Skip to main content
๐Ÿ‡ฎ๐Ÿ‡น Italy ยท EU GDPR / Codice Privacy

Italy Data Removal Guide (2026)

Italian residents may exercise GDPR and national privacy-law rights to access, object to, correct, restrict, or in appropriate circumstances erase personal data held by commercial, marketing, directory, and international providers. The requested outcome depends on the controller, legal basis, source record, and applicable exceptions.

Research status: sources last checked 2026-09-07.

This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.

At a glance

Governing law
EU GDPR / Codice Privacy
Response deadline
For GDPR Articles 15โ€“22 requests, without unjustified delay and no later than 1 month; extendable by 2 months for complexity or request volume with notice within the first month
Regulator
Garante per la protezione dei dati personali
Private right of action
Potential compensation under GDPR Article 82 and other judicial remedies, subject to the claim, standing, jurisdiction, and applicable law

EU General Data Protection Regulation (GDPR) + Codice in materia di protezione dei dati personali (D.lgs. 196/2003)

Italy applies the EU GDPR together with Legislative Decree No. 196/2003 (Codice in materia di protezione dei dati personali), as amended to adapt the national framework to the GDPR. The Garante per la protezione dei dati personali supervises the framework. Its current rights guidance says controllers must respond to Articles 15โ€“22 requests within one month, may extend by two months for complexity or request volume with notice, and must explain a refusal; a complaint under Article 77 is available when processing is non-compliant or the response is missing or unsatisfactory.

Read the full EU GDPR / Codice Privacyexplainer โ†’Scope, penalties, private right of action, enforcement history.

What rights do Italy residents have?

  • โ†’Right of access (Diritto di accesso, Article 15 GDPR)
  • โ†’Right to rectification (Diritto di rettifica, Article 16 GDPR)
  • โ†’Right to erasure / "Diritto alla cancellazione" (Article 17 GDPR)
  • โ†’Right to object to direct marketing; objections to other processing depend on Article 21 conditions
  • โ†’Right to restriction of processing (Article 18 GDPR)
  • โ†’Right to file a formal complaint (Reclamo) with the Garante Privacy

Who holds your data in Italy?

A request in Italy may involve business and property records, telephone directories, credit or risk-information providers, telemarketing operators, B2B platforms, or international data services. Identify the controller, exact listing, natural-person data, processing purpose and legal basis, and whether a statutory source, retention duty, or official-record rule limits the requested outcome.

Public-record sources brokers scrape

  • Business and property records or official publications; review source-specific correction and disclosure rules
  • Telephone and subscriber directories; separate listing changes from RPO marketing opposition
  • Credit, risk-information, and debt-collection providers; distinguish accuracy, retention, and erasure questions
  • Telemarketing, directory, B2B, and international providers; use each current privacy or rights route

How to remove your data in Italy

  1. 1Identify the controller, exact listing, source record, legal basis, and whether the request concerns a natural person rather than only a company or official record.
  2. 2Send a written GDPR rights request to the controller using its current privacy contact or DPO route. State the specific data and right requested, and provide only proportionate identity information if reasonably necessary.
  3. 3Register fixed or mobile numbers with the official Registro Pubblico delle Opposizioni for telemarketing opposition. The current RPO also covers qualifying postal advertising addresses in public telephone lists; registration can affect prior consents, subject to post-registration consent and contractual exceptions.
  4. 4For business, property, directory, credit, or source records, ask the relevant custodian about correction, disclosure, retention, and listing rules; a provider-level request does not automatically amend the source record.
  5. 5If the controller does not respond within the applicable period or the response is unsatisfactory, preserve the correspondence and consider a free Article 77 complaint to the Garante through its current official route.

Generate requests in under 60 seconds

Generate requests for 1,034 US/global broker workflows for $9

Some Italy residents may encounter US-based people-search providers. OfflistMe can prepare source-aware deletion-request drafts for selected recorded workflows; you review the route and applicable law, then send from your own inbox. No account or ID upload to OfflistMe is required for drafting. Pair it with the Italy-specific steps above.

What if a company ignores your request?

Consider the Garante per la protezione dei dati personali information or complaint route above if the controller does not respond or the response is unsatisfactory. This guide records the following penalty orientation: GDPR administrative fines can reach โ‚ฌ20M or 4% of worldwide annual turnover for specified infringements, whichever is higher; the category, scope, and facts control. The private-action note is: Potential compensation under GDPR Article 82 and other judicial remedies, subject to the claim, standing, jurisdiction, and applicable law. Neither field is an individual award or a promise of enforcement.

Open the Garante per la protezione dei dati personali information or complaint route โ†—

FAQ: Italy data removal

How do I block telemarketing calls on mobile phones in Italy?+

Register mobile and landline numbers on the official Registro Pubblico delle Opposizioni (RPO). The current service covers all national fixed and mobile numbers, can revoke prior marketing consents except for later consent and certain contractual relationships, and also has a postal-advertising scope for addresses in public telephone lists. It is a marketing-opposition service, not a universal deletion mechanism for every directory or source record.

How do I submit an Article 17 erasure request in Italy?+

Send a written Article 17 request to the controller's current privacy contact or DPO, identifying the data and the legal basis for the request without oversharing. The Garante states that Articles 15โ€“22 requests generally receive a response within one month, with a possible two-month extension and notice; the controller may lawfully retain some data under GDPR exceptions or another legal obligation.

Related resources

Other country guides