On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian Data Protection Authority (“Garante”) presented to Parliament its Annual Report on activities carried out in 2025. This is more than the customary institutional report (and likely the last to be presented by the current Board, whose term expires in 2027). Rather, it provides a snapshot of a digital ecosystem in which artificial intelligence, digital identity, connected healthcare, algorithmic management of work, child protection and cyber security have become part of a single legal and regulatory agenda. The underlying message is clear: privacy is no longer merely a defensive compliance exercise, but a driver of innovation, trust and competitiveness.
AI and new technologies: from experimentation to accountability
Unsurprisingly, given current developments, the most prominent chapter of the Report is the one on artificial intelligence (AI). The Garante continued to pursue an approach that is not solely enforcement-driven but aimed at addressing risks to data subjects at an early stage: from oversight of deepfakes to enforcement measures concerning deepnude applications and the non-consensual generation of intimate images. From this perspective, the processing of personal data has become the principal point of tension between computational power, model opacity and the protection of individual dignity.
The same approach is reflected in initiatives concerning web scrapingfor the training of generative AI systems and in the favourable opinion on the ministerial guidelines for the introduction of AI in schools. The point is not to halt innovation, but to ensure it is properly governed through a valid legal basis, meaningful transparency, data minimisation, impact assessments where necessary, and documented governance throughout the entire lifecycle of the system. For businesses and public administrations, AI cannot be regarded purely as a technological project: it is, in every respect, also a regulatory issue.
Digital healthcare, public administration and biometrics: innovating, but by design
In the healthcare sector, the Authority issued 28 opinions on draft decrees and regulations, reiterating that the digitalisation of care pathways must incorporate privacy by design, data minimisation, lawfulness, transparency and accountability from the outset. The Report highlights recurring issues in the management of health records, patient identification procedures, the disclosure of health data and the prevention of unauthorised access to information systems. Digital healthcare therefore remains one of the main testing grounds for compliance: the more useful data is for patient care, the more it must be protected through genuinely effective technical, organisational and procedural measures.
The use of biometrics likewise confirms the central importance of the principle of proportionality. The FaceBoarding case at Milan Linate Airport, concerning the centralised storage of passengers’ biometric data, illustrates that the efficiency of the service cannot override the legal assessment of risk, the necessity of the processing and less intrusive alternatives. In a context of increasing automation of identification processes, biometric data remains a high-risk category and requires heightened caution.
On the public sector front, the Report also confirms the Garante’s advisory role in the digitalisation of public administration, including work on the IT-Wallet system. The message is clear: digital identity, interoperability and administrative simplification can only work if the data-processing architecture is designed in a manner consistent with the European framework and with the principle of effective protection of data subjects.
Children and work: where technology meets vulnerability
The protection of children remains a cross-cutting priority. The Garante continued to focus its activities on age verification systems, the phenomenon of sharenting and awareness-raising campaigns, including “Your privacy is worth more than a like”. Children’s personal data should never be regarded as “insignificant”: it is information that may accompany an individual over time, affecting their digital identity, reputation and freedom of self-determination.
In the employment context, instead, the Report confirms the focus on disproportionate processing activities and excessive forms of monitoring. The prohibition imposed on Amazon Italia Logistica in relation to the data of over 1,800 workers is part of a well-established approach: digital tools, monitoring systems, video surveillance and AI solutions applied to the organisation of work must comply with the principles of necessity, proportionality and transparency. Productivity alone does not justify pervasive surveillance.
Telemarketing, news reporting and inspections: traditional challenges become more sophisticated
Alongside the new frontiers of AI, the Report points out that the traditional challenges have by no means disappeared. The fight against aggressive telemarketing, particularly in the energy sector, continues to require significant action, not least because data collection and commercial profiling techniques are becoming increasingly sophisticated. Similarly, in balancing privacy and the right to report news, the Authority reaffirmed the principle of the essential nature of information, criticising excessive sensationalism and the publication of unnecessary details that undermine individual dignity.
Inspection activities confirmed the pervasiveness of data processing and the central importance of controls in high-impact sectors, such as SPID, facial recognition, video surveillance, scientific research, data breaches and public databases. Perhaps the most significant takeaway is that the Garante describes a landscape in which poor practices do not disappear but become layered and amplified by increasingly sophisticated technologies. For this reason, compliance must be continuous, verifiable and underpinned by concrete organisational safeguards.
Key figures for 2025
From data to trust: the Report’s real message
In 2025, the Garante took part in 260 international meetings and contributed to European and global initiatives on AI, data governance and the protection of fundamental rights. Yet the Report’s central message is directed equally at the national level and at day-to-day implementation: businesses and public administrations are called upon to make data protection a structural pillar of governance, security and trust. Privacy compliance can no longer be confined to the records of processing activities or privacy notices: it must be integrated into decision-making processes, technological development models, supplier management, cybersecurity and corporate culture. In other words, the question is no longer whether to innovate, but how to do so without losing control over data and, consequently, over the relationship of trust with individuals, customers, employees and citizens.