Garante per la protezione dei dati personali (Italy) - 577/2026
Italian DPA warns media company over unmarked AI-generated deepfakes of journalist.
Summary
The Italian Data Protection Authority (Garante per la protezione dei dati personali) has issued a warning to media company RTI S.p.a. for airing AI-generated deepfakes of journalist Enrico Mentana without clear markings. The deepfakes, used in a satirical segment, attributed fabricated statements to Mentana, harming his image and reputation. The DPA found that the disclaimers provided were insufficient and violated GDPR's principles of fairness and transparency.
Full text
Help Garante per la protezione dei dati personali (Italy) - 577/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 15:19, 2 September 2026 view sourceCarloc (talk | contribs)750 edits Tag: Decisions [1.0] Latest revision as of 15:44, 2 September 2026 view source Carloc (talk | contribs)750 edits Tag: Visual edit (14 intermediate revisions by the same user not shown)Line 7: Line 7: |DPA_With_Country=Garante per la protezione dei dati personali (Italy)|DPA_With_Country=Garante per la protezione dei dati personali (Italy) |Case_Number_Name=577/2026|Case_Number_Name=Case number: 577/2026 Internal number (from the DPA): 10281021 |ECLI=|ECLI= Line 99: Line 100: The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. For a certain time, the program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities.The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. For a certain time, the program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. Among others, the program also aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). This footage included an AI voiceover that attributed to him words, which he had never spoken. The data subject was depicted while commenting on the news in the TV studio where he usually worked as anchorman. The footage was extremely realistic and was based on authentic footage of the data subject that had aired on a different network (which the controller had regularly licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). This footage included an AI voiceover and attributed words to the data subject, which he had never spoken. The data subject was depicted while commenting on the news in the TV studio where he usually worked as anchorman. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. The data subject filed a complaint. He claimed that the footage was not clearly marked as AI and that, as a consequence, many members of the audience erroneously attributed certain opinions to him and believed that he had expressed those opinions on television. On these grounds, he claimed that the deepfake footage severely harmed his personal image and professional reputation.The data subject filed a complaint. He claimed that the footage was not clearly marked as AI and that, as a consequence, many members of the audience erroneously attributed certain opinions to him and believed that he had expressed those opinions on television. On these grounds, he claimed that the deepfake footage severely harmed his personal image and professional reputation. In its defense, the controller protested that the footage came with sufficient disclaimers that made its AI nature clear. The controller claimed that the voiceover was obviously comedic in nature and that, therefore, the footage could not be mistaken as authentic.In its defense, the controller protested that the footage came with sufficient disclaimers that made its AI nature clear. The controller also claimed that the voiceover was obviously comedic in nature and that, therefore, the footage could not be mistaken as authentic. During its investigation, the DPA found that different versions of the footage included different forms of disclaimers about its AI-generated nature: During its investigation, the DPA found that different versions of the footage included different forms of disclaimers and markings about its AI-generated nature: • The TV version of the footage did not include a disclaimer. However, the show had provided viewers with a disclaimer before airing the footage; • The footage on the controller’s website did not include a disclaimer; however, a disclaimer was present on the page that hosted the footage as well as in the video’s title;* The TV version of the footage was not marked as AI-generated. However, the show had provided viewers with a disclaimer before airing the footage; • The footage on the controller’s platform, included a disclaimer;* The footage on the controller’s website was not marked as AI-generated. However, a disclaimer was present on the page that hosted the footage as well as in the video’s title; • The footage on the controller’s social media channels, included no disclaimers.* The footage on the controller’s platform, was marked as AI-generated; * The footage on the controller’s social media channels, was not marked and did not come with disclaimers. During the procedure the controller removed some of the version of the footage (but not all of them).During the procedure the controller removed some of the version of the footage (but not all of them). === Holding ====== Holding === The DPA held that overall, the controller’s disclaimers were not sufficient to clarify the AI-generated nature of the footage. With regards to television footage specifically, the DPA clarified that the verbal disclaimer was ineffective with regards to members of the audience who tuned in while the footage was airing already.The DPA held that overall, the controller’s disclaimers and markings were not sufficient to clarify the AI-generated nature of the footage. With regards to television footage specifically, the DPA clarified that the verbal disclaimer given during the show was insufficient, as some members of the audience had tuned into the channel when the footage was airing already. Ultimately, the DPA stated that the disclaimers should have been more evident, in order to clearly inform all viewers- including the least attentive ones. Ultimately, the DPA stated that the disclaimers should have been more evident, in order to clearly inform all viewers- including the least attentive ones. Line 121: Line 121: Contrary to the controller’s defenses, the DPA also held that the comedic purpose of the footage was not self-evident. In this regard, the DPA considered that the footage showed no obvious signs of manipulation and depicted the data subject in a plausible setting.Contrary to the controller’s defenses, the DPA also held that the comedic purpose of the footage was not self-evident. In this regard, the DPA considered that the footage showed no obvious signs of manipulation and depicted the data subject in a plausible setting. Overall, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]] (“lawfulness, fairness and transparency”) as well as 25 GDPR (“data protection by design and default”).Overall, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(a) GDPR]] (“lawfulness, fairness and transparency”) as well as [[Article 25 GDPR|25 GDPR]] (“data protection by design and default”). The DPA issued a warning and forbid all further processing of the footage. In considering the sanction, the DPA took into account that the legal questions raised by deepfakes, are still relatively new.The DPA issued a warning and forbade all further processing of the footage. In considering the sanction, the DPA took into account that the legal questions raised by deepfakes, are still relatively new. == Comment ==== Comment == The facts took place before the AI Act had entered into force. Therefore, the Act’s rules on the marking of AI-generated content, did not apply to the case.The facts