The short answer
Cold email into Italy needs the recipient's prior consent. That rule is Article 130 of the Italian Privacy Code, legislative decree 196/2003, and since 2012 it has covered companies as well as individuals. There is no business-to-business carve-out and no legitimate interest route around it.
The surprise is what Italy allows instead. A live operator call to a number in a public directory that is not on the national opposition register is permitted, and the Italian regulator has said in writing that you may make that call specifically to ask for consent to email. Italy is one of the few places in Europe where the phone is the permissive channel and the inbox is the restricted one.
This is a plain-English summary of published law and published decisions, not legal advice. Have an Italian lawyer review your specific setup before you run a campaign.
What Article 130 actually says
Article 130 is headed "Comunicazioni indesiderate", unwanted communications. Paragraph 1 says automated calling or communication systems used without an operator, for advertising, direct selling, market research or commercial communication, are permitted only with the consent of the "contraente o utente", the subscriber or user. Paragraph 2 extends that same rule to electronic communications sent by email, fax, MMS or SMS.
Paragraph 3 handles everything else: communications sent by other means fall under GDPR Articles 6 and 7 and under paragraph 3-bis, the opt-out regime run through the public opposition register. That is the split that matters. Email is opt-in, the operator-assisted call is opt-out.
Two further paragraphs are widely ignored. Paragraph 5 bans promotional messages that conceal the sender's identity, and bans sending them without a suitable address at which the recipient can exercise GDPR Articles 15 to 22. Paragraph 6 lets the regulator, on repeated breaches, order communications providers to filter the addresses you sent from.
The regulator's own route in starts with a call
In its guidelines on marketing and spam of 4 July 2013, the Garante set out the sequence. Subscribers listed in telephone directories who have not signed up to the opposition register "may be contacted via operator-assisted phone calls to ask for the contracting parties' consent to receiving promotional communications by way of the mechanisms mentioned in Section 130(1) and (2) of the Code".
That inverts the standard playbook. The lawful way to earn the right to email an Italian prospect is to ring them first and ask. Most European guides treat email as the safe opener and the phone as the regulated channel; Italy runs the other way, and on purpose, because a live call is treated as less intrusive than an automated message.
The practical consequence is that Italy rewards a conversation-led motion and punishes a volume-led one. If you already run AI voice agents or a human calling desk, that capability is worth more here than your sending infrastructure is.
Companies are covered, and named inboxes bite hardest
Decree 201/2011, converted into law 214/2011, stripped companies out of the data subject definitions with effect from 6 December 2011, and for a few months companies really were freely emailable. That closed on 1 June 2012. Legislative decree 69/2012 replaced the word "interessato" in Article 130 with "contraente o utente", and the definition of "contraente" in Article 4.2.f expressly covers any natural person, legal person, body or association. The Garante confirmed the position in a general decision of 20 September 2012, published in the Gazzetta Ufficiale on 16 November 2012, holding that Chapter 1 of Title X continues to apply to legal persons and associations.
So the generic company mailbox is protected. But the enforcement routes are not symmetrical, and that is what decides your real risk. A company is no longer a data subject, so it cannot complain to the Garante. It can sue for an injunction or damages, file a criminal report, and the Garante can act on its own initiative. An individual can do something far cheaper and faster: complain to the regulator for free.
And the Garante has already ruled on which inboxes belong to individuals. Its 2013 guidelines state that an account in the form [email protected] is a personal email account and its holder a data subject, following Article 29 Working Party Opinions 4/1997 and 5/2004. So info@ carries a slow, expensive remedy while mario.rossi@ carries a fast, free one. The addresses your sequencer prefers are the ones with the shortest path to a regulator.
Public does not mean usable, and INI-PEC is out
The 2013 guidelines are unambiguous: promotional communications may not be sent by these means without prior consent, "not even if the personal data have been taken from publicly available sources, directories, web sites, records or documents". The Garante traces that back to its spam decision of 29 May 2003 and has repeated it in 2021, 2023 and 2024.
