Does Law on Artificial Intelligence require Data Governance?
Italy • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 4 specific requirements for Data Governance across 1 provision:
- Secondary use permitted — Anonymized or pseudonymized health data may be used for AI research without new patient consent, serving significant public interest
- Garante notification — 30-day advance notification to the Italian Data Protection Authority (Garante) required before commencing AI research using health data
- GDPR compliance — All health data processing for AI research must comply with GDPR requirements
- Anonymization standards — Data must be properly anonymized or pseudonymized before secondary use for AI research
Health Data for AI Research #
Italy's secondary-use pathway for health data is a sleeper provision with global reach: any organisation conducting AI research using Italian patient data — including non-Italian researchers accessing Italian health datasets — must satisfy both the GDPR and a 30-day Garante notification before processing. This covers clinical AI model training, drug discovery AI, and public health AI research.
Requirements
| Requirement | Details |
|---|---|
| Secondary use permitted | Anonymized or pseudonymized health data may be used for AI research without new patient consent, serving significant public interest |
| Garante notification | 30-day advance notification to the Italian Data Protection Authority (Garante) required before commencing AI research using health data |
| GDPR compliance | All health data processing for AI research must comply with GDPR requirements |
| Anonymization standards | Data must be properly anonymized or pseudonymized before secondary use for AI research |