Law / Italy

Italy

European Union law applies in Italy Italy is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Italy, described on this page below, applies here too.

23 of 25 named instruments researched to a stage, across all six areas of law we track: 22 in force and 1 repealed, withdrawn or blocked. As of 12 September 2026.

When they take effect22 of 23 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 7 instruments (7 in force) 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 4 instruments (4 in force) 2025: 4 instruments (4 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 7
  3. Scraping law 5
  4. Cybersecurity law 2
  5. Age gating law 3
  6. News aggregation law 3

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (467 words)

Italy enacted Legge 23 settembre 2025, n. 132 ("Disposizioni e deleghe al Governo in materia di intelligenza artificiale"), the first EU member state's dedicated national AI statute, in force from 10 October 2025. Article 1 states that the law is interpreted and applied consistently with the EU AI Act, Regulation (EU) 2024/1689, which is covered separately for the eu jurisdiction and not restated here; what follows covers what Italy's own law adds.

Article 4 sets an AI-specific personal-data consent rule for minors: a child under fourteen needs the consent of whoever holds parental responsibility to access AI technologies and for the resulting processing of their personal data, while a minor between fourteen and eighteen may consent alone provided the required information is easily accessible and understandable.

Article 11 requires that AI use in employment be safe, reliable, transparent, non-discriminatory and respectful of workers' dignity and personal data, and requires an employer or client to inform workers of AI's use as already required by Article 1-bis of Decreto Legislativo 152/1997's automated-decision-and-monitoring-system disclosure duty.

Article 13 limits AI use within a regulated intellectual profession to instrumental and support tasks, keeping the professional's own intellectual work predominant, and requires the professional to clearly disclose to the client which AI systems were used.

Article 20 designates Italy's Agenzia per l'Italia digitale (AgID) and Agenzia per la cybersicurezza nazionale (ACN) as Italy's national AI authorities, alongside the Bank of Italy, CONSOB and IVASS retaining their existing sector market-surveillance roles under AI Act Article 74(6): AgID handles innovation promotion and the notification, assessment, accreditation and monitoring of AI conformity-assessment bodies, while ACN supervises AI systems for cybersecurity compliance, including inspection and sanctioning powers.

Article 26 inserts a new Codice Penale offence, Article 612-quater, punishing with imprisonment from one to five years whoever causes unjust harm to a person by non-consensually disseminating an AI-generated or AI-altered image, video or voice recording capable of misleading as to its genuineness; the offence is prosecutable only on the victim's complaint except where connected to another ex-officio offence or committed against a person incapable by age or infirmity, or against a public authority because of its functions.

The same Article 26 also adds an AI-use aggravating circumstance applicable to any crime (Codice Penale art. 61, no. 11-undecies), and AI-specific aggravated penalty tiers to the offences of attacks on constitutional bodies (art. 294), market manipulation under the Codice Civile (art. 2637), and market abuse under the consolidated financial-intermediation act (art. 185); these are noted here rather than recorded as separate instruments.

Two implementing legislative decrees delegated under the law's Articles 16 and 24 were reported in secondary sources to remain under parliamentary committee review as of mid-2026 against an October 2026 delegated deadline; they are not recorded as instruments because their content is not confirmed against a primary source.

AI governance

Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN)

Legge 23 settembre 2025, n. 132, art. 20official consolidated text of Legge 132/2025, Normattiva

In force 11 months, effective 10 October 2025. Binds public and private bodies.

What this law does

Article 20 designates the Agenzia per l'Italia digitale (AgID) and the Agenzia per la cybersicurezza nazionale (ACN) as Italy's national AI authorities, without displacing the Bank of Italy's, CONSOB's and IVASS's existing sector market-surveillance roles under EU AI Act Article 74(6) (comma 1).

AgID is responsible for promoting AI innovation and development and for defining the procedures and exercising the functions for notifying, assessing, accrediting and monitoring the bodies charged with verifying AI systems' conformity (comma 1, lettera a); ACN is responsible for supervising AI systems, including inspection and sanctioning activities, for cybersecurity compliance, and for promoting AI development on cybersecurity aspects (comma 1, lettera b); the two agencies jointly establish and manage AI regulatory-sandbox spaces, consulting the Ministry of Defence on dual-use AI and the Ministry of Justice on AI used in judicial activity (comma 1, lettera c).

