Is Google Analytics Legal in Italy? Cookie Consent, the Garante's Exemption, and Who Qualifies

The Italian flag blended with a ghosted Google Analytics 4 interface, with the June 2022 Garante ruling and the four-condition analytics exemption highlighted, next to the Clickport logo.
Legal status re-verified against primary sources in July 2026. Every ruling and figure below links to the original decision or report.

Italy's Garante declared Google Analytics illegal in June 2022, the third EU country to do so. The Data Privacy Framework has since restored legal cover for US data transfers. But Italy also has a consent exemption for analytics that most Italian website owners have never configured. Here's the full picture as I read it in July 2026.

Key Takeaways
  • 82% of Italian websites still ran Google Analytics nine months after the Garante declared it illegal in June 2022. The ruling targeted Caffeina Media S.r.l. and gave 90 days to comply.
  • Italy's Garante is one of Europe's most aggressive DPAs. It banned ChatGPT (first Western country), fined OpenAI EUR 15 million (annulled on jurisdiction grounds in March 2026), and issued a EUR 79.1 million fine against Enel Energia, the largest in Italian GDPR history.
  • Italy allows analytics cookies without consent if four conditions are met: IP masking, no cross-site tracking, no third-party data sharing, and aggregated statistics only. Google Analytics fails all four.
  • The EU-US Data Privacy Framework currently provides legal cover for GA data transfers, but the PCLOB has been gutted, FISA 702 lapsed in June 2026 with certifications running to March 2027, and Latombe's appeal against the DPF is pending at the CJEU.
  • The EU Digital Omnibus (proposed November 2025) would codify Italy's existing analytics exemption across all 27 EU member states. Tools that qualify today will qualify EU-wide.

The Garante: who enforces your privacy rules

The Garante per la Protezione dei Dati Personali is a four-member collegiate body elected by the Italian Parliament for non-renewable seven-year terms. It has an annual budget of EUR 48 million. And it has a financial incentive other DPAs don't: 50% of all fines collected go directly back to the Garante's budget for inspections, enforcement, and public awareness. In plain English: every fine half-funds the next investigation.

President Pasquale Stanzione, a private law professor at the University of Salerno, has publicly defended the Garante's independence against political pressure.

The Garante's track record speaks for itself. It was the first Western country to ban ChatGPT (March 2023), then fined OpenAI EUR 15 million in December 2024, the first GenAI GDPR fine in Europe. The Court of Rome annulled that fine in March 2026 on jurisdiction grounds, without ever reaching the merits. The appetite it showed is the point. It fined Clearview AI EUR 20 million for scraping 10 billion facial images. It fined Enel Energia EUR 79.1 million in February 2024 for telemarketing abuses, the largest fine in Italian GDPR history (Enel has appealed; the appeal is still open). While Ireland's DPC takes years to investigate Meta, the Garante went from first ChatGPT complaint to emergency ban in 10 days. The authority took political fire in late 2025 over a fine against the RAI programme Report, and opposition parties demanded the board resign. It didn't. The same four members remain in office, with terms running to July 2027.

Cookie consent in Italy is governed by Article 122 of the Codice Privacy (Legislative Decree 196/2003), Italy's transposition of the EU's ePrivacy Directive. The Codice Privacy was substantially amended by Legislative Decree 101/2018 to align with the GDPR, but Article 122 survived intact because it implements ePrivacy, not GDPR.

The penalty isn't gentle. Cookie violations under Article 122 fall into the higher GDPR penalty tier: up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. Italy also retains criminal penalties for the worst cases of intentional large-scale processing violations. In plain English: cookie mistakes in Italy can, at the extreme, end in criminal court.

Italy has several cookie-specific quirks not found in other EU countries. The cookie banner must include an X button in the upper right corner that closes the banner without activating any non-technical cookies. If a visitor declines cookies, the site can't re-present the consent banner for at least six months. And Accept and Reject buttons must have identical formatting: same size, same color weight, same prominence. The Garante was one of the first DPAs to fine a company for dark patterns in cookie banners, issuing EUR 300,000 against Ediscom SpA in February 2023.

The Garante's current cookie guidelines were adopted June 10, 2021, with a compliance deadline of January 10, 2022. They replaced the 2014 guidelines and remain the binding framework in 2026.

Italy-specific cookie banner rules (unique to the Garante)
Required X button in upper right corner that closes the banner without activating any non-essential cookies
Required Accept and Reject buttons must be identical in size, colour weight, and prominence
Required If a visitor declines, the site cannot re-present the consent banner for at least 6 months
Required Zero cookies, localStorage, or fingerprinting before the user takes an explicit action
Banned Scrolling as consent. Dark patterns. Cookie walls. Pre-ticked boxes. (Ediscom: EUR 300K fine)
An illustration of an Italian cookie banner that fails the Garante's 2021 guidelines: a dominant Accetta tutti button, a buried reject option, and no X close button, annotated with the guideline requirements.
Recreated for illustration: the banner pattern that fails the Garante's 2021 guidelines twice over. No X that closes without consent, and a reject option that is anything but equally prominent.

