The Italian authority publishes its 2025 activity report highlighting the challenges of artificial intelligence and data protection
The Italian data protection authority (Garante) presented its activity report for the year 2025, highlighting its interventions in various fields, notably artificial intelligence, the protection of minors, and employee monitoring.
In 2025, the Garante limited the processing of data of Italian users by two Chinese companies managing the conversational artificial intelligence system DeepSeek. Following an investigation into "deepfakes," the authority issued a warning against users of platforms such as Grok, ChatGPT, and Clothoff, emphasizing the risks of serious rights violations in the absence of consent. In this context, a provisional limitation measure on processing was imposed against the company managing the Clothoff application, located in the British Virgin Islands, capable of artificially generating images of naked persons.
The authority suspended the "FaceBoarding" facial recognition system at Milan Linate airport, deeming it non-compliant with the GDPR. The investigation revealed that biometric data of more than 24,500 passengers were stored in a centralized archive, without the data subjects having adequate control over their data and without the guarantees required by the regulation.
In the field of labor relations, the Garante urgently prohibited Amazon Italia Logistica from processing the personal data of more than 1,800 employees, relating to their health, union activity, and private life, systematically collected and stored for up to ten years. The authority also raised concerns about the use of video surveillance systems allowing remote monitoring of employees in small businesses. A warning was issued to an Italian startup for an extension module on Slack and Teams analyzing conversations to detect employees' stress levels.
The Garante intensified its activity in the health sector, issuing 28 opinions and identifying flaws in the management of health records. It contributed to the compliance of the Italian digital wallet system (IT Wallet System). The protection of minors online remained a priority, with monitoring of age verification on social networks and an awareness campaign against "sharenting," the excessive publication of content about children by their parents.
In figures, the 2025 activity resulted in 807 decisions, 4,288 complaints processed, and 145,846 reports received. The authority issued 65 opinions and forwarded 65 reports to the judicial authority, a significant increase compared to 2024. In total, 506 corrective measures and sanctions were imposed, with sanctions collected exceeding 37 million euros. The number of notified data breaches amounted to 2,415, up 10%, and 130 inspections were conducted.
In 2025, the Garante limited the processing of data of Italian users by two Chinese companies managing the conversational artificial intelligence system DeepSeek. Following an investigation into "deepfakes," the authority issued a warning against users of platforms such as Grok, ChatGPT, and Clothoff, emphasizing the risks of serious rights violations in the absence of consent. In this context, a provisional limitation measure on processing was imposed against the company managing the Clothoff application, located in the British Virgin Islands, capable of artificially generating images of naked persons.
The authority suspended the "FaceBoarding" facial recognition system at Milan Linate airport, deeming it non-compliant with the GDPR. The investigation revealed that biometric data of more than 24,500 passengers were stored in a centralized archive, without the data subjects having adequate control over their data and without the guarantees required by the regulation.
In the field of labor relations, the Garante urgently prohibited Amazon Italia Logistica from processing the personal data of more than 1,800 employees, relating to their health, union activity, and private life, systematically collected and stored for up to ten years. The authority also raised concerns about the use of video surveillance systems allowing remote monitoring of employees in small businesses. A warning was issued to an Italian startup for an extension module on Slack and Teams analyzing conversations to detect employees' stress levels.
The Garante intensified its activity in the health sector, issuing 28 opinions and identifying flaws in the management of health records. It contributed to the compliance of the Italian digital wallet system (IT Wallet System). The protection of minors online remained a priority, with monitoring of age verification on social networks and an awareness campaign against "sharenting," the excessive publication of content about children by their parents.
In figures, the 2025 activity resulted in 807 decisions, 4,288 complaints processed, and 145,846 reports received. The authority issued 65 opinions and forwarded 65 reports to the judicial authority, a significant increase compared to 2024. In total, 506 corrective measures and sanctions were imposed, with sanctions collected exceeding 37 million euros. The number of notified data breaches amounted to 2,415, up 10%, and 130 inspections were conducted.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire