Italy - Web Scraping Guidance (329/2024)
Provision No. 329 (20 May 2024) - Informative Note on Web Scraping for the Purpose of Training Generative Artificial Intelligence (Data Protection Authority)
Provvedimento n.329 (20 May 2024) - Nota informativa su web scraping per finalità di addestramento di intelligenza artificiale generativa (Garante per la protezione dei dati personali)
Italy
RAI-IT-NA-PN2M2XX-2024Provvedimento n.329 (20 May 2024) is an informational note issued by the Italian data protection authority (Garante) addressing large-scale web scraping for the training of generative artificial intelligence (AI) models. It provides guidance for website and platform operators (including public bodies) on technical and organizational measures they may adopt to limit or prevent third-party scraping of personal data, while reaffirming data protection obligations under the EU GDPR and national law.
Summary
Provvedimento n.329, adopted by the Garante per la protezione dei dati personali on 20 May 2024 and published in the Gazzetta Ufficiale on 7 June 2024, is a 'Nota informativa' addressing the phenomenon of mass collection of personal data from websites and online platforms (web scraping) for the purpose of training generative AI models. The document does not itself create new prohibitions but provides practical guidance and possible countermeasures that site and platform operators — particularly those that are also data controllers under the GDPR — may consider to protect personal data published on their services from being harvested for AI training. The note stems from the Authority's mandate under Article 57(1)(b) GDPR to promote public awareness and understanding of data protection risks and safeguards.
Key elements: the note defines the web scraping activity targeted (mass, indiscriminate collection by automated bots intended to store data for later analysis and AI model training), highlights the scale and potential privacy impact (including risks to sensitive categories of data and minors), recalls prior decisions and case law (e.g., Clearview-related measures previously adopted by the Garante), and sets out a non-exhaustive catalogue of technical, organizational and contractual measures site operators may adopt. Recommended measures include creating gated or reserved areas (access by registration), tuning publicity/access/reuse regimes (particularly for public-sector websites subject to openness obligations), deployment of technical anti-scraping controls (robots.txt, rate-limiting, CAPTCHAs, IP blocking, anti-bot detection), contractual restrictions in terms of service and API licensing, and consideration of legal actions where scraping is incompatible with legal bases or specific requirements.
The note emphasizes that these measures must be balanced with legal obligations of controllers (e.g., transparency, access, open data obligations for public bodies) and must themselves respect data protection principles such as data minimization and proportionality. It recommends that controllers conduct case-by-case assessments (including Data Protection Impact Assessments where appropriate) and adopt appropriate security measures. Although the note focuses on guidance to controllers whose content is scraped (not on the legality of scraping per se), it signals that supervisory and enforcement tools remain available under the GDPR and national law where unlawful processing of personal data is identified. The Garante published the note alongside references and links to previous decisions and international material to facilitate further analysis by stakeholders.
Full article
Read full text ↗Overview
The Garante's Provvedimento n.329 of 20 May 2024, published in the Gazzetta Ufficiale on 7 June 2024, issues a "Nota informativa" concerning large-scale web scraping that collects personal data for the training of generative artificial intelligence (AI) systems. The note is addressed primarily to the managers of websites and online platforms (both public and private) that act as data controllers for content published on their services and therefore have responsibilities under the EU General Data Protection Regulation (GDPR). The document explains the phenomenon—described as mass, indiscriminate harvesting of data via automated bots for later storage and training of AI models—and presents a non-exhaustive set of possible countermeasures that controllers might adopt to protect the personal data they publish. The Authority stresses that the guidance does not amount to a blanket ban on scraping nor does it adjudicate the lawfulness of scraping activities per se; rather, it provides practical recommendations to balance openness and reuse obligations with the need to protect personal data. Full text and official publication references can be consulted at the official pages of the Garante and the Gazzetta Ufficiale: Garante - Provvedimento n.329 (doc web n.10020316) and Gazzetta Ufficiale - Provvedimento n.329 (24A02916).
Definitions
For the purposes of the note, "web scraping" is described as the activity of automated collection—typically via bots and crawlers—of large quantities of information available on the web, with a focus on repetitive, mass harvesting intended to compile datasets for subsequent analysis or algorithmic training. "Generative AI" (IAG in Italian) refers to models and systems trained to generate new content (text, images, code, audio, etc.) using large-scale datasets. "Data controller" denotes an entity that determines the purposes and means of processing personal data published on websites or platforms. The note distinguishes direct scraping (collector is also developer), indirect scraping (datasets produced by third parties), and hybrid approaches. It also highlights categories of special concern (e.g., sensitive data, minors' data, and data subject to specific legal regimes such as copyright or public access laws).
