Practical guide

How to draft a complaint to the Italian DPA with AI

4 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The complaint to the Italian Data Protection Authority (Garante per la protezione dei dati personali) is the administrative remedy provided by Art. 77 of the GDPR, allowing data subjects to report violations of data processing regulations. This procedure, also governed by Art. 142 of Legislative Decree no. 196/2003, does not require prior exercise of rights with the controller, operating as a direct and immediate right of action. The primary function of the complaint is to activate the supervisory authority's investigative and corrective powers to terminate unlawful conduct. Using AI facilitates the logical structuring of facts and the correct legal framing of the reported case.

In brief

A complaint to the Italian DPA under Art. 77 GDPR and Art. 142 Privacy Code represents a free, direct right of action. This administrative remedy invokes the corrective powers of Art. 58 GDPR to halt unlawful processing. AI facilitates the extraction of controller data from public registries, the chronological summarization of facts, and the legal mapping of violations under Art. 5 and Art. 6 GDPR. Submission requires a digital signature and transmission via PEC. The Authority must provide status updates within three months, with judicial recourse available under Art. 78 GDPR.

The steps

  1. 1.

    Identification of parties and contact details

    The first step consists of precisely identifying the complainant, the data controller, and any data processor. Through AI, it is possible to automate the extraction of the controller's identification data from public registries or privacy policies, ensuring that notifications are correctly addressed. It is necessary to provide certified email (PEC) addresses for communications, an essential element for managing the administrative procedure. Correct identification of the parties prevents preliminary objections regarding lack of passive legal standing.

  2. 2.

    Chronological statement of facts with AI summarization

    The statement of facts must clearly and concisely outline the circumstances under which the violation occurred, specifying times, places, and methods of the unlawful processing. The use of AI enables the summarization of extensive documentation into a coherent timeline of events, highlighting conflicts with current regulations. It is necessary to detail whether the violation concerns a failure to respond to a request or processing carried out without a legal basis. A precise factual reconstruction minimizes the risk of requests for clarification or further information from the Authority.

  3. 3.

    Legal framework and alleged violations

    In this phase, the provisions of the GDPR or the Privacy Code alleged to have been violated must be identified, such as the general principles under Art. 5 or the lawfulness conditions under Art. 6. AI supports the practitioner in mapping the described facts onto the relevant legal framework, suggesting the most pertinent statutory citations. It is essential to link each factual assertion to a specific infringement of a data subject's right to ensure the complaint is actionable. Referencing Art. 57 of the GDPR helps define the DPA's mandates in the specific case.

  4. 4.

    Formulation of the prayer for relief and corrective requests

    The complainant must specify the remedies requested from the Authority, such as an order to cease processing, data rectification, or restriction. With the support of AI, specific requests based on the corrective powers provided for in Art. 58 GDPR can be drafted and tailored to the severity of the identified violation. Financial compensation for damages cannot be claimed directly through this process, as it falls under the exclusive jurisdiction of the ordinary courts. Clear and precise requests facilitate the adoption of urgent or corrective measures by the Authority.

  5. 5.

    Verification of attachments and filing methods

    The complaint must be accompanied by all documentation suitable for proving the asserted facts, such as email exchanges, screenshots, or privacy notices. AI can assist in compiling a detailed index of exhibits, verifying the consistency between the evidence attached and the alleged violations. The complaint must be signed with a digital signature or handwritten signature accompanied by a copy of an identity document, and submitted via certified email (PEC) to protocollo@pec.gpdp.it. Failure to follow the prescribed submission methods may result in the inadmissibility of the act due to formal defects.

Legal basis: art. 77 GDPRart. 142 D.Lgs. 196/2003art. 57 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Addressed Authority

    Identification of the competent authority, namely the Italian Data Protection Authority located in Rome.

  2. Parties

    Identification and contact details of the complainant and the data controller responsible for the violation.

  3. Statement of facts

    Detailed and chronological account of the circumstances and methods of the contested data processing.

  4. Alleged violations

    Analysis of the specific GDPR and Privacy Code provisions violated and the data subject rights infringed.

  5. Relief requested

    Specific indication of the corrective, injunctive, or sanctioning measures requested from the Authority.

  6. Exhibits and attachments

    Numbered list of documents and evidentiary material submitted in support of the claims.

  7. Date and signature

    Signature of the document by the data subject or appointed counsel with power of attorney, including election of domicile.

Mistakes to avoid

  • Failure to attach a valid ID document when using a handwritten signature, leading to the inadmissibility of the complaint.
  • Requesting financial compensation for damages, resulting in the specific request being declared inadmissible as it falls outside the DPA's powers.
  • Vagueness in the statement of facts or failure to properly identify the data controller, preventing the initiation of the investigation.
  • Submitting the complaint through unofficial channels or methods lacking legal validity, resulting in a procedural bar to the case.

Frequently asked questions

Does filing a complaint with the DPA require the payment of a court fee (contributo unificato)?

No, submitting a complaint under Art. 77 of the GDPR is free of charge and does not require the payment of court fees or taxes, unlike judicial proceedings. This lack of cost aims to guarantee easy access to personal data protection for all data subjects.

Is it necessary to contact the data controller before filing a complaint?

No, under the GDPR, filing a complaint under Art. 77 is a direct right of action and is not subject to the prior exercise of rights with the controller. The data subject may freely choose whether to seek an amicable resolution or proceed directly to the Authority.

What remedies are available if the DPA fails to respond within the prescribed time limits?

The Authority must inform the data subject of the status or outcome of the complaint within three months. In the event of inaction, the data subject may lodge a judicial appeal against the Authority itself under Art. 78 GDPR to ensure effective administrative protection.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automated factual analysis for immediate identification of violations of Articles 5, 6, and 12-22 of the GDPR.
  • Generation of clauses based on the DPA's corrective powers by verifying compliance with Art. 58 GDPR.
  • Assisted filling of variable fields for controller and processor data extracted from verified sources.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free