The rules apply to all trackers, not just cookies. Local storage, fingerprinting, pixel tags, device identifiers. If it reads from or writes to the visitor's device, consent is required under Article 122.

An Aarhus University study of 8,666 Italian websites found that 76% had consent interfaces, but only 23% were compliant with the Garante's requirements. In plain English: 3 banners in 4 exist, but only 1 in 4 is legal. 90% had an Accept button, but only 55% offered any reject option at all. And the reject buttons that did exist were measurably less prominent than the accept buttons. Most Italian cookie banners look compliant at a glance. They aren't. Our cookie banner decision flowchart walks through the compliance checks most Italian sites miss.

The analytics exemption

An illustration of the Google Analytics 4 Admin Tag Settings page in Italian, with four diagonal red 'FAILS GARANTE EXEMPTION' stamps on four settings cards: Anonimizzazione IP (Attivato), Misurazione cross-dominio (with redacted cross-domain entries), Segnali Google (Attivato), and ID utente / User-ID (Attivato). An annotation reads 'Italy's exemption condition 1: IP masking. GA4 truncates the last IPv4 octet, but Google receives and processes the full IP before truncation. The Garante 2022 ruling held this insufficient.' Another reads 'Italy's exemption condition 3: no third-party data sharing. Google Signals feeds GA data into Google Ads, DV360, and Display Network targeting. Fails.' A third reads 'Italy's exemption condition 4: aggregated output only. The User-ID feature tracks individuals across sessions and devices. Combined with condition 2 (cross-domain Client ID), GA fails all four conditions of the Garante's 2021 exemption.'
Recreated for illustration: what disqualifies GA from Italy's analytics exemption. All four Garante conditions fail in the very settings page where they live.

Italy allows analytics cookies to be treated as technical cookies (exempt from consent) if they meet four conditions:

  1. IP masking. At least the fourth octet of IPv4 addresses must be masked before any processing. The Garante notes this creates only 0.4% uncertainty, the minimum acceptable threshold.
  2. Single-site scope. Analytics must produce aggregate statistics for a single website or app. No cross-site tracking.
  3. No third-party data sharing. Your analytics data stays between you and your tool. It can't be combined with other data the provider holds.
  4. Aggregated output only. It must be impossible to identify individual users from the collected data.

Unlike France, which maintained a formal list of approved tools (now transitioning to self-assessment), Italy takes a principles-based approach. There's no official list. Any tool that meets the four conditions qualifies. I prefer this model: it is simpler. You don't need to wait for DPA approval. You configure your tool correctly, document compliance, and operate without consent for analytics.

Google Analytics fails all four conditions. Google can cross-reference truncated IP addresses with other data it holds. It processes data across millions of properties. It feeds into Google's advertising ecosystem. The Garante said this explicitly in its 2022 ruling.

Cookieless analytics tools that don't set cookies, don't track users across sites, and don't share data with third parties meet Italy's exemption by design. Clickport falls into this category: first-party data collection, no cookies, no cross-site tracking, no third-party data sharing. For a broader overview of how this model works across the EU, see our privacy-friendly analytics guide.

Google Analytics: the status in Italy

An illustration of a generic Italian news website with Chrome DevTools docked underneath showing the Network panel during page load. The site brand is blurred. Three Google requests are highlighted red: gtm.js at 380ms, gtag/js at 510ms, g/collect at 640ms. A Cookies tooltip lists _ga, _gid, and _ga_XXXXXXXX on .google-analytics.com. An annotation reads 'Caffeina Media S.r.l., the case that started this. Garante ruling June 9, 2022, 90 days to comply. 82% of Italian websites still ran GA nine months later. Highest non-compliance rate in the EU (France 74%, Austria 66%).' Another reads 'The DPF is the only thing keeping this legal in 2026. PCLOB lost quorum January 2025. FISA 702 sunsets April 2026. The CJEU will review the DPF challenge in late 2026. (Annotation reflects the situation as drawn; see caption for the July 2026 update.)' A third reads 'If the DPF falls, the Garante does not need a new investigation. The precedent is set. Article 122 of the Codice Privacy penalty: up to EUR 20 million or 4% of global turnover.'
Recreated for illustration: what most Italian GA installs still look like. One correction to this graphic's annotations: FISA 702 lapsed in June 2026 rather than sunsetting in April, with existing certifications running to roughly March 2027.

On June 9, 2022, the Garante declared Google Analytics unlawful. The case, originating from one of noyb's 101 coordinated complaints filed in August 2020, found that Caffeina Media S.r.l.'s use of Google Analytics transferred personal data to the US without adequate safeguards. The Garante gave 90 days to comply. No monetary fine was issued.

