The Italian Data Protection Authority, with provision no. 255 of 26 November 2020, has resolved to launch the public consultation procedure relating to the “Guidelines on the use of cookies and other tracking tools“. The relevant notice was published in the Official Journal of the Italian Republic on 11 December 2020 and will expire thirty days after publication.
The objective pursued by the Authority with the adoption of the Guidelines in question is to integrate and clarify specific aspects relating to the use of cookies and other tracking tools, as well as to specify the correct procedures for the preparation of the information and acquisition of consent of users online, where necessary, in compliance with the regulatory framework of reference, consisting of Directive 2002/58/EC (ePrivacy Directive) and subsequent amendments, as implemented in national law under Article 122 of Legislative Decree no. 196/2003 (hereinafter the “Code”), and the EU Regulation 2016/679 (hereinafter the “Regulation”). ePrivacy Directive) and subsequent amendments, as transposed into national law by article 122 of Legislative Decree 196/2003 (hereinafter the “Code”), and by Regulation (EU) 2016/679 (hereinafter the “Regulation”).
In view of the increasing use of new technologies, which make possible increasingly specific and detailed profiling of users, it is necessary to strengthen the protection of the rights of data subjects, encouraging their effective control over the personal information processed and their ability to self-determine.
In particular, with the Guidelines in question, the Authority has focused on the following issues:
- the definition and operation of cookies;
- the functioning of other tracking tools (so-called ‘active’ and ‘passive’ identifiers) and, in particular, among the passive tools, fingerprinting;
- the classification of cookies (technical and profiling) and other tracking tools (technical or commercial);
- the rules applicable to the use of technical cookies, in respect of which the data controller is exempt from the obligation to request the consent of the data subject since it is sufficient to provide the user with the information, even if this is part of the general information notice;
- the need for the prior informed consent of the person concerned for the use of profiling cookies and other tracking tools, pursuant to Article 122 of the Code;
- the unlawfulness, in the absence of the conditions indicated by the Authority, of the use of so-called scrolling and cookie walls in the online acquisition of the user’s consent;
- the redundant and invasive nature of the repeated request for consent through banners every time the user accesses the same site unless one or more of the conditions under which consent was collected have changed;
- the opportunity for updates and improvements in the way consent is obtained online via a banner, in accordance with the principles of privacy by design and privacy by default;
- the use of data minimization measures in order to reduce the identification power of analytics cookies, when used by “third parties”, avoiding that their use leads to the direct identification of the person concerned (so-called single out);
- further information to be provided in the information notice in compliance with the transparency requirements imposed by Articles 12 and 13 of the Regulation, including the indication of other possible recipients of the personal data and the retention periods of the information acquired, and the possibility of providing the information notice not only through several levels (multilayer) but also through several channels and methods (so-called multichannel);
- in relation to the semantic coding of cookies and other tracking tools, the indication, by the data controllers, of the criteria for coding the identifiers adopted, such as to make it possible to distinguish between the different types of cookies, thus supplementing the information provided to users.
For further details on the above, please refer to the Guidelines and the relevant Summary Sheet adopted by the Italian Data Protection Authority. Please note that any comments may be forwarded within the above-mentioned deadline to the e-mail address
