Data Protection & IT Lawyers in Italy

GDPR compliance, data protection, cybersecurity, IT contracts and technology law.

More coming firms being added · All firms offer English service · Free to be listed · Use the wizard →

Filter by specialisation

0 firms shown

🔍

No Data Protection & IT specialists listed yet for Italy

We're actively expanding our directory. In the meantime, use the lawyer wizard — it'll match you to the best available firm for your situation.

Use the Lawyer Wizard → Suggest a Firm

Studio Legale Botta

English likely
Milan English; Italian; French; German
View Google Reviews →

International law firm with strong corporate and commercial practice, serving expats and international clients in Milan and Northern Italy

TaxCorporate MaReal EstateEmployment

Gattai Minoli Agostini & Partners

English likely
Milan English; Italian; French; German; Spanish
View Google Reviews →

Full-service international law firm with extensive English-speaking team, listed in Chambers and Legal500

Corporate MaReal EstateBanking FinanceIntellectual Property

DLA Piper

English likely
Milan English; Italian; French; German; Spanish
★★★★☆ 4.1 (44 reviews)

Global law firm with Milan office, comprehensive legal services for international clients

Corporate MaBanking FinanceImmigrationIntellectual Property

Norton Rose Fulbright

English likely
Milan English; Italian; French; German
★★★★☆ 4.0 (15 reviews)

International firm with Milan office serving corporate and financial clients

Corporate MaBanking Finance

Clifford Chance

English likely
Milan English; Italian; French; German
★★★★½ 4.3 (27 reviews)

Major international law firm with Milan office

TaxCorporate MaBanking Finance

Slaughter and May

English likely
Milan English; Italian; French; German
View Google Reviews →

International law firm with Milan office

Corporate MaBanking Finance

Frequently Asked Questions — Data Protection & IT in Italy

GDPR applies to any organisation that processes personal data of EU residents, regardless of where the organisation is based. A data protection lawyer can advise on compliance.

Fines can reach €20 million or 4% of global annual turnover (whichever is higher). A data protection lawyer can help implement compliant processes to minimise risk.

Need an English-Speaking Lawyer in Italy?

Browse our verified directory of law firms across Italy's major cities. All listed firms offer English-language legal services to expats and foreign nationals.

Find My Lawyer in 60 Seconds

Italian Data Protection Law: GDPR + Codice Privacy Guide

Italy applies the GDPR alongside D.Lgs. 196/2003 (Codice della Privacy) as amended by D.Lgs. 101/2018. The national supervisory authority is the Garante per la protezione dei dati personali.

Garante Enforcement Actions — Notable Fines

CompanyFineIssueYear
Meta (Facebook)€390 million (EU multi-authority)Unlawful legal basis for behavioural advertising; GDPR art. 62023
OpenAI (ChatGPT)€15 millionUnlawful processing of personal data; no age verification; Italian ban then lifted2024
TIM (Telecom Italia)€27.8 millionUnlawful telemarketing; failure to honour opt-outs; D.Lgs. 196/2003 art. 1302021
Enel Energia€26.5 millionUnauthorised telemarketing calls; Registro Pubblico Opposizioni (RPO)2021
Clearview AI€20 millionUnlawful biometric data collection; facial recognition database2022
Regione Lazio€120,000Ransomware breach — inadequate security measures; GDPR art. 322022

Italy-Specific Rules (D.Lgs. 196/2003 as amended)

TopicItalian RuleLegal Basis
Children's consentAge 14 (Italy chose minimum under GDPR art. 8(1); GDPR allows 13–16)D.Lgs. 196/2003 art. 2-quinquies
Employee monitoringControls sugli strumenti di lavoro permissible; internet/email monitoring requires trade union agreement or ITL authorisationL. 300/1970 art. 4 (as amended by DL 151/2015)
Video surveillance at workRequires trade union agreement or Ispettorato del Lavoro authorisation; must inform workers; Garante guidelines applyL. 300/1970 art. 4; Garante Guidelines 2010
Telemarketing — RPORegistro Pubblico Opposizioni (DPR 178/2010 + DL 139/2021) covers mobile/email; opt-out must be honoured within 15 daysDPR 178/2010; DL 139/2021 (extended RPO)
Health dataSensitive data (dati sulla salute) requires explicit consent + specific processing conditions; doctors/healthcare exempt from some requirementsD.Lgs. 196/2003 artt. 2-sexies, 2-septies
Fiscal code (codice fiscale)Codice fiscale is personal data; cannot be used to cross-reference databases without legal basisD.Lgs. 196/2003; Garante Guidance 2008

DPO (Data Protection Officer) Requirements in Italy

The DPO is mandatory under GDPR art. 37 for: (1) public authorities; (2) controllers/processors whose core activities involve large-scale systematic monitoring of individuals; (3) large-scale processing of special category data. Italy has no national employee threshold for DPO appointment (unlike Germany's BDSG § 38 which requires 20+ employees). However, the Garante recommends voluntary DPO appointment for SMEs processing significant volumes of personal data.

⚠️ Key Italy-specific compliance points:
1. RPO registration: Always check the Registro Pubblico Opposizioni before any telemarketing call or email campaign. Failure to check = automatic violation regardless of consent history.
2. Workplace monitoring: Even BYOD policies or IT security monitoring of company systems requires prior union agreement or ITL authorisation under L. 300/1970 art. 4 — this is stricter than GDPR's legitimate interest basis alone.
3. Italian DPA orders: The Garante can issue emergency provisional orders (provvedimenti d'urgenza) within 48 hours for urgent breaches — faster than most EU DPAs.

Sources: GDPR (EU 2016/679); D.Lgs. 196/2003 (Codice della Privacy) as amended by D.Lgs. 101/2018; L. 300/1970 art. 4 (Statuto dei Lavoratori); DPR 178/2010 + DL 139/2021 (RPO).