All news
Italian DPA May 19, 2026 9 min

Italian DPA cracks down on WhatsApp and Telegram in public administration: ban on operational communications with citizens from July 1, 2026

Provision of May 19, 2026: PAs cannot use commercial messaging apps to deliver information to data subjects or request documents. Operational guidelines for DPOs

Deadline July 1, 2026

From July 1, 2026, Italian PAs cannot use WhatsApp, Telegram, Messenger and other commercial messaging apps to communicate with citizens or request documents. Sanctions up to 100,000 EUR + compliance obligation. The PA's DPO must verify by June 30 that an alternative channel exists for every type of communication currently routed via WhatsApp.

Context: widespread WhatsApp abuse in Italian public bodies

Over the past 5 years, WhatsApp use by Italian PAs exploded, especially at municipal level. Many bodies use it to: communicate tax deadlines, request documents for proceedings, send convocations, manage social services bookings, communicate with parents for school services. The DPA conducted a sample audit on 300 municipalities in 2025 finding that 67% use WhatsApp for institutional communications, and 41% request personal documents via chat.

67%of 300 audited
Municipalities using WhatsApp
41%
Municipalities requesting documents via WhatsApp
100KEUR
Maximum fine per body

Reasons for the ban: 5 structural GDPR problems

  • Missing legal basis: WhatsApp is not an institutional channel; Article 6 GDPR for PAs requires a basis in law or public interest, and no Italian law authorizes commercial messaging
  • Extra-EU transfer: Meta Platforms Ireland Ltd. transfers data also to the US (Meta Platforms Inc.) and to global servers - Schrems II and the EU-US Adequacy Decision 2023 have specific requirements that WhatsApp End-to-End does not guarantee for metadata
  • Profiling: Meta uses WhatsApp metadata (who messages whom, when, frequency) for advertising profiling - for PAs this is incompatible with Art. 5(1)(b) GDPR purpose limitation
  • Retention: WhatsApp retains messages on Meta servers indefinitely; PAs have specific documentary retention obligations (Italian Digital Administration Code)
  • Audit trail: no certified audit log of communications possible - mandatory for PA accountability under Art. 5(2) GDPR

What PAs must do by July 1, 2026

  • Census: map ALL uses of commercial messaging within the body (offices, schools, local police, social services)
  • Communication to citizens: privacy notice on the channel change with the new official channel for each service
  • Procedure: prepare process for citizens still writing via WhatsApp after July 1 (respond indicating correct channel, log the switch)
  • Data deletion: remove citizens' phone numbers from contacts, archive conversations with documentary value, delete the rest
  • Internal training: mandatory course for all employees on 'post-WhatsApp ban institutional communications' by September 30, 2026
  • Update Art. 30 Register: remove WhatsApp-based processing, add new ones (citizen PEC, institutional app notification system)

In DPO Workspace

The Events/Urgencies section lets you create a specific 'WhatsApp PA Compliance Workflow' for each PA client: usage census, citizen communication, employee training, Register update. Each step has a checkbox and deadline linked to July 1, 2026.

Official source:Italian DPA - General provision on commercial messaging in PA (May 19, 2026)Official source:Italian Digital Administration Code (CAD)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

Jul 29, 2026 6 min
Italian DPA
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

Jul 15, 2026 3 min
Italian DPA
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

Jul 14, 2026 3 min