[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUqzNgTyg-TGZUcZPZFRAjqlI-uw1YggcwcMf4-f5RmQ":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"9c74d40f-8cad-494f-b5bc-e5b54fa340df","Garante per la protezione dei dati personali (Italy) - 577\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-577-2026-dae444","← Older revision Revision as of 12:00, 8 September 2026 Line 93: Line 93: }} }} The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated. The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated, in violation of [[Article 5 GDPR|Article 5(1)(a)]] and [[Article 25 GDPR|25 GDPR]]. == English Summary == == English Summary == === Facts === === Facts === The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. For a certain time, the program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. The program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). The footage depicted the data subject commenting on the news in the studio where he usually worked as an anchorman, and included an AI voiceover attributing words to the data subject which he never said. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). The footage depicted the data subject commenting on the news in the studio where he usually worked as an anchorman, and included an AI voiceover attributing words to the data subject which he never said. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels.","Italy's Garante per la protezione dei dati personali has issued a warning to media company RTI S.p.a. for airing AI-generated deepfakes of journalist Enrico Mentana without proper disclosure. The deepfakes, which depicted Mentana commenting on news he never spoke about, were aired on TV, streaming platforms, and social media. The DPA found this to be a violation of GDPR's principles on lawful processing and data protection by design and by default.","Italian DPA warns media company over undisclosed AI-generated deepfake of journalist.","Help Garante per la protezione dei dati personali (Italy) - 577\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:57, 3 September 2026 view sourceCarloc (talk | contribs)752 edits Tag: Visual edit← Older edit Latest revision as of 12:00, 8 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators393 editsTag: Visual edit Line 93: Line 93: }}}} The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated.The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated, in violation of [[Article 5 GDPR|Article 5(1)(a)]] and [[Article 25 GDPR|25 GDPR]]. == English Summary ==== English Summary == === Facts ====== Facts === The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. For a certain time, the program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities.The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. The program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). The footage depicted the data subject commenting on the news in the studio where he usually worked as an anchorman, and included an AI voiceover attributing words to the data subject which he never said. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). The footage depicted the data subject commenting on the news in the studio where he usually worked as an anchorman, and included an AI voiceover attributing words to the data subject which he never said. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. Latest revision as of 12:00, 8 September 2026 Garante per la protezione dei dati personali - Case number: 577\u002F2026 Internal number (from the DPA): 10281021 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 25 GDPR Type: Complaint Outcome: Upheld Started: Decided: 23.07.2026 Published: Fine: n\u002Fa Parties: RTI S.p.a. (controller) Enrico Mentana (data subject) National Case Number\u002FName: Case number: 577\u002F2026 Internal number (from the DPA): 10281021 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: carloc The DPA issued a warning against a media company for airing a deepfake of a known journalist without sufficiently marking the footage as AI-generated, in violation of Article 5(1)(a) and 25 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The case involves media company RTI S.p.a. (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. The program aired a segment consisting of satirical, AI-generated deepfakes of known Italian personalities. Among others, the program aired footage of well known journalist and news anchorman Enrico Mentana (the data subject). The footage depicted the data subject commenting on the news in the studio where he usually worked as an anchorman, and included an AI voiceover attributing words to the data subject which he never said. The footage was extremely realistic and was based on authentic footage of the data subject which had aired on a different TV network (and which the controller had licensed from another media company). In addition to airing the footage on television, the controller also made it available via its streaming platform, on its website, and on its social channels. The data subject filed a complaint. He claimed that the footage was not clearly marked as AI and that, as a consequence, many members of the audience erroneously attributed certain opinions to him and believed that he had expressed those opinions on television. On these grounds, he claimed that the deepfake footage severely harmed his personal image and professional reputation. In its defense, the controller protested that the footage came with sufficient disclaimers that made its AI nature clear. The controller also claimed that the voiceover was obviously comedic in nature and that, therefore, the footage could not be mistaken as authentic. During its investigation, the DPA found that different versions of the footage included different forms of disclaimers and markings about its AI-generated nature: The TV version of the footage was not marked as AI-generated. However, the show had provided viewers with a disclaimer before airing the footage; The footage on the controller’s website was not marked as AI-generated. However, a disclaimer was present on the page that hosted the footage as well as in the video’s title; The footage on the controller’s platform, was marked as AI-generated; The footage on the controller’s social media channels, was not marked and did not come with disclaimers. During the procedure the controller removed some of the version of the footage but not all of them. Holding The DPA held that overall, the controller’s disclaimers and markings were not sufficient to clarify the AI-generated nature of the footage. With regards to television footage specifically, the DPA clarified that the verbal disclaimer given during the show was insufficient, as some members of the audience had tuned into the channel when the footage was airing already. Ultimately, the DPA stated that the disclaimers should have been more evident, in order to clearly inform all viewers- including the least attentive ones. Contrary to the controller’s defenses, the DPA also held that the comedic purpose of the footage was not self-evident. In this regard, the DPA considered that the footage showed no obvious signs of manipulation and depicted the data subject in a plausible setting. Overall, the DPA found a violation of Article 5(1)(a) GDPR (“lawfulness, fairness and transparency”) as well as 25 GDPR (“data protection by design and default”). The DPA issued a warning and prohibited all further processing of the footage. In considering the sanction, the DPA took into account that the legal questions raised by deepfakes, are still relatively new. Comment The facts took place before the AI Act’s rules on the marking of AI-generated content, had entered into force. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. SEE ALSO Press Release dated August 7, 2026 [Web Doc. No. 10281021] Decision of July 23, 2026 Register of Decisions No. 577 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_577\u002F2026&diff=52950&oldid=52900","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-09-08T12:00:01+00:00","2026-09-08T12:00:19.335591+00:00",7,[18,21,24,26,28],{"name":19,"type":20},"Striscia la Notizia","product",{"name":22,"type":23},"RTI S.p.a.","vendor",{"name":25,"type":23},"Mediaset S.p.a.",{"name":27,"type":20},"deepfake",{"name":29,"type":20},"AI-generated footage","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":30,"icon":32,"name":33,"slug":34},null,"Policy","policy",[36,41,46,51],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":42},{"id":43,"icon":32,"name":44,"slug":45},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":47},{"id":48,"icon":32,"name":49,"slug":50},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":52},{"id":30,"icon":32,"name":33,"slug":34},[]]