Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

visory Authority’s actions, particularly regarding compliance with administrative deadlines. 1.5 AI Regulation The Regulation (EU) 2024/1689, also known as the AI Act, was adopted on 13 June 2024, and represents the European Union’s first compre - hensive legal framework for artificial intelligence. It establishes harmonised rules for the develop - ment, deployment, and use of AI systems in the EU, aiming to promote safety, transparency, and compliance with fundamental rights while fostering innovation and market development. The regulation applies to providers, deployers, importers, and distributors of AI systems, clas - sifying them by risk level – minimal, limited, or high-risk – while prohibiting certain practices, such as subliminal manipulation or biometric categorisation in public spaces. Specific obli - gations are set for high-risk systems, includ - ing strict data governance and transparency requirements. The AI Act became effective on 10 August 2024, with staggered deadlines for com - pliance: prohibitions take effect after six months, governance and general-purpose AI model rules after one year, and integrated systems’ obliga - tions after three years. At the same time, the Italian legislature is work - ing on drafting an additional national legislative act which, as of today, has not yet been adopted. With regard to data protection, European AI regulations expressly emphasise the need to comply with data protection laws, which are therefore applicable in this context as well. The GDPR already establishes a series of provisions – particularly the obligations of transparency, the right not to be subject to fully automated decisions, and the obligation to conduct a Data Protection Impact Assessment (DPIA) – that are suitable for regulating and ensuring an adequate

level of protection for data subjects, including in the context of the use of AI tools. 1.6 Interplay Between AI and Data Protection Regulations Please see 1.5 AI Regulation .

2. Privacy Litigation 2.1 General Overview

In recent years, data protection litigation in Italy has experienced significant growth, driven by an increasing awareness of rights among data subjects. The most frequent disputes involve unlawful data processing, data breaches, and the improper use of personal data by companies and public administrations. Claims for compensation for privacy violations, particularly for non-material damages, are also on the rise. In this context, the Italian Supervisory Author - ity is playing a crucial role, imposing substantial fines that influence corporate strategies, seeking to stay ahead of other European authorities, and positioning itself as a leader on issues related to AI (for instance, the proceedings initiated against OpenAI and ChatGPT, which concluded with a sanction in December 2024) and employee monitoring, especially concerning the retention of metadata generated through employees’ use of email tools. 2.2 Recent Case Law Please see 1.4 Data Protection Fines in Prac- tice . 2.3 Collective Redress Mechanisms The national legislation on personal data protec - tion does not currently provide explicit regulation

226 CHAMBERS.COM

Powered by