Share This Article
Privacy class actions in Italy have moved from theory to practice after the Court of Milan admitted the first GDPR representative action — and the international data shows where this leads.
On 10 April 2026, the specialised business chamber of the Court of Milan declared admissible the first representative action ever brought in Italy over a data protection breach. The claim concerns the large-scale scraping of personal data of the users of a global online platform, carried out by third parties, and it potentially involves around 35 million people in Italy alone.
For years, Italian general counsels treated GDPR exposure as a regulatory question. Fines, inspections, corrective measures, reputational management. That framing no longer holds. After this order, the same compliance gap that attracts a supervisory authority can also attract an aggregated damages claim brought on behalf of millions of data subjects, without any of them lifting a finger.
The decision is procedural. Nevertheless, it is the most consequential Italian privacy ruling of the year, and the reason is simple: admissibility was the bottleneck.
What the Milan court decided
The action does not accuse the defendant of scraping anything. Instead, it accuses the defendant of failing to put in place technical and organisational measures capable of preventing third parties from harvesting the data of its own users. In other words, the alleged liability rests squarely on the privacy by design and by default principles of Articles 25 and 32 of the GDPR.
That distinction matters enormously. A company can be entirely passive in the incident and still find itself on the wrong side of the claim, simply because its defences were not proportionate to the risk.
The court addressed three preliminary points along the way:
- Jurisdiction. Italian courts have jurisdiction over a foreign controller where a branch operates in Italy, notwithstanding the one-stop-shop mechanism of the GDPR.
- Opt-in. Representative actions under the Italian Consumer Code follow the opt-in model, so the class is built after admissibility rather than before it.
- Scope of the admissibility test. The judge does not anticipate the merits. He or she verifies only that the claim is not manifestly unfounded and that the rights asserted are homogeneous enough to be handled serially.
Three findings that change the risk calculus
Three passages of the order deserve close reading, because together they dismantle the obstacles that had kept collective redress marginal in this country.
1. No mandate from the data subjects
First, the court held that a consumer association listed under Article 137 of the Consumer Code can bring the action without any prior mandate from the individuals concerned. The reasoning rests on the objective of ensuring a high level of consumer protection. Consequently, a claimant organisation no longer needs to assemble a class before it can sue. It needs only standing.
2. No tolerability threshold for non-material damage
Second, and consistently with the case law of the Court of Justice of the EU, the order states that compensation for non-material damage arising from the loss of control over personal data cannot be conditional on the harm exceeding a threshold of seriousness. The CJEU reached the same conclusion in Österreichische Post (C-300/21) and in the line of judgments that followed it. Therefore, the debate shifts from whether damage exists to how much it is worth.
3. Homogeneity survives sub-classes
Third, the court accepted that the requirement of homogeneity can be met even where a single event produces different heads of damage for distinct sub-classes of affected individuals. The condition is that damages remain quantifiable on criteria capable of standardisation for each category. As a result, the familiar defence that “every claimant is different” becomes considerably harder to run.
Taken together, these findings remove standing, proof of damage and manageability of the class as barriers. Those were precisely the three walls that had kept privacy class actions in Italy off the board agenda.
Privacy class actions in Italy against the international benchmark
To understand where this leads, it helps to look at the jurisdictions that arrived here first.
The United States offers the clearest picture. Plaintiffs filed nearly 1,900 data privacy class actions in 2025 alone, an average of more than 150 filings every month. That is over 25% annual growth, and more than 200% growth since 2022. On the settlement side, the top ten privacy class action settlements were worth approximately USD 801.85 million in 2025, USD 2.01 billion in 2024 and USD 1.32 billion in 2023, with data breach settlements adding a further USD 515.79 million at the top end last year. Notably, much of this litigation does not follow a breach at all. Instead, it targets ordinary technologies — website pixels, chatbots, session replay tools — paired with statutory damages regimes.
Europe is following, more slowly but unmistakably. According to the CMS European Class Action Report, claimants filed 133 class actions across Europe in 2023 and 97 in 2024. The cumulative value of UK claims reached EUR 155 billion, followed by Portugal at EUR 54.76 billion and the Netherlands at EUR 36.31 billion. Claims against Big Tech alone reached EUR 36.49 billion in the UK and EUR 17.85 billion in the Netherlands. Historically, the UK, the Netherlands, Germany and Portugal have accounted for roughly 78% of all European class actions, while data protection claims grew elevenfold between 2016 and 2020.
