- Garante: every controller notifies personal data breaches without undue delay and, where feasible, within 72 hours, unless the risk to individuals is unlikely (Art. 33 GDPR). Mandatory channel: the online procedure at servizi.gpdp.it.
- CSIRT Italia: essential and important entities notify significant incidents with an early warning within 24 hours, a notification within 72 hours and a final report within one month (Art. 25 Legislative Decree 138/2024).
- The critical point: the early warning to the ACN is made while the picture is still unclear, but it stays on file. The two accounts of events must be consistent from the start.
Why people talk about a "double track"
Italy's Legislative Decree 138/2024 (D.Lgs. 138/2024, the NIS decree) does not absorb the GDPR: Article 3(11) preserves the rules on personal data protection. When ransomware encrypts the servers of a healthcare company or a managed service provider, the same event can at the same time be a personal data breach (Art. 4(12) GDPR) and a significant incident under Article 25 of the NIS decree. The notifications go to two different authorities, with different legal bases, thresholds and forms.
As Agenda Digitale pointed out in August 2026, the practical risk is the time lag: the early warning to CSIRT Italia goes out within 24 hours, when the incident is still unclear, and that initial assessment can weigh on the Garante's later review. That is why the qualification criteria (who decides, on which thresholds, how the decision is documented, including the decision not to notify) need to be defined beforehand, not during the incident.
Comparing the two notifications
| Garante (GDPR) | CSIRT Italia / ACN (NIS2) | |
|---|---|---|
| Legal basis | Arts. 33 and 34 Regulation (EU) 2016/679 | Art. 25 Legislative Decree 138/2024; Annexes 3 and 4 of ACN Determination 379907/2025 |
| Who notifies | The controller (any organisation); the processor informs the controller | Essential and important entities on the NIS list, through the CSIRT contact |
| What | Personal data breach, unless a risk to rights and freedoms is unlikely | Significant incident: severe operational disruption or financial losses, or considerable losses for third parties (Art. 25(4)); in the initial phase the basic incidents IS-1, IS-2, IS-3 and, for essential entities, IS-4 |
| From when | From when the controller became aware of it | From when the entity became aware of the significant incident |
| Timelines | Without undue delay and, where feasible, within 72 hours; later, with the reasons for the delay. Preliminary + supplementary notification allowed | Early warning 24 hours · notification 72 hours · intermediate report on request · final report within 1 month of the notification · monthly reports if the incident is ongoing |
| Channel | Online procedure at servizi.gpdp.it (mandatory since 1 July 2021) | ACN / CSIRT Italia notification services listed on the Agency's website |
| Communication to others | To data subjects if the risk is high (Art. 34) | To service recipients, where appropriate and after consulting CSIRT Italia (Art. 25(9)) |
| Documentation | Register of all breaches, including those not notified (Art. 33(5)) | Incident management plan and notification procedures (measures RS.MA-01 and RS.CO-02) |
| Maximum fines | Up to €10 million or 2% of worldwide turnover (Art. 83(4)) | Essential up to €10 million or 2%; important up to €7 million or 1.4% (Art. 38(9)) |
Banks and financial market infrastructures follow the DORA Regulation for incident reporting: Chapter IV of Legislative Decree 138/2024 does not apply to these sectors (Art. 3(14)).
The timeline of an incident that triggers both tracks
- T0: awareness. Record the date and time: it is the starting point for all deadlines. Under the GDPR what counts is when the controller has a reasonable degree of certainty about the breach; under NIS, when the entity knows about the significant incident.
- By T0 + 24 hours: early warning to CSIRT Italia. State, where possible, whether the incident seems to be caused by unlawful or malicious acts and whether it may have cross-border impact. CSIRT Italia responds, where possible, within 24 hours.
- By T0 + 72 hours: notification to CSIRT Italia with an initial assessment, severity, impact and indicators of compromise, and notification to the Garante (preliminary if need be).