What it requires

AI prohibited practices

Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered Content

Codice Penale, art. 612-quater, inserted by Legge 23 settembre 2025, n. 132, art. 26, comma 1, lettera c)official consolidated text of Legge 132/2025, Normattiva

In force 11 months, effective 10 October 2025. Binds public and private bodies.

What this law does

Whoever causes unjust harm to a person by transferring, publishing, or otherwise disseminating, without that person's consent, an image, video, or voice recording falsified or altered through the use of an AI system and suited to deceive as to its genuineness, is punished with imprisonment from one to five years.

The offence is prosecutable only on the injured person's complaint, except that it is prosecuted ex officio if connected to another offence for which ex officio prosecution is required, or if committed against a person incapable by age or infirmity, or against a public authority because of its functions.

What it requires

AI sector rules

Legge 132/2025, Sector Human-Oversight and Disclosure Duties (Artt. 4, 11, 13)

Legge 23 settembre 2025, n. 132, artt. 4, 11, 13official consolidated text of Legge 132/2025, Normattiva

In force 11 months, effective 10 October 2025. Binds public and private bodies.

What this law does

Article 4 requires that use of AI systems in employment and elsewhere ensure lawful, correct and transparent personal-data processing consistent with EU data-protection law, communicated in clear and simple language (commi 2-3); a minor under fourteen needs the consent of whoever holds parental responsibility to access AI technologies and for the resulting personal-data processing, while a minor aged fourteen to eighteen may consent alone if that information is easily accessible and understandable (comma 4).

Article 11 requires that AI used in the workplace be safe, reliable, transparent, respect human dignity, and not violate personal-data confidentiality, and requires an employer or client to inform the worker of AI's use in the cases and manner already set by Article 1-bis of Decreto Legislativo 152/1997 (the automated-decision-and-monitoring-system disclosure duty); AI used to organise or manage an employment relationship must observe the worker's inviolable rights without discrimination on sex, age, ethnic origin, religion, sexual orientation, political opinion, or personal, social or economic condition (commi 1-3).

Article 13 limits the use of AI systems within a regulated intellectual profession to instrumental and support activities, so that the professional's own intellectual work remains predominant in the service provided. To preserve the trust relationship between professional and client, it requires the professional to communicate to the client, clearly, simply and completely, the AI systems used.

What it requires

Privacy law7 instruments, 7 in force

Research summary (100 words)

Italy's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Codice in materia di protezione dei dati personali (Personal Data Protection Code, "Codice Privacy"), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses, the Garante's Article 166 sanctioning procedure, and sector-specific prescriptions for genetic, health, and biometric data.

The Garante is one of the EU's most active biometrics regulators, evidenced by its EUR 20 million Clearview AI fine, and one of the most active generative-AI regulators, evidenced by its ChatGPT suspension and ongoing OpenAI enforcement.

Biometric privacy

Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions

Garante Provvedimento n. 146 del 5 giugno 2019Garante Provvedimento n. 146/2019

In force since 5 June 2019. Binds public and private bodies.

What this law does

The Garante's Provvedimento n. 146/2019 imposes specific security measures for genetic data (documented physical-access controls, encrypted or pseudonymized storage, controlled transmission), consent requirements for genetic testing and for processing genetic data to protect a third party's health, and a research-retention rule limiting secondary use of health data to cases where equivalent research cannot be done on data from consenting subjects.

The Garante's leading biometric enforcement action is Provvedimento n. 50 del 10 febbraio 2022 against Clearview AI: a EUR 20 million fine, an EU-wide processing ban on Italy-related facial-recognition data, and an order to delete data and designate an EU representative, for scraping and processing facial images with no valid legal basis.

No dedicated Garante decision or guidance on voiceprints specifically, or on employer fingerprint or facial-recognition timekeeping, is located; these are genuine gaps, not confirmed absences, since the Garante's own thematic search pages cannot be queried.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Garante within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Italy-specific derogation from this timeline or threshold was identified in the Codice Privacy.

What it requires

Comprehensive regime

Codice Privacy (Personal Data Protection Code), as Amended for GDPR Alignment

Decreto Legislativo 30 giugno 2003, n. 196, as amended by Decreto Legislativo 10 agosto 2018, n. 101normattiva.it, D.Lgs. 196/2003 idF D.Lgs. 101/2018 (article by article)

In force since 19 September 2018. Binds public and private bodies.

