks the judge for preliminary investigations to authorise the use of such a system. That authorisation names the geographic area and the persons sought, lasts no more than fifteen days, and is extendable by the judge, on the prosecutor's request, for further periods of fifteen days.
When LexLint raises it
When your app profile says your app processes biometric data.