Italy's data protection authority today published a decision barring broadcaster R.T.I. from further processing the personal data of La7 news director Enrico Mentana in artificial intelligence altered clips aired by the satirical programme Striscia la Notizia, issuing a formal warning without a financial penalty.

The order was adopted in Rome on 23 July 2026 and registered as provvedimento n. 577, carrying document reference 10281021. It was decided by a panel comprising president Pasquale Stanzione, vice-president Ginevra Cerrina Feroni, member Agostino Ghiglia and secretary general Luigi Montuori, with Cerrina Feroni acting as rapporteur. The Garante per la Protezione dei Dati Personali summarised the reasoning in a press release dated 7 August 2026, five days after the transparency obligations of the EU AI Act became applicable across the bloc.

The timing is not incidental. R.T.I. - Reti Televisive Italiane S.p.A., the Mediaset group company that publishes Striscia la Notizia, built part of its defence on the argument that the disclosure duty for deepfakes under Regulation (EU) 2024/1689 would only bind from 2 August 2026. The Garante did not reach that question. It applied the General Data Protection Regulation instead, and found the conduct unlawful under rules that have been in force since 2018.

Three measures, none of them a fine

The authority imposed three distinct measures. Under Article 58(2)(f) of the GDPR it ordered a ban on any further processing of the complainant's data in the manner described, except plain retention for possible judicial use. Under Article 58(2)(b) it issued a formal warning to R.T.I. for failing to observe the provisions on data processing, with particular regard to the measures required to secure the general principles of lawfulness, fairness and transparency. Under Article 17 of the Garante's own regulation n. 1/2019 it ordered the measures to be recorded in the internal register maintained pursuant to Article 57(1)(u) of the Regulation.

R.T.I. has thirty days from receipt of the decision to communicate what steps it has taken to comply. Failure to answer that request is itself punishable under Article 166 of the Italian privacy code and Article 83(5)(e) of the GDPR. Breaching the processing ban carries heavier exposure: the criminal sanction provided by Article 170 of the code, alongside the administrative fine available under Article 83(5)(e).

The decision explains why no penalty accompanied the finding. The Garante considered the warning proportionate because the legal question is novel, arising from recently introduced technological instruments whose contours remain unsettled, particularly where they are used inside entertainment programming and therefore attach to artistic expression. R.T.I. may appeal to the ordinary courts within thirty days of notification, or sixty days if the appellant resides abroad, under Article 78 of the Regulation and Article 152 of the code.

A news anchor in his own studio

Mentana filed his complaint under Article 77 of the GDPR through counsel. According to the decision, he objected that Striscia la Notizia had reproduced his image using artificial intelligence systems to build segments in which he appears as an unwitting protagonist, filmed in the role that is properly his as director of the La7 evening newscast, and made "per interpretare un copione scritto dagli autori del programma televisivo di Mediaset" - to perform a script written by the authors of the Mediaset television programme. The complaint added that the staging carried the La7 newscast logo, which made it more credible still.

The full segments were subsequently uploaded to the programme's website and social channels and to the Mediaset Infinity platform. After a cease and desist letter, the broadcaster's lawyers replied that the material amounted to a joking parody protected by the right of satire. The complainant countered that the conduct had gone beyond any correct exercise of that right, because a great many people had believed the videos were real.

A notice on the website stating that the image is a deepfake, on his account, works only for an attentive viewer and takes no account of those who begin watching a segment already under way. In the social extracts, most of which carried no indication of artificial intelligence before the letter, recognition of the technique was left entirely to the user.

The complaint cited comments posted under the programme's social posts - stupido, ignorante, ubriaco, pagliaccio, rosicone, vigliacco - as evidence that many readers took the statements to be authentic, causing what he described as a serious injury to his honour, reputation and professional standing. On the legal characterisation, he argued that satire is the symbolic representation of reality expressed through paradox, that it must take its cue from a news event in which the target is the protagonist, and that here a digital fake had instead been used in his professional capacity to launch invented items and circulate views he does not hold.