What this law does

Italy gives the General Data Protection Regulation (GDPR) domestic effect through the Codice in materia di protezione dei dati personali (Personal Data Protection Code), Decreto Legislativo 196/2003 as amended by Decreto Legislativo 101/2018, in force from 19 September 2018. Beyond the GDPR baseline it adds its own Titolo III criminal offenses for unlawful processing (Artt.

167, 167-bis, 167-ter, 168, 170, 171; Art. 169 was abrogated outright by the 2018 decree), the Garante's own Article 166 sanctioning procedure, and sector-specific security and consent prescriptions for genetic, health, and biometric data.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier of up to EUR 20 million or 4% of global turnover. No Italy-specific derogation from this EU-wide framework was identified.

What it requires

Data subject rights

GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement

Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023Garante notice of violation, 29 January 2024

In force since 25 May 2018. Binds public and private bodies.

What this law does

Individuals in Italy have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. The Garante's ChatGPT/OpenAI matter is Italy's leading automated-processing enforcement episode: a provisional order suspending OpenAI's processing of Italian users' personal data on 30 March 2023, and a formal notice of violation on 29 January 2024.

A further EUR 15 million fine (December 2024) and the Court of Rome's annulment of that fine on a one-stop-shop competence ground (18 March 2026, once OpenAI's Irish establishment shifted lead-authority jurisdiction to Ireland's DPC) are not independently verified here, and rest on secondary sourcing rather than a confirmed read.

What it requires

Enforcement supervision

GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis)

Regulation (EU) 2016/679, Art. 82; Codice di procedura civile, Art. 840-bis (as reformed by Legge 12 aprile 2019, n. 31)GDPR Art. 82

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Garante is Italy's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines under the Codice Privacy Article 166 procedure.

GDPR Article 82 arms an individual with a direct private right of action, and Italy additionally has a general class-action mechanism, Codice di procedura civile Article 840-bis (azione di classe), in force since 19 May 2021, confirmed against the article's own text: it covers homogeneous individual rights against enterprises or public-service managers, brought by an individual class member or a registered nonprofit organization.

The article does not name data protection specifically, and whether it has actually been used for a GDPR claim is not established.

What it requires

Sensitive categories

GDPR Article 9 Special Categories and Codice Privacy Article 167(2)

Regulation (EU) 2016/679, Art. 9; D.Lgs. 196/2003, Art. 167(2)GDPR Art. 9(1)

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. The Codice Privacy adds no separate biometric-specific statute but does add its own Article 167(2) criminal offense specifically for unlawful Article 9-10 processing, and Provvedimento n. 146/2019's security and consent prescriptions for genetic and health data.

The Garante's Clearview AI decision confirms Italy applies no general publicly-available carve-out: processing publicly posted facial images to build a biometric identification database brought them within Article 9's special-category regime regardless of prior public availability.

What it requires

Scraping law5 instruments, 4 in force, 1 repealed, withdrawn or blocked

Research summary (541 words)

Italy has no scraping-specific statute, so general law governs each dimension separately.

Computer-misuse law reaches unauthorized access rather than open-web crawling as such: Codice Penale art. 615-ter punishes abusively accessing, or remaining within, a computer or telematic system protected by security measures, and art. 615-quater punishes possessing, producing or distributing codes, passwords, devices or instructions suited to accessing such a protected system, without authorization; both were substantially strengthened by Legge 28 giugno 2024, n. 90, in force from 17 July 2024, which also repealed the previously separate malware-distribution offence at art. 615-quinquies and folded its scope into the broadened art. 615-quater.

Because both offences turn on defeating or misusing access to a system protected by security measures, a plain reading does not reach reading a public, unauthenticated page that carries no security measure to circumvent, and no reported case on that point is cited. No Italian court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no Italian unfair-competition, misappropriation or trespass doctrine specific to scraping, is established here.

On copyright and text-and-data-mining, Legge 633/1941 (Legge sul Diritto d'Autore, "LDA") artt. 70-ter and 70-quater, inserted by Decreto Legislativo 8 novembre 2021, n. 177 transposing Digital Single Market (DSM) Directive (EU) 2019/790 artt.

3-4, and in force since 12 December 2021, permit text-and-data-mining: art. 70-ter unconditionally for research organisations and cultural-heritage institutions carrying out scientific-research text and data mining (TDM) with lawful access, and art. 70-quater generally, including for commercial use, for anyone with lawful access, unless the rightholder has expressly reserved the use.