The same guidelines close the single most tempting list in Italy. INI-PEC, the national register of certified email addresses for companies and professionals created by decree 179/2012, may not be used to send promotional email without prior consent. It exists so that businesses and professionals can exchange documents with public administration, and that purpose limits what you may do with it.
The guidelines add one more constraint that quietly rules out a common workaround. You may not use a first promotional message to tell recipients they can object, and you may not use it to ask for consent. Bundling the permission request into the pitch does not launder the pitch.
The one exception, and the conditions on it
Article 130.4 contains Italy's soft opt-in, and it is narrower than the version most teams have in mind. The controller may email without consent only where all of the following hold.
- It is selling its own products or services.
- The email address was provided by the person in the context of the sale of a product or a service. A whitepaper download or a webinar signup is not a sale.
- What is being offered is analogous to what was sold.
- The person was adequately informed and did not refuse the use, either at the outset or on any later message.
- The right to object is presented at collection and in every single message, easily and free of charge.
There is a drafting asymmetry worth putting to your lawyer. Paragraphs 1 and 2 were widened in 2012 to "contraente o utente" so they would catch companies. Paragraph 4 still reads "interessato". The prohibition was extended to legal persons; the exemption was not rewritten to match.
The 2026 case that priced the wrong thing
On 12 February 2026 the Garante decided a complaint against Lex Iuris S.r.l. of Bologna, a legal training company. Two lawyers had each received one unsolicited promotional email on 25 November 2024. Their addresses had been taken from public sources to consider them as possible teaching collaborators, then put on a marketing list by what the company called human error, because the two shared a surname.
The Garante rejected the excuse. Data gathered to propose a professional collaboration should have been kept apart from marketing lists, because lists built for marketing must come from sources capable of documenting that a valid consent was given. It found a breach of GDPR Article 6.1.a and Article 130.2 of the Code. Then, because there was no damage, one email each, no follow-up and a small company, it classified the unlawful emailing as a minor infringement under GDPR Article 83.2 and recital 148, issued a reprimand, and imposed no fine at all for the emails.
The 15,000 euro fine was for something else entirely. Both recipients had also asked for access to their data and never got a reply. That failure, under GDPR Articles 12 and 15, is what got priced, at 0.075 per cent of the 20 million euro statutory maximum. The Garante called it grossly negligent, noted the requests had gone to both the ordinary mailbox and the certified PEC address, and reaffirmed the thirty day response window.
The lesson is not the one most outbound teams expect. In Italy, sending the wrong email cost nothing. Ignoring the reply cost fifteen thousand euros.
The reply address you are required to publish
Put Article 130.5 and the February 2026 decision side by side and a concrete obligation appears. The statute requires every promotional message to carry a suitable address at which the recipient can exercise GDPR Articles 15 to 22. The most recent enforcement in this area fined a company for not answering exactly those requests.
An unsubscribe link is not that address. Rights requests cover access, rectification, erasure, restriction, portability and objection, and they need a monitored destination and a named owner. If you hold an Italian PEC address, watch it: the Garante treated an unwatched one as implausible rather than mitigating.
This is the cheapest compliance work in the whole programme, and it is the part most cold email operations never build.
How the opposition register works if you call
If you take the phone route, the Registro Pubblico delle Opposizioni is the gate. It sits under the Ministry of Enterprise and Made in Italy, it is free for subscribers, and it covers mobile numbers as well as fixed ones, with unlisted landlines transferred into it by default since December 2022. Operators must register, submit in advance the lists of numbers they intend to call, and receive them back within 24 hours flagged for objections and consent withdrawals. Access is paid, on tariffs the ministry sets annually.