The jurisdictional picture is equally instructive:
- The Netherlands remains the most aggressive forum, thanks to the opt-out WAMCA regime. One foundation has claimed non-material damages on behalf of ten million Dutch internet users over real-time bidding practices.
- Germany is seeing a steady rise in collective actions, particularly in GDPR and technology-related claims.
- Portugal now accounts for around 27% of all European filings, up from 23% the year before.
- England and Wales, despite Lloyd v Google, continue to generate the largest claimed quantum in Europe through group litigation and collective proceedings.
Italy was the conspicuous absentee from that list. It is no longer.
Why scraping sits at the centre of the exposure
The timing is not accidental. On 7 July 2026, the European Data Protection Board adopted Guidelines 03/2026 on web scraping in the context of generative AI, open for public consultation until 30 October 2026.
Those guidelines address the scraper. However, they also do something else, and it has gone largely unnoticed. They articulate in considerable detail what the data protection community now expects around scraping, including the treatment of robots.txt, ai.txt, CAPTCHA and authentication walls as meaningful signals. Consequently, a claimant has a published benchmark against which to measure whatever defences a defendant had in place on the day.
Regulatory guidance rarely stays regulatory for long. Once a standard is written down, it becomes the yardstick in civil proceedings too.
What companies should do now: a practical checklist
None of the following depends on how the Milan proceedings end on the merits.
1. Run a documented security risk assessment. Identify the scraping and enumeration scenarios that are realistic for your data, not the generic ones borrowed from a template.
2. Calibrate the measures to the risk. Rate limiting, anomaly detection, bulk enumeration controls, API restrictions and authentication design all belong in the file, together with the reasons behind each choice.
3. Record the measures you decided not to take. Accountability protects you where you can show why something was disproportionate. It exposes you where the record is simply silent.
4. Revisit your DPIAs, above all those covering large user bases and publicly exposed profile data.
5. Honour opposition signals and log them. robots.txt, ai.txt, CAPTCHA and login walls now carry evidential weight, on both sides of the scraping relationship.
6. Model the aggregated exposure. Multiply a modest per-capita figure by your Italian user base, then compare the result with your worst-case administrative fine. The comparison is usually sobering.
7. Align incident response with litigation. Documents created in the first 72 hours will be read years later by opposing counsel, and they will be read uncharitably.
8. Check your insurance. Cyber policies frequently address regulatory exposure far better than they address collective civil liability.
The Milan order establishes no infringement, and the merits phase may well end differently. Even so, the strategic significance is real.
Europe already had the machinery. The Representative Actions Directive, implemented in Articles 140-ter and following of the Italian Consumer Code, has been available since 2023. What was missing was a court willing to apply it to a GDPR claim, together with rulings on standing, damage and homogeneity that made the mechanism workable in practice. This order supplies both, and it does so in a jurisdiction with a large user base and an active consumer movement.
For companies, the practical consequence is straightforward. GDPR exposure can no longer be measured in administrative fines alone. Civil liability, aggregated across millions of data subjects and supported by an increasingly sophisticated litigation funding market, can dwarf them. Furthermore, it is triggered by exactly the same failing: security measures that were not proportionate to the risk, or that were adopted but never documented.
So I will put to you the question I have been putting to clients over the last weeks. If a representative action landed tomorrow over a scraping incident affecting your users, what would your documentation actually prove? In my experience, the answer depends far less on what a company did than on what it wrote down at the time.
On a related topic, you may find of interest the article “EDPB Web Scraping Guidelines: Five Open Questions for the Growth of AI” on this blog, which covers the guidance now shaping the standard of care in this area.
The impact of privacy class actions in Italy depends heavily on how your organisation assessed, calibrated and documented its security measures, and on the size of your Italian user base. If you would like to discuss what this ruling means for your risk profile, or to review your position before a claim arrives, you can reach me at giulio.coraggio@dlapiper.com, and our team is happy to help.

