Law / Italy

GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis)

Regulation (EU) 2016/679, Art. 82; Codice di procedura civile, Art. 840-bis (as reformed by Legge 12 aprile 2019, n. 31)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect the Garante to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Italy.
  • Expect any person in Italy who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation, potentially pursued through the general azione di classe mechanism.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Codice Privacy Article 167 (Trattamento illecito di dati, unlawful processing of data) punishes, for anyone acting to gain a profit or cause harm to the data subject and who thereby causes concrete harm: imprisonment from six months to one year and six months for processing in violation of the Article 123, 126, and 130 electronic-communications rules or a Garante order under Article 129 (Art. 167(1)); rising to imprisonment from one to three years where the unlawfully processed data are GDPR Article 9 or 10 special categories, or the violation is an unlawful transfer of personal data to a third country or international organization (Art. 167(2)-(3)). A related offense, Article 170, punishes failure to comply with a Garante order issued under GDPR Article 58(2)(f) that causes concrete harm to a data subject, with imprisonment from three months to two years, prosecutable only on the injured person's own complaint. The Codice Privacy's Titolo III, Capo II also criminalizes unlawful communication or dissemination of large scale processed data (Art. 167-bis), fraudulent acquisition of large scale processed data (Art. 167-ter), false statements to the Garante (Art. 168), and processing violations in an employment context (Art. 171); Art. 169's separate security measures offense was abrogated outright by the 2018 GDPR-alignment reform.

Penalty structure

Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for the provisions listed in (a) to (e), including non-compliance with a supervisory-authority order under Article 58. The lower Article 83(4) tier, up to EUR 10,000,000 or 2 percent, applies instead to the Article 25 to 39 controller and processor obligations, including the Article 33 and 34 breach notification duties, recorded on the instrument covering those articles. Italy applies both GDPR tiers through the Garante's own Codice Privacy Article 166 procedure, confirmed against the article's own text: Article 166 maps specific Codice Privacy provisions to each GDPR Article 83 paragraph, directs that the Legge 24 novembre 1981, n. 689 administrative-sanctions procedure applies so far as compatible, and lets the Garante add an accessory sanction publishing the sanctioning order, in full or extract, on its own website.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Garante per la protezione dei dati personali (Italian Data Protection Authority), Italy's GDPR Article 51 supervisory authority, established under Codice Privacy Title II, Capo I (Artt. 153-154).

Enforcement record

CMS GDPR Enforcement Tracker Report, 7th edition (cut-off 1 March 2026, published 21 May 2026), Italy country page: 2024, the latest year the page reports (2025 reads 'no public information so far'), records 835 decisions, EUR 24,000,000 in collected fines, and 130 inspections. actions_per_year (835) and fines_per_year (EUR 24,000,000) are that 2024 figure; trend is recorded as rising against the page's own prior-year figures, which show 263 decisions and EUR 7,977,343 in 2023, after 231 decisions and EUR 9,459,457 in 2022. The report's years back to 2019 (232 decisions, EUR 3,017,363) show no steady trend before the 2024 jump, so total_fines and median_fine are not recorded here rather than summed across an uneven series with a still-unreported 2025. The page does not state whether every counted decision resulted in a fine, and it does not separately track private civil claims under GDPR Article 82 or the azione di classe mechanism.

As of
2 September 2026
Trend
Rising
Currency
EUR
Source link
https://cms.law/en/int/publication/gdpr-enforcement-tracker-report/italy
Fines per year
24,000,000
Actions per year
835

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Garante is Italy's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines under the Codice Privacy Article 166 procedure.

GDPR Article 82 arms an individual with a direct private right of action, and Italy additionally has a general class-action mechanism, Codice di procedura civile Article 840-bis (azione di classe), in force since 19 May 2021, confirmed against the article's own text: it covers homogeneous individual rights against enterprises or public-service managers, brought by an individual class member or a registered nonprofit organization.

The article does not name data protection specifically, and whether it has actually been used for a GDPR claim is not established.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

GDPR Art. 82
Codice di procedura civile Art. 840-bis

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app