What foreign parent companies must fix before the tracking-pixel consent deadline hits — and what the Garante's 2026 audit programme means for your Italian entity
URL: https://panatolawfirm.com/en/gdpr-italian-subsidiary-compliance-garante-2026
ABSTRACT: On 17 April 2026, Italy's data protection authority, the <i>Garante per la protezione dei dati personali</i>, issued Provision No. 284 requiring prior opt-in consent before embedding tracking pixels in commercial emails — with a hard compliance deadline of 28 October 2026. For foreign companies operating through an Italian subsidiary, this is not simply a marketing-team problem: it sits inside a broader web of Italian and EU obligations that a group-level GDPR policy almost certainly does not cover. This article sets out exactly what your Italian entity must have in place, in what order, and before which deadlines.
The email lands in a subscriber's inbox. The newsletter loads. Somewhere in the HTML, a one-pixel image calls home — recording the recipient's IP address, device, location, and the precise time they opened the message. For years, marketers treated this as routine. Italy has now decided it is surveillance, and the Garante has given companies until 28 October 2026 to treat it accordingly.
If your group runs a subsidiary in Italy — a
S.r.l., a
S.p.A., or a registered branch — that deadline applies directly to your Italian entity. Ignoring it is not a viable option. The Garante's enforcement programme for 2026 includes at least forty targeted audits, and the authority has already demonstrated, in the weeks before the pixel ruling, that it is prepared to issue fines measured in the millions: Poste Italiane and Postepay received a combined penalty of €12.5 million for embedding device-surveillance SDKs in their apps without valid consent. The pixel deadline is the next enforcement front.
What GDPR obligations apply to an Italian subsidiary of a foreign company?The short answer is: more than most parent companies realise. Regulation (EU) 2016/679 (the GDPR) applies directly across the EU, but Italy adds a further national layer on top. Legislative Decree No. 196 of 30 June 2003, as substantially amended by Legislative Decree No. 101 of 10 August 2018 (the Italian Privacy Code), supplements the GDPR in ways that have no direct equivalent in other EU member states — and no equivalent at all in UK, US, Canadian, or Australian law.
Article 122 of the Italian Privacy Code, which governs electronic communications, is the most practically significant of these additions. It requires prior opt-in consent — not merely the absence of objection, but active, informed, and freely given agreement in advance — for any tool that stores or accesses information on a user's terminal device. The Garante has long applied this to browser cookies. Garante Provision No. 284 of 17 April 2026, published in the
Gazzetta Ufficiale on 29 April 2026, extends the same logic explicitly to email tracking pixels that identify individual recipients.
Unlike in most common-law countries — including the United Kingdom, where the Privacy and Electronic Communications Regulations impose a similar opt-in rule but enforcement against email pixels has historically been limited — Italy treats non-compliant tracking as a matter of both administrative and criminal law. The Garante may impose administrative fines of up to €20 million or 4% of global annual turnover under the GDPR ceiling. But the Italian Privacy Code also preserves criminal sanctions: intentional, large-scale violations can carry custodial sentences of up to six years under Article 167-bis. That is not a theoretical risk. It is a risk that falls on the individuals running your Italian entity.
Does my Italian subsidiary need a separate DPA or privacy notice?Yes — and this is the point where most foreign groups have a gap they have yet to close.
A group-level GDPR compliance programme drafted for the parent company does not automatically protect the Italian subsidiary. The subsidiary is a separate legal entity and, almost always, a separate data controller under EU law. It must maintain its own Record of Processing Activities (ROPA), as required by Article 30 of the GDPR. That record must reflect the subsidiary's actual processing operations — Italian payroll, Italian customer data, Italian marketing lists — not simply replicate the parent's template.
Where the parent processes personal data on behalf of the subsidiary (hosting email platforms, running CRM systems, providing shared HR tools), a Data Processing Agreement under Article 28 of the GDPR must be in place between the two entities. This is frequently absent in foreign-owned groups, where the parent and subsidiary relationship is treated as one integrated operation. It is not. The Garante will look for it.
The subsidiary's privacy notices must be in Italian, must reflect Italian-law requirements (including the Art. 122 consent flows), and must be readily accessible, not buried in small print. Cookie banners on any website operated by the Italian entity must include an X-button or equivalent reject option, must present accept and reject choices with equal visual prominence, and must not reappear more frequently than every six months once a user has made a choice. These are Garante requirements that go beyond the GDPR's text.
