Law / Italy

Codice Privacy (Personal Data Protection Code), Article 122, Consent for Storing or Accessing Information on a Terminal Device

Decreto legislativo 30 giugno 2003, n. 196, art. 122

In force since .

A device storage and tracking consent rule binding public and private bodies.

Obligation class
Consent, Disclosure

As of .

What it requires

  • Before you store information on a subscriber's or user's terminal device, or access information already stored there, obtain their consent after informing them through the simplified procedures that the Garante sets.
  • You need no consent for technical storage or access whose sole purpose is to carry out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for you to supply an information society service that the subscriber or user explicitly requested.
  • You may collect consent through specific software or device configurations that are easy and clear for the subscriber or user to use.
  • Do not use an electronic communications network to access information stored in a subscriber's or user's terminal equipment, to store information or to monitor the user's operations, except as the consent rule permits.

If you get it wrong

Penalty structure

Article 166(2) places violations of Article 122 under the administrative sanction of Article 83(5) of the GDPR, which sets fines of up to EUR 20,000,000 or, for an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.

Rule
Higher of
As of
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

The Garante per la protezione dei dati personali, which Article 166(3) makes competent to adopt corrective measures and to impose the sanctions of Article 83 of the GDPR.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 122(1) permits storing information in the terminal equipment of a subscriber (contraente) or user (utente), or accessing information already stored there, only on condition that the subscriber or user has given consent after being informed through simplified procedures.

That rule does not prevent technical storage or access whose sole purpose is to carry out the transmission of a communication over an electronic communications network, or that is strictly necessary for the provider of an information society service explicitly requested by the subscriber or user to supply that service.

In fixing the simplified procedures the Garante per la protezione dei dati personali (the Italian data protection authority) also takes account of proposals from the most representative national consumer and trade associations. Article 122(2) allows consent to be expressed through specific configurations of software or devices that are easy and clear for the subscriber or user to use.

Article 122(2-bis) prohibits, subject to paragraph 1, the use of an electronic communications network to access information stored in the terminal equipment of a subscriber or user, to store information or to monitor the user's operations.

Article 121(1-bis)(f) defines a subscriber as any natural person, legal person, body or association party to a contract with a provider of publicly available electronic communications services for their supply, or otherwise the recipient of such services through prepaid cards. Article 121(1-bis)(g) defines a user as any natural person who uses a publicly available electronic communications service, for private or business reasons, without necessarily being subscribed to it.

Article 166(2) places violations of Article 122 under the administrative sanction of Article 83(5) of the General Data Protection Regulation (GDPR). Article 166(3) makes the Garante the authority competent to adopt corrective measures and to impose the sanctions of Article 83 of the GDPR. Article 83(5) of the GDPR sets fines of up to EUR 20,000,000 or, for an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.

When LexLint raises it

When your app profile says your app tracks devices.

Back to the example  ·  Lint your app