[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1xIMQG-EtqQaplLBVKRIWfQCUXI5OitGbReFUdTFcH4":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"06b6aff9-feaa-4f3e-9a8f-8c16ce8848bb","Garante per la protezione dei dati personali (Italy) - 9788429","garante-per-la-protezione-dei-dati-personali-italy-9788429-e875a8","← Older revision Revision as of 09:55, 25 July 2026 (One intermediate revision by the same user not shown) Line 33: Line 33: |GDPR_Article_Link_2= |GDPR_Article_Link_2= |EU_Law_Name_1=Article 5(3) ePrivacy Directive 2002\u002F58\u002FEC |EU_Law_Name_1=Article 5(3) Directive 2002\u002F58\u002FEC |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj |EU_Law_Name_2= |EU_Law_Name_2= Line 71: Line 71: Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's \"one-stop-shop\" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05\u002F2020 EDPB, 'Opinion 5\u002F2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities', 12 March 2019, (available [https:\u002F\u002Fedpb.europa.eu\u002Fsites\u002Fdefault\u002Ffiles\u002Ffiles\u002Ffile1\u002F201905_edpb_opinion_eprivacydir_gdpr_interplay_en_0.pdf here]). on this point. Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's \"one-stop-shop\" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05\u002F2020 EDPB, 'Opinion 5\u002F2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities', 12 March 2019, (available [https:\u002F\u002Fedpb.europa.eu\u002Fsites\u002Fdefault\u002Ffiles\u002Ffiles\u002Ffile1\u002F201905_edpb_opinion_eprivacydir_gdpr_interplay_en_0.pdf here]). on this point. The DPA held that the controller’s new privacy policy violated [https:\u002F\u002Feur-lex.europa.eu\u002FLexUriServ\u002FLexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:HTML#tocId7 Article 5(3) of the ePrivacy Directive] (Directive 2002\u002F58\u002FEC). The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent Article 5(3) was modified by [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:32009L0136&from=EN Directive 2009\u002F136\u002FEC]. This summary references the consolidated version of the Directive. . For this reason, legitimate interest under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]] is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated [https:\u002F\u002Fwww.gazzettaufficiale.it\u002Fdettaglio\u002Fcodici\u002FdatiPersonali\u002F121_0_1 Article 122 of the Italian Privacy Code] (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) of the Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA held that the controller’s new privacy policy violated [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj Article 5(3) Directive 2002\u002F58\u002FEC]. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent Article 5(3) was modified by [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:32009L0136&from=EN Directive 2009\u002F136\u002FEC]. This summary references the consolidated version of the Directive. . For this reason, legitimate interest under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]] is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated [https:\u002F\u002Fwww.gazzettaufficiale.it\u002Fdettaglio\u002Fcodici\u002FdatiPersonali\u002F121_0_1 Article 122 of the Italian Privacy Code] (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj Article 5(3)]. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller. The DPA issued a warning against the controller.","The Italian Data Protection Authority (Garante per la protezione dei dati personali) has issued a warning to a controller for violating Article 5(3) of the ePrivacy Directive and Article 122 of the Italian Privacy Code. The authority found that the controller's new privacy policy improperly used legitimate interest as a legal basis for processing cookies, instead of requiring user consent. Despite the Irish DPA being the lead supervisory authority under GDPR's one-stop-shop mechanism, the Italian DPA asserted its competence to enforce the ePrivacy Directive.","Italian DPA issues warning over cookie consent violations.","Help Garante per la protezione dei dati personali (Italy) - 9788429: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 14:26, 16 July 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators221 editsTag: Visual edit← Older edit Revision as of 09:55, 25 July 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators100 editsTag: Visual editNewer edit → (One intermediate revision by the same user not shown)Line 33: Line 33: |GDPR_Article_Link_2=|GDPR_Article_Link_2= |EU_Law_Name_1=Article 5(3) ePrivacy Directive 2002\u002F58\u002FEC|EU_Law_Name_1=Article 5(3) Directive 2002\u002F58\u002FEC |EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj|EU_Law_Link_1=https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj |EU_Law_Name_2=|EU_Law_Name_2= Line 71: Line 71: Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's \"one-stop-shop\" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05\u002F2020\u003Cref>EDPB, 'Opinion 5\u002F2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities', 12 March 2019, (available [https:\u002F\u002Fedpb.europa.eu\u002Fsites\u002Fdefault\u002Ffiles\u002Ffiles\u002Ffile1\u002F201905_edpb_opinion_eprivacydir_gdpr_interplay_en_0.pdf here]).