Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment
Decreto Legislativo 30 giugno 2003, n. 196, as amended by Decreto Legislativo 10 agosto 2018, n. 101
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 19 September 2018.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Italy, following the Codice Privacy's institutional and procedural rules.
- Expect a Codice Privacy Titolo III criminal offense (Artt. 167, 167-bis, 167-ter, 168, 170, 171) to attach to unlawful processing, on top of GDPR's own administrative-fine exposure.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Italy gives the General Data Protection Regulation (GDPR) domestic effect through the Codice in materia di protezione dei dati personali (Personal Data Protection Code), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018, in force from 19 September 2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses for unlawful processing (Artt.
167, 167-bis, 167-ter, 168, 170, 171; Art. 169 was abrogated outright by the 2018 decree), the Garante's own Article 166 sanctioning procedure, and sector-specific security and consent prescriptions for genetic, health, and biometric data.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
normattiva.it, D.Lgs. 196/2003 idF D.Lgs. 101/2018 (article by article)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.