Where the subsidiary's processing involves high-risk activities — behavioural profiling, large-scale processing of sensitive data, systematic monitoring of employees — a Data Protection Impact Assessment (DPIA) is mandatory under Article 35 of the GDPR before that processing begins or continues.
What is the Garante's inspection plan for 2026?The Garante publishes an annual inspection programme setting out its priority sectors and the number of audits it intends to conduct. The 2026 programme identifies at least forty targeted inspections, with a stated focus on electronic marketing, app-based tracking, and the data practices of foreign-owned entities with Italian operations.
This is not random. The Garante has developed a pattern of coordinated enforcement: it identifies a practice sector-wide, issues a public provision establishing the legal standard and a compliance deadline, and then audits within that sector after the deadline passes. The cookie-banner enforcement wave of 2022–2023 followed exactly this sequence. Provision No. 284 of April 2026 on email pixels follows the same pattern. Companies that have not complied by 28 October 2026 should expect to fall within the authority's field of view.
The Garante may initiate an inspection on its own motion, following a complaint, or following a referral from another EU data protection authority under the GDPR's consistency mechanism. For a foreign group, a complaint to the UK Information Commissioner's Office or the Irish Data Protection Commission about a group-wide practice can, in principle, trigger a referral that reaches the Italian subsidiary.
Do I need consent for email open-tracking in Italy?Yes, as of 28 October 2026. This is the direct effect of Garante Provision No. 284 of 17 April 2026.
A tracking pixel embedded in an email that — when loaded — transmits the recipient's IP address, device type, approximate location, and timestamp to a third-party server identifies the recipient and constitutes processing of personal data. The Garante's provision extends the Article 122 consent requirement to cover exactly this mechanism. Prior opt-in consent must be obtained before the email containing the pixel is sent, or the pixel must be suppressed entirely for contacts from whom no such consent exists.
Scienti et volenti non fit iniuria — no wrong is done to one who knows and consents. The principle is ancient, but the Garante has made it operationally precise: the consent must be specific, informed, and recorded. Assumed consent, pre-ticked boxes, and consent buried inside general terms and conditions are not valid.
Practically, this means auditing your current email marketing platform to establish which contacts in your Italian list have given pixel-tracking consent that meets the new standard. Contacts who have not must either be re-consented through a compliant opt-in flow before 28 October 2026, or removed from pixel-tracked campaigns. The email platform's data processing agreement with your Italian entity must also be reviewed: if the platform processes tracking data on your subsidiary's behalf, it must meet Article 28 requirements, and the contract must reflect current sub-processing arrangements.
The compliance checklist: what to do before 28 October 2026The sequence matters as much as the substance. Working backwards from the deadline, a foreign-owned Italian subsidiary should address these steps in order.
First, audit current email marketing practices to identify which campaigns use tracking pixels and which contacts in the Italian list have given compliant pixel-tracking consent. Second, review the legal basis and consent records for all electronic marketing to Italian contacts — both email and SMS — against the Article 122 standard.
Third, update or draft a standalone ROPA for the Italian entity, reflecting its actual processing activities, including any new pixel-consent processing activity. Fourth, review the Data Processing Agreement between the parent company and the Italian subsidiary, and with all third-party email service providers.
Fifth, check that the Italian-language privacy notice on the subsidiary's website and in its email footer accurately describes pixel-tracking processing and provides the required information under Articles 13 and 14 of the GDPR. Sixth, verify that the website's cookie banner meets the Garante's current technical requirements: X-button, equal prominence, six-month non-repetition rule.
Seventh, assess whether any high-risk processing by the subsidiary requires a DPIA that has not yet been conducted. Eighth, check whether the subsidiary has appointed a Data Protection Officer — mandatory if it processes personal data on a large scale or processes special-category data, and the assessment must be made on the subsidiary's own processing, not the group's consolidated volume.
The American legal scholar Lawrence Lessig observed that "code is law" — that the technical architecture of digital systems regulates behaviour as powerfully as any statute. The Garante's pixel provision is the moment Italy's law caught up with that architecture. Compliance is now a technical implementation task as much as a legal one.