Legge 23 settembre 2025, n. 132 (Italy's national AI law) extended this framework explicitly to AI training: its art. 25 inserted LDA art. 70-septies, confirming that reproduction and extraction from lawfully accessible works or databases for AI training, including generative AI, is permitted under the same artt.

70-ter and 70-quater conditions, and its art. 26(3) added a new criminal offence at LDA art. 171, comma 1, lettera a-ter, for reproducing or extracting text or data in violation of artt. 70-ter or 70-quater, including through an AI system; art. 171's chapeau states that penalty in lire ("multa da L. 500 a L. 20.000") in the text, and no verified euro-converted figure is available, so the fine amount is not recorded here. Italy's sui generis database right, at LDA artt.

102-bis and 102-ter (Titolo II-bis, inserted 1999, transposing the EU Database Directive 96/9/EC), gives a database's maker the right to prohibit extraction or re-utilisation of the whole or a substantial part of a database representing a substantial investment, for fifteen years from the database's completion or first making-available (renewable on a substantial new investment), while a legitimate user may extract or re-use insubstantial parts for any purpose, subject to a bar on repeated and systematic extraction of insubstantial parts that conflicts with the database's normal exploitation or unjustifiably prejudices its maker.

Personal-data reach over scraped public personal data is addressed comprehensively by Italy's landed privacy-topic research (General Data Protection Regulation (GDPR) and the Codice Privacy) and is not restated here. No statute was located assigning independent legal weight to a robots.txt directive; a machine-readable signal such as robots.txt functions, at most, as one of the "adequate means" a rightholder may use to reserve TDM use under LDA art. 70-quater, rather than carrying force of its own.

Computer misuse

Codice Penale Art. 615-quater, Illicit Possession or Distribution of Access Devices

Codice Penale, art. 615-quater, as amended by Legge 28 giugno 2024, n. 90official consolidated text of Codice Penale art. 615-quater, Brocardi.it

In force since 17 July 2024. Binds public and private bodies.

What this law does

Whoever, to procure an advantage for themselves or another or to cause harm to another, abusively obtains, holds, produces, reproduces, distributes, imports, communicates, delivers, otherwise makes available to others, or installs apparatus, instruments, parts of apparatus or instruments, codes, passwords or other means suited to accessing a computer or telematic system protected by security measures, or otherwise supplies indications or instructions suited to that purpose, is punished with imprisonment up to two years and a fine up to EUR 5,164 (comma 1).

The penalty rises to imprisonment from two to six years where one of the aggravating circumstances of art. 615-ter, comma 2, number 1) is present (comma 2), and to imprisonment from three to eight years where the conduct concerns the systems described in art. 615-ter, comma 3 (comma 3), both added when Legge 90/2024 amended commi 1-2 and inserted a new comma after comma 2, effective 17 July 2024.

What it requires

Codice Penale Art. 615-quinquies, Illicit Malware Devices (Repealed)

Codice Penale, art. 615-quinquies, repealed by Legge 28 giugno 2024, n. 90, art. 16, comma 1, lettera d)official consolidated text of Codice Penale art. 615-quinquies, Brocardi.it

Repealed: no longer in force. Binds public and private bodies.

What this law does

Before its repeal, Article 615-quinquies punished, with imprisonment up to two years and a fine up to EUR 10,329, whoever, intending to unlawfully damage a computer or telematic system or its information, data or programmes, or to cause the total or partial interruption or alteration of its operation, abusively obtained, held, produced, reproduced, imported, distributed, communicated, delivered, otherwise made available to others, or installed devices, apparatus or computer programmes suited to that purpose.

Legge 90/2024, art. 16, comma 1, lettera d), repealed the article outright, folding its subject matter into the broadened Article 615-quater rather than replacing it with a distinct offence, effective 17 July 2024.

Note and primary source

Codice Penale Art. 615-ter, Unauthorized Access to a Computer or Telematic System

Codice Penale, art. 615-ter, as amended by Legge 28 giugno 2024, n. 90official consolidated text of Codice Penale art. 615-ter, Brocardi.it

In force since 17 July 2024. Binds public and private bodies.