Then comes the number that breaks naive processes. A scrubbed telemarketing list is valid for 15 days, or 30 for postal marketing. If your Italian calling list is older than a fortnight it is no longer scrubbed. Registration also wipes prior marketing consents, so only consent obtained after the registration date, or a contract in force or ended no more than thirty days ago, lets you call a listed number.
Penalties, and the filtering power nobody mentions
Breaches of Article 130 are sanctioned under GDPR Article 83.5, with a ceiling of 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher. Italian practice adds two wrinkles: under Article 166.8 of the Code you can settle within thirty days by paying half, and under Article 166.7 publication of the decision on the Garante's website can be added as an accessory sanction, as it was in February 2026.
The provision to actually fear is Article 130.6. On repeated breaches the Garante can direct electronic communications providers to apply filtering measures to the email addresses the messages came from. Every other penalty is money. That one is your deliverability, and it does not travel back with you when you switch domains inside the same operation.
What lawful outreach into Italy looks like
A defensible Italian motion looks less like a sequence and more like a sales process.
- Open on the phone, not in the inbox. Use publicly listed numbers, screen them against the opposition register, and re-screen every 15 days.
- Use the call to ask for permission, then log what was said, by whom, and when. Written proof of consent is the standard, so a CRM note that survives an audit is the deliverable.
- Do not buy or scrape Italian lists. The test is not whether the data was public, it is whether the source can document consent. Almost no vendor list can.
- Leave INI-PEC alone.
- Publish a real rights address in every message and give someone the job of answering within thirty days.
- Treat named inboxes as higher risk than generic ones, which is the reverse of the usual instinct.
Italy is not a market to run on volume, and the February 2026 decision says why: the send was free and the silence was expensive. For the neighbouring regimes see our guides to Spain, France and Germany, and the GDPR compliance guide for the data layer underneath them. If you would rather have the calling and consent capture built for you, that is what our lead generation team does.
Frequently Asked Questions
Not without prior consent. Article 130.2 of the Italian Privacy Code, legislative decree 196/2003, allows promotional email only where the recipient has consented, with one narrow exception in Article 130.4 for a controller emailing its own existing customers about analogous products. There is no business-to-business exemption, and the Garante has repeatedly held that data being publicly available does not create a right to use it for marketing.
Article 130 covers them. Since 1 June 2012 the article has protected the contraente o utente rather than only the data subject, and the definition of contraente expressly includes legal persons, bodies and associations. The Garante confirmed this in a general decision of 20 September 2012. The practical difference is the remedy: a company cannot lodge a complaint with the Garante and must go to the civil or criminal courts, whereas a named individual can complain to the regulator for free.
Yes, within limits, and this is the unusual part of Italian law. The Garante's 2013 guidelines on marketing and spam state that subscribers listed in telephone directories who are not registered with the public opposition register may be contacted by operator-assisted phone calls in order to ask for their consent to receive promotional communications by the means covered in Article 130.1 and 130.2. You must screen against the register first, and a screened telemarketing list stays valid for only 15 days.
No. Article 130 is a specific rule that requires consent for promotional email, and it is not displaced by a GDPR Article 6.1.f balancing test. In its decision of 12 February 2026 the Garante found a breach of both GDPR Article 6.1.a and Article 130.2 where promotional emails were sent to addresses taken from public sources without consent and without any other suitable legal basis.
No. INI-PEC is the national register of certified email addresses for companies and professionals, created by decree 179/2012. The Garante's 2013 guidelines state that these addresses may not be used to send promotional email without prior consent, because the register exists to support the exchange of documents between public administration and businesses, and that purpose limits how the addresses may be reused.
The statutory ceiling is the GDPR Article 83.5 maximum of 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher, and Article 166.8 of the Italian Code lets you settle within thirty days by paying half. Actual outcomes vary widely. In the 12 February 2026 Lex Iuris decision the unlawful emails drew only a reprimand as a minor infringement, while a 15,000 euro fine was imposed for failing to answer the recipients' access requests under GDPR Articles 12 and 15.