---
title: "Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) — KYE Protocol™ coverage"
description: "Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it."
url: https://kyeprotocol.com/compliance/it-codice-privacy/
lang: en
source: "KYE Protocol"
---

> Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.

Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018)

# Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) — 83% of in-scope requirements covered.

3 requirements · 3 in scope (2 enforced · 1 designed). The 83% is weighted over the in-scope base.

**Source:** Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018). National statute implementing/supplementing Regulation (EU) 2016/679 (GDPR) in Italy. Substantive obligations resolve to the deep GDPR per-article registry (internal) reused via the framework\_\_jurisdiction edge; this registry maps only the Italy-specific national deltas.

## By category

| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
| --- | --- | --- | --- | --- | --- | --- |
| GDPR transposition (national basis) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Supervisory authority + accountability | 1 | 1 | 0 | 0 | 0 | **100%** |
| Breach notification (national channel) | 1 | 0 | 1 | 0 | 0 | **50%** |

## Every requirement → the KYE™ artefact that enforces it

| ID | Title | Status | KYE™ enforcement |
| --- | --- | --- | --- |
| `it-codice-privacy.gdpr-transposition` | Codice in materia di protezione dei dati personali (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) transposes / supplements the GDPR (Reg. (EU) 2016/679) into Italy national law — the substantive data-protection obligations resolve to the GDPR per-article bijection | enforced | **audit\_events**: `kye.purpose.admissibility.v1`, `kye.evidence.decision_map.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/12-PURPOSE-PERMISSION.md`, `constitution/21-DELEGATED-AUDITABILITY.md` |
| `it-codice-privacy.supervisory-authority` | Cooperation with the national supervisory authority (the Garante) — records of processing and the demonstrable-accountability account an AI agent's data processing must produce on request | enforced | **audit\_events**: `kye.evidence.pack.v1`, `kye.compliance.attestation.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/21-DELEGATED-AUDITABILITY.md`, `constitution/31-DATA-GOVERNANCE-PACK.md` |
| `it-codice-privacy.breach-notification` | Personal-data breach notification to the Garante (and affected individuals) within the GDPR Art. 33/34 window, on the national reporting channel | designed | **audit\_events**: `kye.signal.incident.opened.v1`, `kye.compliance.attestation.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md` |

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