What this law does

Whoever abusively enters a computer or telematic system protected by security measures, or remains within it against the express or tacit will of whoever has the right to exclude them, is punished with imprisonment up to three years (comma 1); this base offence is prosecutable only on the victim's complaint.

Imprisonment rises to two to ten years where the offender is a public official or public-service employee abusing their powers or duties, or a person who also unlawfully practises as a private investigator, or an operator abusing their access to the system; where the offender uses threats or violence against people or property or is visibly armed; or where the offence causes destruction, damage, removal, inaccessibility, or interruption of the system, or destruction or damage of the data, information or programmes it holds (comma 2); these aggravated cases are prosecuted ex officio.

Where an offence under comma 1 or comma 2 reaches a system of military, public-order, public-security, health or civil-protection interest, imprisonment rises respectively to three to ten years or four to twelve years (commi 3-4). Legge 90/2024 raised the comma-2 introductory penalty range and amended comma 3, effective 17 July 2024; an earlier text of this article, reproduced in older secondary commentary, shows the comma-2 range as one to five years before that amendment.

What it requires

Copyright and text and data mining (TDM)

Legge sul Diritto d'Autore Artt. 70-ter and 70-quater, Text-and-Data-Mining Exceptions

Legge 22 aprile 1941 n. 633, artt. 70-ter, 70-quater, inserted by Decreto Legislativo 8 novembre 2021, n. 177; art. 70-septies inserted by Legge 23 settembre 2025, n. 132, art. 25official consolidated text of Legge 633/1941, Normattiva

In force since 12 December 2021. Binds public and private bodies.

What this law does

Article 70-ter permits reproductions by research organisations and cultural-heritage-protection institutions, for scientific-research purposes, for text-and-data-mining (text and data mining (TDM)) from works or other material in networks or databases to which they have lawful access, and communication to the public of the research's results where expressed in new original works (comma 1); TDM is defined as any automated technique for analysing large quantities of text, sound, images, data or metadata in digital form to generate information, including patterns, trends and correlations (comma 2).

Article 70-quater permits, without prejudice to Article 70-ter, reproductions and extractions from works or other material in networks or databases to which there is lawful access, for TDM purposes generally, including commercial use, unless the rightholders of the copyright, related rights or database right have expressly reserved the use (comma 1); copies made under either article may be kept only as long as needed for the TDM purpose, and must be secured to a level at least equal to that required under Article 70-ter.

Legge 132/2025 (Italy's national AI law), art. 25, inserted Article 70-septies, confirming that reproductions and extractions for TDM through AI models and systems, including generative AI, from lawfully accessible works or database material, are permitted under the same Articles 70-ter and 70-quater conditions, subject to the Berne Convention, effective 10 October 2025.

The same law's art. 26(3) added a new criminal offence at Article 171, comma 1, lettera a-ter, punishing reproduction or extraction of text or data from works or material in networks or databases in violation of Articles 70-ter or 70-quater, including through an AI system; Article 171's chapeau states the penalty as a fine in Italian lire ("da L. 500 a L. 20.000") in the text, and no verified euro-converted figure is available, so that amount is not recorded here.

What it requires

Database right

Legge sul Diritto d'Autore Artt. 102-bis and 102-ter, Sui Generis Database Right

Legge 22 aprile 1941, n. 633, artt. 102-bis, 102-ter, inserted by Decreto Legislativo 6 maggio 1999, n. 169official consolidated text of Legge 633/1941, Normattiva

In force since 16 June 1999. Binds public and private bodies.

What this law does

A database's maker ("costitutore"), meaning whoever makes a substantial investment, in money, time or work, to constitute, verify or present a database, holds the right, independent of any copyright protection the database may separately enjoy, to prohibit extraction or re-utilisation of the whole or a substantial part of its content (art. 102-bis, commi 1(a), 3).

"Extraction" is the permanent or temporary transfer of the whole or a substantial part of the database's content onto another medium; "re-utilisation" is any form of making that content available to the public (comma 1(b)-(c)).

The right arises when the database is completed and expires fifteen years after 1 January of the year following completion, or, for a database made available to the public before that period expires, fifteen years after 1 January of the year following first making-available; a substantial new investment in the database's content restarts an equally long protection term (commi 6-8).

Repeated and systematic extraction or re-utilisation of insubstantial parts of the database's content is not permitted where it presupposes operations contrary to the database's normal management or unjustifiably prejudices its maker (comma 9).