82% of Italian websites still had Google Analytics installed nine months later. That means 4 sites in 5 ignored the ruling. The highest non-compliance rate of the three countries studied (France: 74%, Austria: 66%).

Then the EU-US Data Privacy Framework was adopted in July 2023. Google is DPF-certified. The specific transfer objection from the 2022 ruling is, for now, addressed. GA data transfers to the US are currently legal.

But "currently" is doing a lot of work.

Google Analytics legal status in Italy: timeline
Jul 2020
CJEU strikes down Privacy Shield (Schrems II). US data transfers lack legal basis.
Aug 2020
noyb files 101 complaints across EU, including complaints filed with the Italian Garante.
Jun 2022
Garante declares Google Analytics unlawful. Orders Caffeina Media to comply within 90 days.
Jul 2023
EU-US Data Privacy Framework adopted. Google certified. Transfers temporarily legal.
Jan 2025
Trump fires all Democratic PCLOB members. The privacy oversight board loses quorum.
Sep 2025
The EU General Court dismisses Latombe's challenge (T-553/23). The DPF survives its first judicial test.
Oct 2025
Latombe appeals to the CJEU. The court that struck down Safe Harbor and Privacy Shield will review the DPF.
Jun 2026
FISA Section 702 lapses after a 45-day extension. Existing certifications keep collection running until roughly March 2027.

The DPF is under simultaneous pressure from three directions. The CJEU has struck down both prior frameworks (Safe Harbor in 2015, Privacy Shield in 2020). Norway's Datatilsynet has warned that if the DPF is revoked, "there will most likely not be a transition period." Max Schrems has said the European Commission may need to "pause or stop the deal on its own."

If the DPF falls, the Garante has already banned Google Analytics once. It wouldn't need to start a new investigation. The precedent is set.

Notable enforcement actions

Garante's largest GDPR fines
Enel Energia SpA
9,300+ unauthorized contracts via rogue telemarketing agents (Feb 2024)
EUR 79.1M
TIM SpA (Telecom Italia)
Millions of unsolicited calls, one person contacted 155 times in a month (Jan 2020)
EUR 27.8M
Clearview AI
Web-scraped 10+ billion facial images for biometric database (Mar 2022)
EUR 20M
Wind Tre SpA
Forced consent for marketing/profiling/geolocation in mobile apps (Jul 2020)
EUR 16.7M
OpenAI (ChatGPT)
No legal basis for training, unreported data breach, no age verification (Dec 2024; annulled on jurisdiction grounds Mar 2026)
EUR 15M
Italy ranks second in the EU by number of enforcement actions, behind only Spain. Which means Rome out-enforces everyone but Madrid. Sources: CMS Enforcement Tracker, EDPB

The Garante's cookie enforcement has been lighter than France's CNIL in monetary terms, but the Ediscom dark patterns case (EUR 300,000, February 2023) set an EU precedent: it was the first time any DPA formally sanctioned dark patterns as a standalone GDPR violation. Cookie compliance was named a priority inspection area for the second half of 2024.

What's coming

The EU Digital Omnibus. The Digital Omnibus would codify Italy's existing analytics exemption across all 27 EU member states.

The DPF is under active legal challenge. If it falls, the Garante has already banned Google Analytics once. It wouldn't need a new investigation.

Garante's 2026 inspection plan. At least 40 targeted inspections are planned for the first half of 2026, supported by the Guardia di Finanza. That means better than 1 inspection a week. Priority areas include telemarketing in the energy sector, AI tools in education, anonymization techniques, and whistleblowing systems. Cookie compliance isn't explicitly named as a 2026 priority, but the Garante's pattern of continuous enforcement suggests it remains on the radar.

Check your own site
See what your site loads before consent.
Paste your URL into the free GDPR checker. It reads your page source, identifies every tracking script, and checks whether each one is gated behind consent, the inventory the Garante's cookie guidelines expect you to know. No signup, about thirty seconds.
Scan your site for trackers →

What this means for your website

If you're using Google Analytics with a cookie banner: Make sure your banner meets the Garante's 2021 requirements. Equal-prominence Accept and Reject buttons. X button that defaults to no cookies. No re-prompting for six months after refusal. And have a contingency plan for the day the Data Privacy Framework falls. The Garante has already ruled GA illegal once. A free scan of your site shows whether your scripts respect the banner or fire before it.

If you're using Google Analytics without a cookie banner: You are violating Article 122 of the Codice Privacy. GA doesn't qualify for Italy's analytics exemption. The penalty is up to EUR 20 million or 4% of global turnover.

If you want analytics without the consent dependency: A cookieless tool that meets Italy's four exemption conditions sees nearly every visitor from day one. No banner. No data loss. No DPF dependency. See how it works, and compare the leading tools that meet these conditions in our GA alternatives breakdown.

A closing note, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or source it came from. If your setup is complicated, show this to your DPO or lawyer.

And if you're weighing an Italian analytics decision right now and something here doesn't match what you're seeing, email me.

David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment