Practical guide
How to file a report to the Privacy Authority with AI
5 min read · Updated May 2026 · Editorial oversight: Avv. Federico Papa
The report (segnalazione) to the Data Protection Authority is a key instrument for participation and oversight provided for by Art. 144 of D.Lgs. 196/2003, as amended by D.Lgs. 101/2018. This act allows any person to submit facts or circumstances to the Authority that constitute a violation of current data protection laws. Unlike a formal complaint (reclamo), a report can address general non-compliance, encouraging the Authority to exercise its ex officio powers under Art. 57 and 58 of the GDPR. This submission initiates an administrative procedure governed by the Authority's Regulation no. 1/2019.
In brief
The report to the Italian Data Protection Authority, provided by Art. 144 of D.Lgs. 196/2003, enables the submission of GDPR or Privacy Code violations. Unlike the formal complaint, this tool is free and does not require direct personal harm, activating ex officio powers under Art. 57 and 58 of the GDPR. AI assists in the chronological reconstruction of facts and the identification of non-compliance. The procedure, governed by Regulation no. 1/2019, requires data controller identification and documentary evidence, submitted via PEC or registered mail with a digital signature.
The steps
- 1.
Assessment of legal grounds
A report can be filed by anyone observing a violation, without the need to prove direct personal harm as required for a formal complaint. It must be verified that the contested processing falls within the scope of the GDPR or the updated Italian Privacy Code. The subject of the report must be detailed and concern specific conduct, including systemic practices, carried out by a data controller or processor. It is advisable to preliminarily assess whether the conduct violates the principles of lawfulness, fairness, and transparency set forth in Art. 5 of the GDPR. The use of AI through targeted prompts can assist in quickly identifying the legal references between Art. 144 of the Code and the GDPR.
- 2.
Identification of the parties
The document must contain the full identification details of the reporter and the elements necessary to uniquely identify the data controller or data processor. It is necessary to indicate the company name, registered office, or address of the reported party to allow the Authority to start the investigation. If the reporter requests confidentiality regarding their identity, they must explicitly state the reasons, bearing in mind that the Authority must still guarantee the counterpart's right of defense. The lack of identification data for the controller may render the report inadmissible due to the impossibility of proceeding.
- 3.
Detailed description of facts
An analytical narration of events must be provided, specifying times, places, and methods of the data processing deemed unlawful. It is fundamental to attach any available documentary evidence, such as screenshots, emails, system logs, or contracts, to provide objective confirmation. The description must not be vague but must allow the Authority to understand exactly which processing operation is being complained about. A precise factual reconstruction is necessary to allow the office to exercise the investigative powers provided by Regulation no. 1/2019. AI tools can be used to chronologically summarize the facts starting from the collected documentation.
- 4.
Identification of non-compliance
The professional must link the stated facts to violations of the GDPR or the Privacy Code, explicitly citing the provisions assumed to be breached. Although the Authority performs its own legal assessment, solid technical reasoning facilitates the acceptance of the report and guides the oversight activity. It must be highlighted whether the violation concerns the lack of a proper legal basis, failure to provide notice, or non-compliance with data subject rights. The analysis should take into account the case law and guidelines of the European supervisory authorities. Through specific prompts, AI can support the identification of specific violations based on the description of the facts.
- 5.
Request for Authority intervention
In this phase, the Authority is formally requested to exercise the corrective and punitive powers under Art. 58 of the GDPR. One can request measures such as reprimands, orders to bring processing into compliance, or a temporary or definitive ban on data processing. It is useful to specify the urgency of the intervention if the unlawful processing risks causing serious and irreparable harm to the community or categories of data subjects. The request must be formulated consistently with the powers granted by law to avoid improper or excessive petitions.
- 6.
Submission and signature
The report must be dated and signed by the reporter, preferably using a digital signature to guarantee its integrity and authorship. Submission must be via Certified Email (PEC) to the Authority's institutional address or via registered mail with return receipt. It is necessary to ensure that all attachments are in readable formats and that the size of the digital file does not exceed technical limits. Submission via PEC ensures legal certainty of the filing date. Pursuant to Art. 11 of the Authority's Regulation no. 1/2019, the office performs a preliminary admissibility assessment and decides whether to start the investigation, unlike a complaint where fixed time limits apply for informing the applicant (3 months to communicate the status or outcome pursuant to Art. 77 GDPR), which constitutes a fundamental difference compared to a report.
Legal basis: art. 144 D.Lgs. 196/2003art. 57 GDPRart. 58 GDPR
The template structure
The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.
Authority addressed
Indication of the office of the Italian Data Protection Authority competent for receiving the act.
Reporter and controller
Full identification details of the reporting party and the data controller or processor being contested.
Reported facts
Analytical description of the conduct or processing deemed non-compliant with current regulations.
Non-compliance profiles
Statement of the GDPR or Privacy Code provisions assumed to be violated by the described processing.
Request for oversight
Petition addressed to the Authority for the exercise of investigative and corrective powers under Art. 58 GDPR.
Date and signature
Place, date, and handwritten or digital signature of the reporter with contact details for communications.
Mistakes to avoid
- Requesting damages: the Authority does not have the power to award compensation, a jurisdiction that belongs exclusively to the ordinary courts.
- Failure to attach evidence: submitting a report based on mere conjecture without screenshots or documents usually leads to direct dismissal.
- Lack of specificity: formulating generic accusations without indicating the data processed or the violation methods makes it impossible to start an investigation.
- Submitting anonymous reports: although the Authority may act ex officio, anonymity prevents the reporter from receiving updates on the status of the procedure.
Frequently asked questions
Is there a cost or stamp duty for filing a report to the Authority?
While filing a report is free of charge, submitting a formal complaint to the Authority is subject to a 150.00 euro administrative fee, as established by the Authority's Deliberation no. 511 of 20 December 2018, except for specific exemptions.
What is the difference between a complaint and a report under the Privacy Code?
A complaint (reclamo, art. 77 GDPR) protects the data subject's specific rights, while a report (segnalazione, art. 144 Code) is a more flexible tool to report general violations, although it still initiates an administrative procedure.
Can the outcome of a report be challenged before a court?
Express decisions by the Authority are challengeable under Art. 152 of the Code. The challengeability of the Authority's 'silence' is regulated by Art. 78 of the GDPR regarding complaints; for a report under Art. 144, as there is no obligation to act specifically on the position of the reporter (who is not a data subject), the challengeability of silence under Art. 152 is controversial in scholarship and case law.

What edit.legal automates
- —Automatic verification of legal references between Art. 144 of the Privacy Code and GDPR provisions.
- —Guided structuring of the reported facts to ensure the precision required by Regulation no. 1/2019.
- —Automatic generation of intervention requests based on the exhaustive list of powers under Art. 58 GDPR.
Put edit.legal to the test on actual cases
Try edit.legal for free on an active case. No credit card required.
Try edit.legal for freeThis guide is for informational purposes only and does not constitute legal advice for your specific case.