Back to Feed
PolicySep 2, 2026

Garante per la protezione dei dati personali (Italy) - 577/2026

Italy's DPA warns media company for airing unmarked AI deepfake of journalist.

Summary

Italy's Garante per la protezione dei dati personali has issued a warning to media company RTI S.p.a. for airing satirical AI-generated deepfake footage of journalist Enrico Mentana without adequate disclaimers. The DPA found that the disclaimers were insufficient to clearly inform viewers of the AI-generated nature of the content, leading to potential misattribution of statements and harm to the journalist's reputation.

Full text

Help Garante per la protezione dei dati personali (Italy) - 577/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 15:19, 2 September 2026 view source Carloc (talk | contribs)750 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 15:19, 2 September 2026 Garante per la protezione dei dati personali - 577/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 25 GDPR Type: Complaint Outcome: Upheld Started: Decided: 23.07.2026 Published: Fine: n/a Parties: RTI S.p.a. (controller) Enrico Mentana (data subject) National Case Number/Name: 577/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: carloc The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. For a certain time, the program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. Among others, the program also aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). This footage included an AI voiceover that attributed to him words, which he had never spoken. The data subject was depicted while commenting on the news in the TV studio where he usually worked as anchorman. The footage was extremely realistic and was based on authentic footage of the data subject that had aired on a different network (which the controller had regularly licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. The data subject filed a complaint. He claimed that the footage was not clearly marked as AI and that, as a consequence, many members of the audience erroneously attributed certain opinions to him and believed that he had expressed those opinions on television. On these grounds, he claimed that the deepfake footage severely harmed his personal image and professional reputation. In its defense, the controller protested that the footage came with sufficient disclaimers that made its AI nature clear. The controller claimed that the voiceover was obviously comedic in nature and that, therefore, the footage could not be mistaken as authentic. During its investigation, the DPA found that different versions of the footage included different forms of disclaimers about its AI-generated nature: • The TV version of the footage did not include a disclaimer. However, the show had provided viewers with a disclaimer before airing the footage; • The footage on the controller’s website did not include a disclaimer; however, a disclaimer was present on the page that hosted the footage as well as in the video’s title; • The footage on the controller’s platform, included a disclaimer; • The footage on the controller’s social media channels, included no disclaimers. During the procedure the controller removed some of the version of the footage (but not all of them). Holding The DPA held that overall, the controller’s disclaimers were not sufficient to clarify the AI-generated nature of the footage. With regards to television footage specifically, the DPA clarified that the verbal disclaimer was ineffective with regards to members of the audience who tuned in while the footage was airing already. Ultimately, the DPA stated that the disclaimers should have been more evident, in order to clearly inform all viewers- including the least attentive ones. Contrary to the controller’s defenses, the DPA also held that the comedic purpose of the footage was not self-evident. In this regard, the DPA considered that the footage showed no obvious signs of manipulation and depicted the data subject in a plausible setting. Overall, the DPA found a violation of Article 5(1)(a) GDPR (“lawfulness, fairness and transparency”) as well as 25 GDPR (“data protection by design and default”). The DPA issued a warning and forbid all further processing of the footage. In considering the sanction, the DPA took into account that the legal questions raised by deepfakes, are still relatively new. Comment The facts took place before the AI Act had entered into force. Therefore, the Act’s rules on the marking of AI-generated content, did not apply to the case. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Press Release dated August 7, 2026 [Web Doc. No. 10281021] Decision of July 23, 2026 Register of Decisions No. 577 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter, the “Regulation”); HAVING REGARD TO the Code on Data Protection, containing provisions for the adaptation of national law to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the “Code”); HAVING REGARD TO the complaint filed with the Data Protection Authority, pursuant to Art. 77 of the Regulation, on XX, in which Mr. Enrico Ettore Mentana, represented by lawyers XX and XX, alleged the unauthorized use of his image by R.T.I. - Reti Televisive Italiane S.p.A., in its capacity as producer of the program “Striscia la Notizia,” which, beginning on XX, unlawfully reproduced the aforementioned image through the use of artificial intelligence systems in order to create “reports” – detailed in the complaint – in which he “appears (unwittingly) as the protagonist and is depicted in his role as News Director of La7’s news program (…) to perform a script written by the authors of the Mediaset television program, while also displaying the La7 News logo to make the staging appear even more credible”; he also noted that the full video footage was subsequently uploaded to the television program’s website and social media channels, as well as to the Mediaset Infinity platform, and requested the erasure of all improperly used images; RECITAL that the complainant specifically pointed out that: following a cease-and-desist letter sent on XX to both the broadcaster and the program’s editorial staff regarding the use of his image, the company’s attorneys argued that it was a lighthearted parody permitted by the right to satire and the laws that protect it; in response to this, the complainant noted that the broadcaster’s conduct went beyond the proper exercise of the right to satire, especially given that a great many people believed the videos—produced by *Striscia la Notizia* and disseminated on television and social media—were real; R.T.I., despite having justified its actions, proceeded to gradually remove the published videos from social media; however, it uploaded the episodes of the program to the Striscia la Notizia website via links different from those indicated by the defense attorneys in the cease-and-desist letter; The dissemination of the videos, in addition to constituting an unlawful commercial exploitation of the plaintiff’s image, violates the proper processing of personal data and, for all intents and purposes, constitutes the offenses of unlawful data processing, impersonation, as well as defamatory conduc

Entities

deepfake (product)RTI S.p.a. (vendor)Mediaset S.p.a. (vendor)Striscia la Notizia (product)AI (product)