A legitimate user of a database made available to the public may not prejudice the rightholder, may not act contrary to the database's normal management or unjustifiably prejudice its maker, and may otherwise extract or re-use insubstantial parts, assessed qualitatively and quantitatively, of the database's content for any purpose without the maker's authorisation (art. 102-ter, commi 1-3). A contractual clause violating any of those rules is void (comma 4). Both articles have been in force since 16 June 1999.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (513 words)

Italy transposed the NIS2 Directive (Directive (EU) 2022/2555) on time and in force through Decreto Legislativo 4 settembre 2024, n. 138, in effect since 16 October 2024 (Gazzetta Ufficiale n. 230 of 1 October 2024).

It binds an essential or important entity, defined by sector annexes that include the digital providers named in the Directive (an online marketplace, an online search engine, a cloud computing service) alongside public administration, to risk-management measures (Article 24) and to a graduated incident-notification clock to CSIRT Italia within the national competent authority, the Agenzia per la Cybersicurezza Nazionale (ACN): a 24-hour pre-notification, a 72-hour notification, an intermediate report on request, and a final report within one month (Article 25).

Legge 28 giugno 2024, n. 90 (in force since 17 July 2024) sits mostly outside this topic: its own incident-notification duty (Article 1) binds only public administrations, central and local, together with publicly controlled urban and extra-urban transport companies, local health authorities and their in-house information-technology providers, none of which is a private duty-bearer this topic tracks, so that duty belongs to the Government Accountability wing rather than here.

Legge 90/2024's remaining private-facing provisions reinforce, rather than create, other designation-based regimes: Article 2 extends ACN's warning-and-remediation sanction to entities already covered by the Perimetro di Sicurezza Nazionale Cibernetica or by the former NIS1 transposition, and Article 3 aligns the Perimetro's own notification clock to the same 24-hour and 72-hour timing.

The Perimetro di Sicurezza Nazionale Cibernetica (Decreto-Legge 21 settembre 2019, n. 105, Article 1) binds a public or private operator only once a confidential Prime Ministerial decree designates it onto a non-public register; no activity in the lint's vocabulary can express a designation a developer cannot see, so it is named here rather than flagged on a guess, and Article 1(8) of the same decree lets a designated entity's Perimetro incident notification also satisfy its NIS2 Article 25 duty where the two regimes overlap.

No Italian instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; Legge 90/2024's own remaining chapter on public contracts for information-technology goods and services (Articles 4 to 15-bis) governs the state's own procurement choices for strategic purchases rather than placing a security duty on a product before it reaches any market.

Italy has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation together with the Garante's own guidance, and personal-data breach notification under GDPR Articles 33 and 34 to the Garante per la protezione dei dati personali, both of which sit in the privacy topic rather than here.

Only the digital-provider slice of the essential-and-important-entity class (an online marketplace, an online search engine, a cloud computing service and a comparable digital platform) is flagged on this jurisdiction's rows; the wider sector classes NIS2 also reaches, and the Perimetro's own designated class, are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

Sector security regimes

Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures

D.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24Decreto Legislativo text, Normattiva, D.Lgs. 4 settembre 2024, n. 138

In force since 16 October 2024. Binds public and private bodies.

What this law does

Article 24 requires an essential or important entity, defined by Article 3 against the sector annexes and including the digital providers those annexes name (an online marketplace, an online search engine, a cloud computing service), to adopt technical, operational and organisational measures adequate and proportionate to the risks its network and information systems face, on a multi-risk approach covering at least risk-analysis and security policy, incident handling (including the procedures for the Article 25 and 26 notifications), business continuity and disaster recovery, and supply-chain security, transposing NIS2 Article 21.

Article 23 places approval and oversight of these measures on the entity's own management body, whose members can be held liable for an infringement under Article 38.

What it requires

Vulnerability and incident reporting

Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification

D.Lgs. 4 settembre 2024, n. 138, Art. 25Decreto Legislativo text, Normattiva, D.Lgs. 4 settembre 2024, n. 138, Art. 25

In force since 16 October 2024. Binds public and private bodies.

What this law does

Article 25 requires an essential or important entity to notify CSIRT Italia, without unjustified delay, of any incident with a significant impact on the provision of its services, on a graduated clock: a pre-notification within 24 hours of becoming aware of the incident, a full notification within 72 hours, an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an ongoing incident, monthly progress reports and a final report within one month of its resolution).

