Cookie Consent by Free Privacy Policy Generator
Panato Law Firm — Verona logo

Search

Enter a keyword to start searching

Content developed with the assistance of AI tools and reviewed by the author.

Italy GDPR Enforcement 2026: Foreign Companies' Guide - Panato Law Firm — Verona

The Poste Italiane decision, new email-pixel rules and the compliance steps every UK, US and Australian business sending to Italian consumers must take before 28 October 2026

URL: https://panatolawfirm.com/en/italy-gdpr-enforcement-2026-foreign-companies

ABSTRACT: In April 2026, Italy's data protection authority issued its most significant double enforcement action of the year: a combined €12.5 million fine against Poste Italiane and Postepay for unlawful app tracking, followed the next day by binding guidelines requiring opt-in consent for email tracking pixels, with a hard deadline of 28 October 2026. For UK, US, Australian and other foreign companies sending marketing emails to Italian consumers or processing their data, both actions carry direct legal consequences — whether or not those companies have a single office in Italy.

Your Shopify store is based in London or Toronto. You run email marketing campaigns that reach tens of thousands of Italian subscribers. Your open-rate pixel fires automatically when any recipient opens a message. You have no Italian office, no Italian staff, and you have never thought much about the Italian data protection authority. After April 2026, that position is no longer tenable.

On 17 April 2026, Italy's Garante per la Protezione dei Dati Personali (the Garante), a collegial independent authority established under Law 196/2003 as amended and empowered to enforce the General Data Protection Regulation (Regulation (EU) 2016/679), issued two decisions that have reshaped / that are reshaping for every operator reaching Italian consumers. The first, Decision No. 237/2026 (Doc-Web 10241537), imposed a combined €12.5 million fine on two of Italy's largest financial services groups. The second, Provision No. 284 of 17 April 2026, published in the Gazzetta Ufficiale n. 98 on 29 April 2026, set binding rules on email tracking pixels and a six-month deadline to comply. Neither decision carves out foreign operators / makes any exception for foreign operators.

The Poste Italiane Decision: What the Garante Actually Found

The investigation began in April 2024, following 140 reports and 12 complaints from users of the BancoPosta and Postepay mobile applications. On 17 April 2026, the Garante found that Poste Italiane and Postepay, acting as joint controllers, unlawfully processed the personal data of millions of customers via the BancoPosta and Postepay applications, in breach of Articles 5, 6, 13, 25, 28, 32, and 35 of the General Data Protection Regulation, as well as Article 122 of the Personal Data Protection Code.

The Garante established that the ThreatMetrix application had collected data relating to installed and running applications on users' Android devices without a valid legal basis and without providing sufficient transparency to data subjects. Users who tapped "authorize" were kept in the app; those who did not were locked out after three refusals. The Garante found that 303,880 users had their accounts restricted for refusing to authorise device surveillance. That is coercive consent, void under GDPR Article 7(4).

The companies argued that scanning installed applications was necessary for fraud prevention under the Payment Services Directive (PSD2, Directive (EU) 2015/2366, Article 97). That defence did not satisfy the GDPR necessity test. Additional violations included deficient user disclosures, absence of a Data Protection Impact Assessment (DPIA), inadequate security measures, improper data retention policies, and irregularities in processor designation. Data was also retained for 28 months, exceeding the companies' own declared maximum of 24 months.

The Garante fined Poste Italiane S.p.A. €6,624,000 and PostePay S.p.A. €5,877,000 for GDPR violations. The Garante also ordered both entities to cease the contested processing and to notify the authority of compliance — an operational sanction that may prove as costly as the fine.

The non-obvious lesson for foreign businesses is this: the decision establishes that a plausible security rationale — even one grounded in sector-specific EU legislation — does not override GDPR's proportionality and transparency requirements. If your app or website collects device-level signals, behavioural data, or browser fingerprints under a broad "fraud prevention" or "security" banner, that justification must still pass a documented necessity test, and users must be genuinely free to refuse without losing access to your service.

The Email-Pixel Guidelines: A Hard Deadline for Every Sender Reaching Italy

The day after the Poste Italiane announcement, the Garante published Provision No. 284 of 17 April 2026 — the first dedicated Italian regulatory framework for email tracking pixels. remove sentence — it repeats the preceding sentence verbatim. The rules were published in the Gazzetta Ufficiale n. 98 on 29 April 2026 and give organisations six months to adjust, ending 28 October 2026.

