Practical guide
How to draft a complaint to the Italian Data Protection Authority with AI
2 min read · Updated May 2026 · Editorial oversight: Avv. Federico Papa
A complaint to the Garante is the primary remedy by which a data subject reports a violation of data protection law (Art. 77 GDPR and Arts. 140-bis et seq. of the Italian Privacy Code). An effective complaint clearly identifies the data controller, the contested processing operations, and the provisions violated.
In brief
A complaint under Art. 77 GDPR and Arts. 140-bis of the Italian Privacy Code reports data protection violations to the Garante. Effective drafting requires identifying the controller, reconstructing facts chronologically, and attaching evidence like responses to requests under Arts. 15-22 GDPR. Admissibility depends on the absence of pending court actions. The procedure links factual allegations to violations of Arts. 6, 13, 14, or 32 GDPR to obtain corrective measures under Art. 58 GDPR. AI speeds up the drafting of the official template submitted via certified email.
The steps
- 1.
Check the prerequisites
Confirm that the contested processing concerns the data subject's personal data and that no court action is pending on the same matter between the same parties (Art. 140-bis Privacy Code).
- 2.
Identify controller and processing
Identify the controller (and any processor), describe the contested processing in detail, and reconstruct the facts chronologically, attaching relevant evidence (emails, privacy notices, responses to requests under Arts. 15-22 GDPR).
- 3.
Identify the violated provisions
Link each factual allegation to the specific provision violated: missing legal basis (Art. 6), defective privacy notice (Arts. 13-14), failure to respond to data subject requests (Arts. 15-22), or security breaches (Art. 32).
- 4.
State the requests
Request the Garante to adopt corrective measures under Art. 58 GDPR (e.g. processing ban, compliance order, administrative fine) and submit the complaint via the official DPA template or certified email (PEC).
Legal basis: art. 77 GDPRart. 140-bis d.lgs. 196/2003art. 58 GDPR
What edit.legal automates
- —Reconstructs the legal framework with verified citations (GDPR, Privacy Code, Garante decisions)
- —Generates the complaint structure with logically linked facts, violations, and remedies
- —Cross-checks every citation against official databases prior to filing
Put edit.legal to the test on actual cases
Try edit.legal for free on an active case. No credit card required.
Try edit.legal for freeThis guide is for informational purposes only and does not constitute legal advice for your specific case.