Italy
Summary
Law: Personal Data Protection Code, Containing Provisions to Adapt the National Legislation to General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) (the Code) and General Data Protection Regulation (Regulation (EU) 2016/679)
Regulator: Italian data protection authority (Garante)
Summary: Italy implemented the GDPR by means of the Personal Data Protection Code, Containing Provisions to Adapt the National Legislation to the GDPR (the Code). The current version of the Code was enacted by means of Legislative Decree no. 101 of August 10, 2018 (only available in Italian here), which entered into force on September 19, 2018.
The Code includes some notable derogations from the GDPR, such as the age of consent, which is set at 14 years old, and in relation to the legal basis of public interest.
Supervision over the Code is conducted by the Italian data protection authority (Garante), which acts upon data subjects' complaints, provides specific data protection measures for data controllers and processors, and adopts guidelines to assist organizations' compliance with the GDPR. The Garante is a very active regulator, issuing enforcement decisions regularly, focusing on international data transfers, unsolicited telemarketing calls, and the fulfillment of data subject's rights. The Garante has also issued specific guidance in key compliance areas such as the processing of special categories of personal data in the employment context and the processing of genetic data, as well as on cookies.