Shopify privacy law · Italy
Shopify cookie consent in Italy
Italy's Garante is one of the most active EU regulators. April 2026 €12.5M fine against Poste Italiane specifically for cookie-banner failures. First layer must offer both Accept AND Reject (or an 'X' close button treated as reject), plus granular controls with named third parties.
Governing law: GDPR + Italian Data Protection Code (D.lgs. 196/2003, amended)
Enforcement reality
The Garante per la Protezione dei Dati Personali (GPDP) publishes detailed provvedimenti (rulings) that other EU DPAs often follow. Its June 2021 cookie guidelines set the current EU floor: Accept + Reject on the first layer with equal prominence, granular per-category toggles behind a Preferences link, and named third-party recipients. The April 2026 €12.5M fine against Poste Italiane cited failure to provide granular controls and the absence of a clearly-labeled Reject option on the first layer. The Garante has confirmed it treats US-based ecommerce selling to Italian consumers as within its jurisdiction — geo-blocking is not a defence.
Regulator: Garante per la Protezione dei Dati Personali (GPDP)
Recent enforcement actions
- Poste Italiane·2026·€12.5M
Cookie banner failed to offer granular controls; Reject option not clearly labeled on first layer
- Enel Energia·2022·€26.5M
Unlawful telemarketing based on data acquired without consent
- TIM·2020·€27.8M
Aggressive marketing calls without valid consent
What Shopify merchants must do in Italy
- Accept AND Reject on the first-layer banner (or 'X' close button treated as reject — Garante 2021 guidelines)
- Granular per-category controls behind a Preferences link, not buried in the policy
- Named third-party recipients — not just 'partners' or 'marketing tools'
- Privacy policy in Italian if you target Italian customers
- Consent renewed no more than every 6 months (Garante default)
- DSAR response within 30 days, free of charge for first request
- Right-to-object honoured immediately for direct marketing
How Consentico handles Italy
Consentico's geo-targeting detects Italy visitors at the edge and applies the right banner — opt-in posture for EU/UK rules, with Google Consent Mode v2 signals and a per-decision audit log. The banner survives Shopify theme switches and uninstalls cleanly.
Related concepts
- GDPREU regulation governing how organisations process personal data of EU/EEA residents. Applies to any Shopify store with EU visitors.
- ePrivacy DirectiveEU directive (2002/58/EC, amended 2009) requiring opt-in consent for cookies and similar storage. Enforced together with GDPR.
- Consent (GDPR)Freely given, specific, informed, and unambiguous indication of agreement. No pre-checked boxes, no implied consent from continued browsing.
- DSARData Subject Access Request — when an EU/UK resident asks you for a copy of, or deletion of, their personal data.
Compliant in Italy — in five minutes.
Free for stores under 5,000 banner views per month. No code, no theme edits.