With decision No. 797 of December 30, 2025, the Italian Data Protection Authority launched the inspection activities plan for the first half of 2026. At least 40 inspections are planned, conducted also with the support of the Tax Police (Guardia di Finanza).
Sectors under scrutiny
- Data breaches on databases of particular relevance (banking and financial sector)
- Whistleblowing: proper functioning of internal reporting channels under Legislative Decree 24/2023
- Electronic health dossier (structure, access, profiling)
- Telemarketing in the energy sector (lead acquisition, double opt-in, code of conduct)
- Use of AI tools in school environments (NEW area)
- Customs information system
- Pseudonymization and sharing of telco big data
Points of attention for the DPO
If your client falls into one of the above sectors, it's time to do targeted internal audit. Verify Art. 30 record, data breach procedures, DPIA for high-risk processing activities. An inspection without adequate preparation generates fines even on formal documentary shortcomings.
What to prepare if you're in banking
- Formalized data breach management procedure with timing and responsibilities (in light of the Intesa Sanpaolo 31.8M fine)
- Detailed audit trail on database access
- Documentation of risk assessments on customer management systems
- Evidence of customer notices on all processing activities, including intra-group
What to prepare if you're in education
- Complete mapping of AI tools in use (teaching, evaluation, student monitoring)
- DPIA for every AI system processing minors' data
- Clear legal basis for each processing activity
- Notices to parents in understandable language (Art. 12 GDPR)
In DPO Workspace
Sector templates cover healthcare, PA, professional studios, commerce, and manufacturing. For banking and education sectors, in case of high demand we can add dedicated templates. Write to us via feedback if you need it.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free