All news
Italian DPA July 2, 2026 4 min

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

The 2025 figures presented to Parliament on 2 July show a tougher authority and a market that keeps failing in the same places. How to read them as a DPO

TL;DR for the DPO

2025 report (presented 2/7/2026): 807 collegial decisions, 506 corrective/sanctioning measures, EUR 37.7M collected (+54.5% vs 24.4M in 2024), 2,415 breaches notified (78.7% from the private sector), 130 inspections, 65 criminal referrals (16 in 2024). 93.8% of complaints concern telecoms networks and marketing, almost all automated telemarketing.

The three points that matter

  • The fine curve is rising (+54.5% collected): the era of gentle warnings is closing. For controllers, the cost of non-compliance is no longer theoretical.
  • 2,415 breaches notified - almost 7 a day - but only a tiny share ends in sanctions: notifying properly and on time is NOT what exposes you, it is what protects you (the opposite of what clients fear; see the Trenitalia case).
  • AI is the new inspection front: DeepSeek restricted, warnings on deepfakes and 'nudify' apps, facial-recognition FaceBoarding halted at Linate airport (biometric data of 24,500 passengers in a centralised archive), urgent ban on Amazon over data of 1,800 workers. Anyone using AI on people is under special watch.

What to do now, in practice

Three concrete actions from the report: 1) review breach procedures with clients - statistics show that those who notify correctly are almost never sanctioned for the breach itself; 2) if a client does telemarketing, it sits in the sector absorbing 93.8% of complaints: top priority on lists, consents and opt-out registers; 3) inventory AI systems (the systems register in the generator): biometrics, emotions and worker surveillance are exactly the themes of the 2025 decisions.

Why it matters for your clients

The annual report is the best compass for where the authority will look in the next 12 months: more fines collected, more criminal referrals, inspections on digital identity, electronic registers, facial recognition and public databases. For a DPO it is ready-made material for the next client meeting: not 'the GDPR says', but 'the authority just did'.

Official source:Italian Data Protection Authority - 2025 activity report, presented to Parliament on 2 July 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

Jul 29, 2026 6 min
Italian DPA
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

Jul 15, 2026 3 min
Italian DPA
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

Jul 14, 2026 3 min