Companies that treat this as a marketing department issue are misreading the risk. The ROPA, the DPA with the parent, the DPIA for high-risk processing — these are legal obligations sitting with the directors of the Italian entity. In Italy, those obligations carry personal exposure.
Image prompt: A glass-walled modern office in Milan or Verona, late afternoon light casting long shadows across a desk where two professionals — one clearly from a foreign context, holding a British or American passport alongside a sheaf of Italian legal documents — review a laptop screen together. The screen subtly reflects a red calendar alert. The mood is focused and urgent, not alarmed. Colour palette: warm amber natural light contrasted with cool blue screen glow, muted greys for the office interior. Photorealistic style, wide-angle lens.
Image file: gdpr-italian-subsidiary-compliance-garante-2026-cover
JSON-LD:
LANGUAGE QA: layers an additional national code on top of it -> adds a further national layer on top · as extensively amended by -> as substantially amended by · before the fact -> in advance · that sits with the individuals who run your Italian entity -> that falls on the individuals running your Italian entity · not simply adopt the parent's template wholesale -> not simply replicate the parent's template · must be accessible — not buried -> must be readily accessible, not buried in small print · The pixel deadline is the next front -> The pixel deadline is the next enforcement front · have a gap they have not yet closed -> have a gap they have yet to close
CHECK:
AUTHORITY 1: Garante Provision No. 284 of 17 April 2026 (email tracking pixels, Art. 122 extension, 28 October 2026 deadline) / EXISTS? Confirmed by the instructing brief as a verified, real provision published in the Gazzetta Ufficiale 29 April 2026 / CONTENT MATCHES what I wrote? Yes — email pixel consent, prior opt-in, October 2026 deadline.
AUTHORITY 2: Garante fine against Poste Italiane and Postepay, combined €12.5 million, device-surveillance SDKs / EXISTS? Cited in brief as recent (early 2026), but exact Garante decision number and date not independently confirmed in this drafting session beyond the brief / CONTENT MATCHES? Partial — figure and parties match brief; primary source document number TO VERIFY.
AUTHORITY 3: Garante 2026 Annual Inspection Plan (at least 40 targeted audits, focus on electronic marketing and foreign-owned entities) / EXISTS? Garante publishes annual inspection plans as standard practice; 2026 figure cited by brief / CONTENT MATCHES? Partial — general existence of annual plan is well established; specific 40-audit figure and sector focus TO VERIFY against the published 2026 document.
AUTHORITY 4: Legislative Decree No. 196/2003 as amended by D.Lgs. 101/2018, Article 122 / EXISTS? Yes, verifiable on Normattiva / CONTENT MATCHES? Yes — Art. 122 governs electronic communications, consent for terminal-device access.
AUTHORITY 5: Regulation (EU) 2016/679, Articles 13, 14, 28, 30, 35 / EXISTS? Yes, EUR-Lex / CONTENT MATCHES? Yes — standard GDPR provisions as cited.
OVERALL: AMBER. The core legal basis (Provision 284, Art. 122, GDPR provisions) is confirmed. The Poste Italiane/Postepay fine and the specific 40-audit figure in the 2026 inspection plan require primary-source verification before publication. Both are credible and sourced from the verified brief; recommend cross-checking on garante.privacy.it before the article goes live.
LOCAL NOTE:
1. Search intent targeted: informational with strong transactional pull — readers encountering this article have an Italian subsidiary and are at the awareness-to-action stage; they need a checklist, not an overview.
2. Local-market framing used: the article addresses UK, US, Irish, Canadian and Australian parent-company counsel and compliance officers who assume their group-level GDPR policy covers Italian operations; the explicit contrast between UK PECR enforcement practice and Italy's Art. 122 criminal-penalty exposure is calibrated to shock recognition in common-law readers.
3. Italian terms retained untranslated: <i>S.r.l.</i> and <i>S.p.A.</i> kept in italics at first mention because they are the specific Italian entity forms a reader's Italian corporate documents will show — translating them as "limited company" would lose the legally specific identification that helps readers connect the article to their own situation. <i>Gazzetta Ufficiale</i> kept in italics after first contextual explanation because it appears in official references and readers searching for the provision will encounter the Italian name.
Do you need legal assistance or a free estimate?
Author: Editorial Team — Panato Law Firm
Editorial Team — Panato Law Firm Staff