- Without undue delay: communication to data subjects if the risk is high; communication to service recipients where appropriate.
- Within one month of the NIS notification: final report with a detailed description, root cause, mitigation measures and cross-border impact; supplementary notification to the Garante once the picture is complete.
To calculate the 72-hour deadline precisely, use our breach deadline calculator.
What the Garante form asks
Since 1 July 2021, notifications can only be sent through the Garante's online procedure (decision of 27 May 2021, doc. web 9667201). On the same page the Garante publishes a facsimile form, not to be used for submission but useful for preparing your answers. The form is in Italian. Its sections are:
| Section | Content |
|---|---|
| Type of notification | Preliminary, complete or supplementary (referring to the previous file); Art. 33 GDPR or Art. 26 Legislative Decree 51/2018 |
| A. Person notifying | Surname, first name, email, phone, role |
| B. Controller | Name, tax code/VAT number, address, phone, email, PEC (certified email) |
| B1. Contact for information | DPO (with the reference number of the communication of contact details) or another contact |
| B2. Other parties involved | Joint controllers, processors, representative of a controller not established in the EU |
| C. Summary information | When it happened, when and how the controller became aware of it, reasons for any delay, brief description, nature (confidentiality, integrity, availability), cause, categories of data, volume of data, categories and number of data subjects |
| D. Detailed information | Underlying security incident, categories of data, IT systems and infrastructure involved and their location, security measures in place |
| E. Consequences and severity | Possible consequences by type of loss, potential adverse effects, estimated severity (negligible, low, medium, high) with reasons |
| F. Measures taken | Measures to remedy and reduce the effects; measures to prevent similar breaches |
| G. Communication to data subjects | Whether and when it was made, or why it will not be made (Art. 34(3)), number of recipients, content, channel |
| H. Other information | Data subjects in other EEA or non-EEA countries, notifications to other supervisory authorities or other regulatory bodies, report to judicial or police authorities |
Two details that matter on the double track: a preliminary notification requires at least sections A, B, B1 and C; and section H explicitly asks whether the breach has been notified to other regulatory bodies, so the notification to CSIRT Italia must be declared there too. The notification must not contain the breached personal data itself (for example the names of the data subjects).
List of fields taken from the Garante's facsimile form in the version in circulation on 1 October 2026; the online form may differ in detail. Always check at servizi.gpdp.it.
What to prepare before it happens
- A single qualification procedure that, for each event, decides and records the reasons: is it a personal data breach? Is it a NIS significant incident (IS-1…IS-4 or Art. 25(4))? Who signs off the decision?
- Defined roles: the CSIRT contact and deputies (designated on the ACN portal), the DPO, who has access to servizi.gpdp.it, who informs the board.
- Expected service levels (SL) already documented for services and activities (measure DE.CM-01), otherwise IS-3 cannot be assessed.
- A single incident register with timestamps for awareness and every submission, the Garante file numbers and CSIRT references, and the reasons for not notifying.
- Ready-made templates for the early warning, the Garante notification and communications to data subjects and customers, consistent with each other.
- Contracts with processors (Art. 28 GDPR) and suppliers that set reporting times compatible with the 24-hour NIS deadline.
Sources
- Regulation (EU) 2016/679 (GDPR), Arts. 4, 33, 34 and 83.
- Garante, Data breach page and decision of 27 May 2021 on the online procedure (in Italian).
- Legislative Decree 138/2024, Arts. 3, 25, 26 and 38 (Gazzetta Ufficiale General Series No 230 of 1 October 2024).
- ACN, basic specifications: Annexes 3 and 4 of Determination 379907/2025 (basic significant incidents, in Italian).
- EDPB, Guidelines 9/2022 on personal data breach notification under GDPR.
- Agenda Digitale, "Data breach, il doppio binario ACN-Garante che espone le imprese" (August 2026, in Italian).
Content checked as of 1 October 2026.