\u003C\u002Fref> on this point.Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's \"one-stop-shop\" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05\u002F2020\u003Cref>EDPB, 'Opinion 5\u002F2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities', 12 March 2019, (available [https:\u002F\u002Fedpb.europa.eu\u002Fsites\u002Fdefault\u002Ffiles\u002Ffiles\u002Ffile1\u002F201905_edpb_opinion_eprivacydir_gdpr_interplay_en_0.pdf here]).\u003C\u002Fref> on this point. The DPA held that the controller’s new privacy policy violated [https:\u002F\u002Feur-lex.europa.eu\u002FLexUriServ\u002FLexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:HTML#tocId7 Article 5(3) of the ePrivacy Directive] (Directive 2002\u002F58\u002FEC). The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent\u003Cref>Article 5(3) was modified by [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:32009L0136&from=EN Directive 2009\u002F136\u002FEC]. This summary references the consolidated version of the Directive.\u003C\u002Fref>. For this reason, legitimate interest under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]] is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated [https:\u002F\u002Fwww.gazzettaufficiale.it\u002Fdettaglio\u002Fcodici\u002FdatiPersonali\u002F121_0_1 Article 122 of the Italian Privacy Code] (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) of the Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive.The DPA held that the controller’s new privacy policy violated [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj Article 5(3) Directive 2002\u002F58\u002FEC]. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent\u003Cref>Article 5(3) was modified by [https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002FPDF\u002F?uri=CELEX:32009L0136&from=EN Directive 2009\u002F136\u002FEC]. This summary references the consolidated version of the Directive.\u003C\u002Fref>. For this reason, legitimate interest under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]] is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated [https:\u002F\u002Fwww.gazzettaufficiale.it\u002Fdettaglio\u002Fcodici\u002FdatiPersonali\u002F121_0_1 Article 122 of the Italian Privacy Code] (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of [https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2002\u002F58\u002Foj Article 5(3)]. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.The DPA issued a warning against the controller. Revision as of 09:55, 25 July 2026 Garante per la protezione dei dati personali - 9788429 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(3) Directive 2002\u002F58\u002FECArticle 122 d. lgs. 30 giugno 2003, n. 196 (Italian Privacy Code) Type: Investigation Outcome: Other Outcome Started: Decided: 07.07.2022 Published: Fine: n\u002Fa Parties: n\u002Fa National Case Number\u002FName: 9788429 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Italian Original Source: Garante per la Protezione dei Dati Personali (in IT) Initial Contributor: Carloc The Italian DPA issued a warning against TikTok for processing cookies without the users' consent under its announced privacy policy update. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's \"one-stop-shop\" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05\u002F2020[1] on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) Directive 2002\u002F58\u002FEC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent[2]. For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3). The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller. Comment TikTok postponed their privacy policy update after the DPA’s warning. Since the decision was based on the ePrivacy Directive, the DPA’s warning was limited to the storing and gaining of access to cookies. However, the investigation had a broader scope. The DPA highlighted other issues in the announced privacy policy: • the age verification process in place was lacking;[3] • the policy used an incorrect notion of legitimate interest; • the policy","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429&diff=52500&oldid=52279","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-07-25T09:55:06+00:00","2026-07-25T10:00:23.730102+00:00",7,[18,21,24],{"name":19,"type":20},"Garante per la protezione dei dati personali","vendor",{"name":22,"type":23},"GDPR","product",{"name":25,"type":23},"ePrivacy Directive","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":28,"name":29,"slug":30},null,"Policy","policy",[32,36,41,46],{"category":33},{"id":34,"icon":28,"name":22,"slug":35},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":37},{"id":38,"icon":28,"name":39,"slug":40},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":42},{"id":43,"icon":28,"name":44,"slug":45},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":47},{"id":26,"icon":28,"name":29,"slug":30},[]]