Governance and Institutional Framework
The measure is grounded in the Garante's supervisory and awareness-raising powers as set out in Article 57(1)(b) of the GDPR and references national implementing legislation (d.lgs. 196/2003 as amended). The Authority frames the note within its broader inquiry into web scraping (an earlier initiative beginning with an investigative notice dated 21 December 2023) and builds on prior enforcement activity concerning scraping and unlawful repurposing of personal data (for example, previous decisions and public documents concerning the activities of third-party actors such as Clearview). The document clarifies the roles: website/platform operators who are data controllers should assess and possibly implement technical, organisational and contractual measures; the Garante retains competence to investigate and take enforcement action where unlawful processing is suspected. The institutional texts referred to include the GDPR itself (Regulation (EU) 2016/679) and the official Garante publication pages: Garante - Provvedimento n.329.
Key Focus Areas
The note structures its guidance around a set of focus areas relevant for controllers facing the risk of scraping for AI training: (1) access regimes and publicity: controllers should review whether published data must remain public or whether access restrictions are appropriate (e.g., registration-protected zones); (2) contractual and terms-of-use strategies: updating terms of service and API contracts to expressly prohibit mass extraction and re-use for AI training where incompatible with legal bases; (3) technical anti-scraping measures: implementation of robots.txt, rate limiting, bot detection, CAPTCHAs, IP blacklisting/whitelisting, and other measures that reduce automated harvesting; (4) data governance and minimization: revising publication practices to avoid unnecessary exposure of personal data and ensuring principle of minimization; (5) legal and enforcement responses: preparing to deploy cease-and-desist notices and, where appropriate, report violations to authorities; (6) balancing public-interest transparency obligations with privacy protection, especially for public-sector bodies bound by openness and re-use duties. The note emphasizes a case-by-case analysis and suggests that small entities weigh costs and feasibility when adopting measures. It reiterates that protective measures must not contravene other legal duties (e.g., transparency or reuse obligations for public administrations).
Implementation Framework
The Garante recommends a layered, risk-based approach to implementation. Controllers should begin with a factual mapping: identify categories of personal data published, legal bases for publication, expected reuse and access rights, and the volume and sensitivity of data exposed. Based on that mapping, controllers should assess appropriate measures across technical, organisational and contractual dimensions. Technical steps include adjusting robots.txt and meta tags, deploying real-time bot detection and throttling, shielding endpoints behind authenticated APIs, segmenting or gating access to particularly sensitive sections, and monitoring unusual access patterns. Organisational measures include updated internal policies, staff training, incident response plans and documentation for decisions (records of processing, DPIAs where necessary). Contractual measures include revising terms of use, adding explicit prohibitions on mass harvesting and AI training, and appropriate licensing for any allowed data reuse. The Garante suggests that public authorities must carefully reconcile these measures with public-sector transparency and open-data obligations, possibly applying differentiated regimes per dataset or content type. For more detail see the official note: Garante - Nota informativa.
Monitoring and Evaluation
The note advises continuous monitoring of traffic and access patterns, logging of automated access attempts, and periodic reviews of access control effectiveness. Controllers are encouraged to keep traceable records of measures adopted and risk assessments carried out, and to perform periodic Data Protection Impact Assessments (DPIAs) when scraping risks to data subjects are high (e.g., large-scale processing of special categories of data or children’s data). Metrics for evaluation include reduction in automated harvesting incidents, number of blocked IPs/requests, and compliance audits of contractual clauses. The Authority notes that such monitoring and documentation will facilitate both internal governance and any future supervisory inquiries.
Penalties, Liability, and Appeals
While the note itself is informational and not sancionatory in form, it explicitly recalls that unlawful processing of personal data remains subject to the enforcement regime of the GDPR and national law. Potential enforcement measures include orders to cease unlawful processing, corrective measures and administrative fines under Article 83 GDPR (including fines up to €20 million or 4% of global annual turnover, whichever is higher) where applicable. Civil liability to data subjects (compensation) may arise under Article 82 GDPR. The Garante retains the power to investigate and apply remedies; controllers should therefore document their risk assessments and the proportionality of any protective actions. For legal background on enforcement powers see the GDPR text: Regulation (EU) 2016/679 and the Garante's official page: Provvedimento n.329.
Relationship to Other Instruments
The note situates itself relative to other legal and policy frameworks: the GDPR (privacy/data protection), national implementing legislation (d.lgs. 196/2003, as amended), public-sector transparency/open-data rules, and intellectual property law (copyright may limit redistribution of certain content). It also references prior Garante documents addressing scraping incidents and breaches (for instance, earlier case material concerning Clearview and other scraping-related decisions available in the Garante's document archive). The note complements EU-level policy debates and does not prejudge future legislation specific to AI training datasets (such as sectoral or EU AI Act provisions), but it highlights areas where harmonisation between data protection obligations and other legal regimes is necessary.
