Digital Operational Resilience Act (DORA)

🇮🇹Digital Operational Resilience Act in Italy

A comprehensive guide to Digital Operational Resilience Act compliance for organisations operating in Italy. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About Digital Operational Resilience Act

The EU regulation establishing a comprehensive framework for digital operational resilience in the financial sector, covering ICT risk management, incident reporting, testing, and third-party risk.

Effective: 17 January 2025Max penalty: €5,000,000 for entities; €500,000 for individuals or 2% of total annual worldwide turnover for critical ICT third-party providers
Full Digital Operational Resilience Act overview

Digital Operational Resilience Act Enforcement in Italy

Italy's Garante is one of the oldest data protection authorities in Europe and one of the most active in terms of enforcement volume and fine amounts. The Italian Privacy Code (Legislative Decree 196/2003) was substantially amended by Legislative Decree 101/2018 to align with the GDPR, maintaining sector-specific rules on health data, marketing, and journalistic processing. The Garante has been notably active in addressing telemarketing abuse, with TIM/Telecom Italia receiving one of Europe's largest fines. Italy was the first EU country to temporarily ban ChatGPT in March 2023, citing GDPR concerns, and the Garante has continued to lead EU-wide scrutiny of AI systems. The Garante has also issued comprehensive cookie guidelines and enforced strict rules on marketing consent chains.

Data Protection Authority

Garante per la protezione dei dati personali

Key Enforcement Focus Areas in Italy

  • Telemarketing and aggressive commercial practices
  • AI and emerging technology oversight (ChatGPT ban precedent)
  • Health and medical data processing
  • Cookie consent and web tracking
  • Employee and judicial data processing

Notable Enforcement Actions in Italy

TIM/Telecom Italia

€27,800,000(2020)

Millions of unsolicited promotional calls and messages, including to users on the opt-out register

Enel Energia S.p.A.

€26,500,000(2022)

Aggressive telemarketing through unauthorised contact lists and lack of consent verification

Clearview AI

€20,000,000(2022)

Unlawful processing of biometric data through mass facial recognition scraping

OpenAI (ChatGPT)

€15,000,000(2024)

Processing personal data without adequate legal basis, transparency failures, and age verification deficiencies

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Italy