A trust-service provider notifies within 24 hours rather than 72. CSIRT Italia in turn responds within 24 hours of the pre-notification with an initial assessment and, on request, technical guidance, transposing NIS2 Article 23.

What it requires

Age gating law3 instruments, 3 in force

Research summary (166 words)

Italy created a binding age verification duty for adult content providers through Article 13-bis of Decreto-legge 15 settembre 2023, n. 123 (the Decreto Caivano, Youth Hardship Decree), converted with amendments by Legge 13 novembre 2023, n. 159. AGCOM (Autorita per le Garanzie nelle Comunicazioni, the Italian Communications Authority) adopted the implementing technical rules in Delibera n. 96/25/CONS of 8 April 2025, which became binding for Italy based platforms on 12 November 2025.

Separately, Article 2-quinquies of the Codice in materia di protezione dei dati personali (Data Protection Code), inserted by Decreto Legislativo 101/2018, sets 14 as the minimum age at which a minor can independently consent to registering for an information society service such as a social media platform.

Italy has no enacted national app store or device level age verification mandate; a government sponsored bill to bar social media and video sharing platform access for under 15s remained in pre-parliamentary drafting, still awaiting review by AGCOM and the data protection authority, as of mid 2026.

Adult content age verification (AV)

Decreto-legge 15 settembre 2023, n. 123 (Decreto Caivano, Youth Hardship Decree), Art. 13-bis, converted by Legge 13 novembre 2023, n. 159

D.L. 123/2023, Art. 13-bis, conv. con modificazioni dalla L. 159/2023official consolidated statute text, Normattiva

In force since 14 November 2023. Binds private bodies.

What this law does

Establishes a legal duty for website operators and video sharing platform providers that distribute pornographic images or videos in Italy to verify that users are adults before granting access, delegating the technical and process details to AGCOM.

Note and primary source

Delibera AGCOM n. 96/25/CONS dell'8 aprile 2025 (technical and process rules for age verification)

AGCOM Delibera n. 96/25/CONS (8 April 2025), published in Gazzetta Ufficiale 12 May 2025official delibera text, AGCOM

In force 10 months, effective 12 November 2025. Binds private bodies.

What this law does

Adopts the binding technical and process rules that website managers and video-sharing platform providers must use to verify users are adults before granting access to pornographic content, using a dual anonymity model with independent certified third party verifiers so that neither the verifier nor the site learns both the user's identity and the service accessed.

Providers established in Italy had six months from publication, until 12 November 2025, to comply; AGCOM published a list of about 48 covered pornographic sites on 31 October 2025, and providers not established in Italy had until 1 February 2026.

Note and primary source

Social media and minors

Codice in materia di protezione dei dati personali (Data Protection Code), Art. 2-quinquies, minimum age for social media consent

D.Lgs. 196/2003 (Codice Privacy), Art. 2-quinquies, inserted by D.Lgs. 101/2018official consolidated statute text, Normattiva

In force since 19 September 2018. Binds private bodies.

What this law does

Sets 14 as the minimum age at which a minor can independently consent to processing of personal data for an information society service, including registering for a social media account. Providers must obtain parental consent for users under 14. This functions as Italy's de facto minimum social media registration age, though it is a data protection consent rule rather than a mandated identity verification requirement.

Note and primary source

News aggregation law3 instruments, 3 in force

Research summary (333 words)

Italy created a press-publisher neighbouring right transposing Article 15 of the EU Digital Single Market Copyright Directive (2019/790) through Article 43-bis of Legge 22 aprile 1941, n. 633 (Legge sul Diritto d'Autore, "LDA"), inserted by Decreto Legislativo 8 novembre 2021, n. 177 and in force since 12 December 2021.

The right exempts private or non-commercial use by individual users, hyperlinks, and the use of single words or "very short extracts", defined as any portion of the publication that does not dispense the reader from consulting the article in full.

AGCOM (Autorità per le garanzie nelle comunicazioni) sets the criteria for the "equo compenso" (fair compensation) that an online service owes a publisher and determines the amount when negotiation fails; a party that still cannot reach a contract after AGCOM's determination may bring the dispute before the specialised business-law section of the ordinary courts.

Italy has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act.