International Alignment
The Garante references international materials and decisions from other data protection authorities when framing its guidance. The note acknowledges similar concerns raised in other jurisdictions and cross-border enforcement dynamics where data controllers, processors or scraping actors operate transnationally. It invites controllers to consider international decisions and case studies (for instance, redacted decisions or supervisory authority guidance from other EU data protection authorities) when formulating measures. See the Garante reference list and links for cited international material: Garante - references.
Implementation Timeline
| Milestone | Date |
|---|---|
| Deliberation / adoption by Garante | 2024-05-20 |
| Publication in Gazzetta Ufficiale | 2024-06-07 |
| Recommended immediate actions for controllers (adopt risk mapping) | Immediate / ongoing |
| Periodic review and DPIA where required | As needed; recommended within 3-6 months of initial assessment |
Sources and References
Requirements for a company
What an organisation has to do under Italy - Web Scraping Guidance (329/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
10- Revise publication practices to minimize unnecessary exposure of personal data.Website and platform operators (data controllers).
- Perform Data Protection Impact Assessments (DPIAs) for high-risk data processing.Website and platform operators (data controllers).
- Map published personal data, including categories, legal bases, and sensitivity.Website and platform operators (data controllers).
- Assess appropriate technical, organizational, and contractual measures based on data mapping.Website and platform operators (data controllers).
- Implement updated internal policies, staff training, and incident response plans.Website and platform operators (data controllers).
- Keep traceable records of adopted measures and risk assessments carried out.Website and platform operators (data controllers).
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
2- Implement technical anti-scraping measures like robots.txt, rate limiting, and bot detection.Website and platform operators (data controllers).
- Prepare to deploy cease-and-desist notices and report violations to authorities.Website and platform operators (data controllers).
Should not do
0Nothing in this category.
Who must do what
The obligations under Italy - Web Scraping Guidance (329/2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Website and platform operators (data controllers). | Revise publication practices to minimize unnecessary exposure of personal data. “revising publication practices to avoid unnecessary exposure of personal data and ensuring principle of minimization” | Ongoing | Key Focus Areas | Critical |
| 2 | Website and platform operators (data controllers). | Perform Data Protection Impact Assessments (DPIAs) for high-risk data processing. “perform periodic Data Protection Impact Assessments (DPIAs) when scraping risks to data subjects are high” | As needed; recommended within 3-6 months of initial assessment | Monitoring and Evaluation | Critical |
| 3 | Website and platform operators (data controllers). | Map published personal data, including categories, legal bases, and sensitivity. “identify categories of personal data published, legal bases for publication, expected reuse and access rights, and the volume and sensitivity of data exposed.” | Immediate / ongoing | Implementation Framework | Important |
| 4 | Website and platform operators (data controllers). | Assess appropriate technical, organizational, and contractual measures based on data mapping. “assess appropriate measures across technical, organisational and contractual dimensions.” | Ongoing | Implementation Framework | Important |
| 5 | Website and platform operators (data controllers). | Implement updated internal policies, staff training, and incident response plans. “Organisational measures include updated internal policies, staff training, incident response plans and documentation for decisions” | Ongoing | Implementation Framework | Important |
| 6 | Website and platform operators (data controllers). | Keep traceable records of adopted measures and risk assessments carried out. “keep traceable records of measures adopted and risk assessments carried out” | Ongoing | Monitoring and Evaluation | Important |
| 7 | Website and platform operators (data controllers). | Continuously monitor traffic, log automated access attempts, and review access control effectiveness. “continuous monitoring of traffic and access patterns, logging of automated access attempts, and periodic reviews of access control effectiveness.” | Ongoing | Monitoring and Evaluation | Important |
| 8 | Website and platform operators (data controllers). | Review data publicity and consider appropriate access restrictions for published data. “controllers should review whether published data must remain public or whether access restrictions are appropriate” | Ongoing | Key Focus Areas | Important |
| 9 | Website and platform operators (data controllers). | Update terms of service and API contracts to prohibit mass data extraction for AI training. “updating terms of service and API contracts to expressly prohibit mass extraction and re-use for AI training” | Ongoing | Key Focus Areas | Important |
| 10 | Public-sector website and platform operators (data controllers). | Balance public-interest transparency obligations with privacy protection, especially for public bodies. “balancing public-interest transparency obligations with privacy protection, especially for public-sector bodies” | Ongoing | Key Focus Areas | Important |
| 11 | Website and platform operators (data controllers). | Implement technical anti-scraping measures like robots.txt, rate limiting, and bot detection. “implementation of robots.txt, rate limiting, bot detection, CAPTCHAs, IP blacklisting/whitelisting, and other measures” | Ongoing | Key Focus Areas | Recommended |
| 12 | Website and platform operators (data controllers). | Prepare to deploy cease-and-desist notices and report violations to authorities. “preparing to deploy cease-and-desist notices and, where appropriate, report violations to authorities” | Ongoing | Key Focus Areas | Recommended |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026