The guidelines treat the invisible tracking pixel in a marketing email as access to a recipient's terminal device — the same legal category as a cookie — and require prior consent when the pixel measures open rates or performs behavioural analysis for promotional campaigns. This is not a novel interpretation invented by the Garante alone. The European Data Protection Board confirmed this reading in its Guidelines 2/2023 on the technical scope of Article 5(3) (final version, 7 October 2024): loading a pixel is a form of "gaining access" to information stored on the recipient's terminal, the same operation the cookie rule already governs.

Both regulations apply based on where the recipient is located when the email is opened. Nationality and company headquarters do not matter. A brand based in Singapore sending to a recipient located in Rome is in scope. A French brand sending to a recipient located in New York is not. The territorial hook is the recipient's location, not the sender's registration.

There is some practical flexibility. The Garante allows tracking consent to be collected alongside marketing email consent in a single request, provided the language is neutral and non-coercive. However, the user must also be able to revoke previous choices easily and in a granular manner: either by revoking the single consent thereby ceasing all communications, or by revoking it solely with regard to tracking, while continuing to receive emails without pixels. There is also a technical escape route: anonymised aggregate statistics are the escape hatch. Measure opens in aggregate with no individual identification and you sidestep the consent requirement.

For existing subscriber lists, contacts collected before 29 April 2026 fall under the Garante's transitional regime. Tracking can continue during the six-month window, provided senders inform each contact about their tracking practices at the next meaningful interaction and make a withdrawal mechanism available. After 28 October 2026, the transitional period closes.

Does GDPR Apply to UK Companies Selling to Italian Customers?

Yes — and this is the passage that most foreign operators miss. Unlike in most common-law jurisdictions, where regulatory reach typically requires a local establishment, a registered branch, or a domestic contract, GDPR's territorial scope under Article 3(2) is determined by the targeting of individuals in the EU, not by where the controller is incorporated. A UK-registered company that sells goods or services to Italian consumers, monitors their behaviour (including through email pixels), or processes their personal data in the context of an Italian market is fully subject to GDPR — and therefore to Garante enforcement — even post-Brexit, because the UK GDPR mirrors the EU GDPR's substance, and the Garante's jurisdiction is triggered by the location of the data subject, not the data controller.

The Garante's H1-2026 inspection plan prioritises data breaches, whistleblowing platforms and AI providers. Foreign e-commerce and financial services operators have also featured in recent preliminary inquiries. The authority has used urgent processing bans against non-compliant entities as a precursor to formal proceedings.

Do I Need an EU Representative in Italy for GDPR Compliance?

Non-EU companies that target EU residents must appoint an EU representative under GDPR Article 27. This is an independent obligation, separately enforceable from any substantive data protection breach. The representative must be established in an EU Member State and must be formally designated in the controller's privacy notice. The Garante has, in documented cases, used the absence of a GDPR Article 27 representative as grounds for urgent corrective measures, including temporary processing bans. The representative does not need to be Italian — any EU-established entity will do — but the appointment must be made in writing and published.

UK companies lost the ability to use a UK-based representative to cover their EU exposure after Brexit. A UK entity serving Italian (or other EU) consumers now needs both a UK representative under UK GDPR (if it also processes UK residents' data) and a separate EU representative under EU GDPR. Many businesses operating on both sides of the Channel have failed to maintain the EU-side appointment since 2021.

What Are the Garante's Enforcement Priorities in 2026?

The OpenAI case is the instructive counterpoint. On 18 March 2026, the Court of Rome ruled in OpenAI's favour, annulling a €15 million fine and an order requiring OpenAI to conduct a media campaign about AI model training that had been imposed by the Garante. However, the ruling is narrower than it appears. The Court of Rome annulled that fine on 18 March 2026, holding that OpenAI's February 2024 Irish establishment had made the Irish Data Protection Commission the lead authority under the one-stop-shop, without ruling on the substance of the alleged infringements. In plain terms: OpenAI did not receive a finding that its conduct was lawful. The court simply held that the Garante had been the wrong regulator to adjudicate matters arising after OpenAI established itself in Ireland. The judgment leaves the substantive questions entirely open. The Garante has not obtained a ruling on whether OpenAI's training practices violated European privacy law. OpenAI has not obtained a ruling that they did not.

The lesson for foreign companies without EU establishments is the opposite of reassurance: the one-stop-shop mechanism that helped OpenAI is only available to companies with an EU establishment. A US, UK, Australian or Canadian company with no EU office cannot use it. The Garante can act as lead authority, impose fines, and order processing bans directly.