Separately from the 2021 neighbouring right, the LDA has long carried general exceptions that reach news aggregation directly: Article 65 permits free reproduction or communication to the public, in another periodical or broadcast, of current-affairs articles of an economic, political or religious character unless the publisher has expressly reserved the right, provided the source, date and author are credited; Article 70 permits summary, quotation or reproduction of parts of a work for criticism, discussion, teaching or scientific research, within the limits justified by that purpose and without competing with the work's economic exploitation, again with attribution.

No hot-news or misappropriation doctrine distinct from ordinary unfair-competition law, and no case law construing Article 43-bis's hyperlink or very-short-extract exemptions, is established here. Personal-data protection over aggregated content is addressed by Italy's landed privacy-topic research (General Data Protection Regulation (GDPR) and the Codice Privacy) and is not restated here.

The EU Digital Single Market Directive itself, including Article 15's baseline, is covered separately for the eu jurisdiction; what follows covers Italy's own transposition and its pre-existing general exceptions.

Press publishers' right

Legge sul Diritto d'Autore Art. 43-bis, Press Publisher Neighbouring Right

Legge 22 aprile 1941, n. 633, art. 43-bis, inserted by Decreto Legislativo 8 novembre 2021, n. 177, art. 3official consolidated text of Legge 633/1941, Normattiva

In force since 12 December 2021. Binds private bodies.

What this law does

Press publishers, whether acting singly, in association, or as a consortium, hold the exclusive reproduction and communication-to-the-public rights of LDA Articles 13 and 16 over the online use of their journalistic publications by information-society service providers, including media-monitoring and press-review businesses (comma 1).

A journalistic publication is a collection of mainly journalistic literary works, which may include photographs or video, forming a single item of a periodical publication under one title, published under an editor's or press agency's editorial responsibility and control; purely scientific or academic periodicals are excluded (comma 2). The right does not reach private or non-commercial use by individual users, hyperlinking, or the use of single words or very short extracts (comma 6).

A very short extract is defined as any portion of the publication that does not dispense the reader from consulting the article in full (comma 7).

An online service must pay the publisher equitable compensation ("equo compenso") for online use; AGCOM adopts the regulation setting the criteria for that compensation, weighing factors including the number of online consultations of the article, the publisher's years of activity and market relevance, the number of journalists it employs, both parties' technology and infrastructure investment costs, and both parties' economic benefits from the publication in visibility and advertising revenue (comma 8).

If the parties cannot agree an amount within thirty days of a request to negotiate, either may ask AGCOM to determine the equitable compensation; AGCOM decides within sixty days based on the same regulatory criteria (commi 9-10). If the parties still do not reach a contract after AGCOM's determination, either may bring the matter before the specialised business-law section of the ordinary courts (comma 11). Article 43-bis has been in force since 12 December 2021.

Note and primary source

Snippet reproduction

Legge sul Diritto d'Autore Art. 65, Free Reproduction of Current-Affairs Articles

Legge 22 aprile 1941, n. 633, art. 65official consolidated text of Legge 633/1941, Normattiva

In force since 29 April 2003. Binds public and private bodies.

What this law does

Current-affairs articles of an economic, political or religious character, published in magazines or newspapers, or broadcast, or made available to the public, and other material of the same character, may be freely reproduced or communicated to the public in other magazines or newspapers, including broadcast ones, if reproduction or use has not been expressly reserved, provided the source, date and author's name (if given) are indicated (comma 1).

Reproduction or communication to the public of protected works or material used on the occasion of current events is permitted for the exercise of the right to report news, within the limits of that informational purpose, again with source and author credited unless impossible (comma 2). The current text of Article 65 has been in force since 29 April 2003.

Note and primary source

Legge sul Diritto d'Autore Art. 70, Quotation and Criticism Exception

Legge 22 aprile 1941, n. 633, art. 70official consolidated text of Legge 633/1941, Normattiva

In force since 9 February 2008. Binds public and private bodies.

What this law does

The summary, quotation or reproduction of passages or parts of a work, and their communication to the public, is free if done for criticism or discussion, within the limits justified by that purpose and provided it does not compete with the work's economic exploitation; if done for teaching or scientific research, the use must also be illustrative in purpose and non-commercial (comma 1).

A summary, quotation or reproduction must always be accompanied by the title of the work, the names of the author, publisher and, for a translation, the translator, where those appear on the reproduced work (comma 3). The current text of Article 70 has been in force since 9 February 2008.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.