Categories: Insights, Practice

Tag: Cookies, data protection, Garante Privacy


27 Jul 2021

Cookies and other tracking tools: the new Data Protection Authority Guidelines

On 10 June, the Italian Data Protection Authority approved the new ” Cookie Guidelines.”The term cookie refers to a small text file that a website (publisher or “first party”) can autonomously send to the user’s device (e.g. Smartphone, PC or Tablet) when viewing a web page or different sites or web servers (“third parties”). Usually, cookies make it possible to store the preferences expressed by the user so that they do not have to be re-entered later. The browser saves the information and transmits it to the site’s server when the user visits that website again.

The Guidelines, adopted by the Data Protection Authority, considered what emerged during the public consultation promoted at the end of last year. The guidelines aimed to strengthen users’ decision-making power over the use of their data when surfing online.

Here are the main changes.

Privacy Policy

Under Regulation (EU) 2016/679 on the protection of personal data (better known as the “GDPR“), the policy to be issued to users/data subjects shall specify (i) possible recipients, (ii) the retention periods of personal data processed and (iii) a description of all the consequences of any action taken by the user/data subject.

The Data Protection Authority recommends that Analytics cookies, which the Data Controller uses to assess the effectiveness of a service, be used only for statistical purposes.

The multi-layer privacy policy is confirmed, with a banner (short policy) when accessing the site containing specific information on positioning, size, font and content, and a link to the extended policy.

The user/data subject must choose between consent or modulating their preferences on tracking and be provided with a link to another area to select the functions, third parties and cookies, possibly grouped by similar categories, to the use of which the user consents.

Consent by scrolling

The mere “scrolling down” of the page cursor is unsuitable for the collection of an appropriate consent to the installation and use of profiling cookies or other tracking tools by the data controller.

Given the controller’s autonomy in identifying the most appropriate solutions to achieve compliance with data processing regulations, the Data Protection Authority invites the controller to assess every possible solution rigorously. According to the Data Protection Authority, if the user action does not correspond to any unmistakable, documentable computer event with the mentioned features, including user awareness, it will be impossible to attribute the consent validity under applicable regulations.

Renewal of the consent request

Obtaining consent for cookies may not be repeated unless (i) the processing conditions change significantly, (ii) the site operator can’t record the user’s previous choice due to a user decision and (iii) at least six months have elapsed since the previous request.

Review of consents

Users/data subjects shall be provided with the ability to review choices made at any time and in a simple, immediate and intuitive manner. This can be done using a dedicated area made accessible through a link placed in the footer of the site that makes the function explicit and says “review your choices on cookies” or similar.

Website owners have six months to comply with the principles contained in the Guidelines.

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 marzo 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…

3 Mar 2026

Employee monitoring: when “bossware” becomes a legal risk (Agenda Digitale, 2 marzo 2026 – Martina De Angeli)

Monitoring workers through digital tools is a rapidly expanding practice, accelerated by the spread of remote work and the digital transformation of companies. Before adopting these systems, however,…

3 Mar 2026

Melismelis signs the campaign for the 50th anniversary of De Luca & Partners

For the historic labor law firm, the agency developed the 50th-anniversary logo and advertising campaign, managed online and offline media planning, and renewed the website’s visual identity. Milan,…

27 Feb 2026

Dismissals: the Corte costituzionale grants broader discretion to judges and greater scope for reinstatement (I Focus del Sole 24 Ore, 26 febbraio 2026 – Vittorio De Luca e Alessandra Zilla)

The regulation of dismissals continues to represent one of the central pillars of Italian labour law, an area of constant tension between freedom of economic initiative and the…