The Garante can impose the full range of GDPR corrective measures, including orders to cease processing, temporary or permanent bans on tracking-pixel use, and administrative fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher. Italy also layers criminal liability onto serious violations under the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018) — an exposure that most common-law practitioners do not flag and most foreign clients do not anticipate.

Can Italy's Data Authority Block a Foreign Company from Processing Italian Data?

Yes. The Garante has issued emergency processing bans in the past — the 2023 ChatGPT suspension being the most prominent example — and its powers under GDPR Article 58(2) allow it to impose temporary or permanent bans without awaiting the conclusion of a full investigation. For companies with no EU establishment, there is no one-stop-shop filter and no lead-authority buffer. The Garante acts directly.

The practical compliance sequence for any foreign company serving Italian consumers is as follows. First, audit whether you are in scope: do you sell to Italian consumers or monitor their online behaviour? If yes, EU GDPR applies to you. Second, appoint an EU representative under Article 27 if you have no EU establishment — and document that appointment in your privacy notice. Third, audit every tracking pixel in every email sent to Italian addresses and either obtain properly structured opt-in consent or switch to anonymised aggregate open-tracking before 28 October 2026. Fourth, review any device-level data collection, SDK integrations, or fraud-prevention tools that scan users' devices and ensure the legal basis is both documented and genuinely proportionate. Fifth, conduct or update your DPIA for any high-risk processing. Finally, review data retention periods against your own stated policies: the Garante fined Poste Italiane in part because actual retention exceeded declared retention.

Nemo auditur propriam turpitudinem allegans — no one may rely on their own wrongdoing as a defence. In the Garante's hands, that maxim translates to this: a controller cannot escape liability by arguing that it was unaware of the rules it was breaking, or that its own privacy notice failed to disclose the full extent of its processing. Ignorance of Italian data protection law is not a mitigating factor; it is, in the Garante's enforcement practice, an aggravating one.

As the jurist Lawrence Lessig observed, in networked environments code is law — and the corollary is that every technical default setting (pixel-on, data-retained, consent-bundled) is a regulatory choice. The Garante's April 2026 decisions make that point with precision: the defaults that most email marketing platforms ship with, and that most e-commerce operators leave unchanged, are now non-compliant in Italy.

Panato Law Firm, led by Avv. Marco Panato in Verona, Italy, advises international clients on Italian data protection compliance, including Garante enforcement matters, GDPR Article 27 representative obligations and cross-border data processing arrangements. If your business reaches Italian consumers and you are uncertain whether your current practices are compliant, write to info@panatolawfirm.com or call +39 045 5867034.

Image prompt: A close-up of a laptop screen displaying an Italian-language email unsubscribe flow, with a visible consent toggle for "tracking" clearly separate from the newsletter opt-in toggle; the setting is a minimalist home office with warm amber lamplight, reflecting a foreign professional navigating an unfamiliar regulatory system; colour palette of deep navy, warm amber, and cool white with Italian-language text visible on the screen.

Image file: italy-gdpr-enforcement-2026-foreign-companies-cover

JSON-LD:

LANGUAGE QA: the position is no longer tenable -> that is no longer sustainable / you can no longer afford to ignore this · issued two decisions that reshaped the compliance landscape -> issued two decisions that have reshaped / that are reshaping · Neither decision contains a carve-out for foreign operators -> Neither decision carves out foreign operators / makes any exception for foreign operators · acting as joint controllers, had unlawfully processed personal data of millions of customers -> acting as joint controllers, unlawfully processed the personal data of millions of customers · Users who tapped 'authorize' were kept in the app; those who did not were locked out after three refusals -> Users who tapped 'Authorise' stayed in the app; those who refused were locked out after three attempts · The PSD2 fraud-prevention defence failed the GDPR necessity test -> That defence did not satisfy the GDPR necessity test · an operational consequence as damaging as the fine itself -> an operational sanction that may prove as costly as the fine · The Garante adopted Provision No. 284, the first dedicated guidelines on the use of email tracking pixels -> remove sentence — it repeats the preceding sentence verbatim

CHECK:
REFERENCE: Regulation (EU) 2016/679
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Articles 5
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 122
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 7
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 97
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 3
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 27
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

REFERENCE: Article 58
1. EXISTS? not verified by the agent
2. CONTENT MATCHES? not verified
3. CONFIRMING SOURCE: —

OVERALL: RED — section rebuilt automatically, verify every reference at the official source before publication.

Do you need legal assistance or a free estimate?

Author: Editorial Team — Panato Law Firm


Editorial Team — Panato Law Firm -

Editorial Team — Panato Law Firm Staff