Licensed footage and the satire defence

R.T.I. responded on 17 April 2025 to an information request the Garante had sent on 28 March 2025 under Article 157 of the code. All the audiovisual excerpts, the company stated, were licensed to it by LA7 under a contract signed on 9 March 2021 and later extended. LA7 could dispose of the image rights, never withheld consent, and knew the clips would air inside Striscia la Notizia, receiving regular usage reports without objection. At a hearing on 27 February 2026, the company reiterated that the images had not been obtained through web scraping but purchased for consideration, with an invoice issued by La7 S.p.A.

The only thing done to the material, according to R.T.I., was dubbing Mentana with a voice other than his own through computer systems. The purpose was the exercise of satire by way of imitation, with the single difference that technological evolution had replaced the human voice actor.

On disclosure, the company argued it had gone beyond what the law required. It said it could "potuto benissimo non includere tali avvertenze aggiuntive" - could perfectly well have left out the additional warnings - having made clear from the outset that the speaker was not the real Enrico Mentana, through a disclaimer on the use of artificial intelligence technologies from the first broadcast, explanatory notes beneath each video on the official site, and, on Mediaset Infinity, a title indication, the Striscia and Canale 5 logos and a scrolling lower third on the video itself.

R.T.I. also noted that deepfakes are not a prohibited practice as such under the European AI Regulation, that the specific information duties on creators are reduced where the content forms part of an evidently artistic, creative, satirical or fictional work, and that the obligation would in any event become applicable only from 2 August 2026. It described itself as among the first Italian companies to work with the Polizia Postale against illicit deepfakes, and noted that Mentana had himself been the target of a fraudulent one. Striscia la Notizia, it added, was the first Italian programme to use the technique satirically, from 2019 onwards, against a list of public figures none of whom complained.

On the law, R.T.I. invoked Cass. civ., Sez. III, ordinance 6960 of 14 March 2024, under which satire is exempt from the requirement of truth because it expresses an ironic judgment through implausibility and hyperbole. It argued that the derogations Article 85 of the Regulation allows for journalistic processing extend to satire, so that consent and the other legal bases in Article 6 fall away.

The rebuttal: a licence to use is not a licence to alter

Replying on 22 April 2025, Mentana observed that no copy of the contract had been produced. What was described, he argued, is an ordinary footage licensing arrangement of the sort that governs relations between broadcasters, and while La7 can license extracts of its own programmes, it cannot authorise their modification to the detriment of the people appearing in them. R.T.I., on this reading, circulated a film materially different from the original.

He disputed the claim that no one was misled, saying a high number of users had asked him to account for things he had apparently said. The programme's editing, he argued, resembles a montage of real broadcast clips, including genuine on-air errors by television personalities, which makes separating the real from the artificial unusually hard. Had the fake been as crude as the broadcaster maintained, there would have been no reason to add further indications after the letter arrived. The word deepfake, he added, is not in common use.

The distinction he drew between an impersonator and a synthetic double went to the heart of the data protection question. However skilled, an impersonator does not use captured images or appropriate and distort the subject's personal data, but reproduces the subject's most characteristic traits.

Why the disclaimers failed

The Office opened proceedings on 22 September 2025 under Article 166(5) of the code, alleging breaches of Articles 5(1)(a), (b) and (c), 6 and 25 of the Regulation and Article 137 of the code. R.T.I. filed a defence memorandum on 22 October 2025.

The Garante accepted that the processing belongs to the exercise of freedom of expression and that Articles 136 to 139 of the code apply, satire included. Those provisions confirm the lawfulness of such processing without consent, provided it respects the rights, fundamental freedoms and dignity of the people concerned.

What it did not accept was the adequacy of the execution. The authority found that the complainant's real image was used, filmed inside the television studio from which he directs an evening newscast, with its genuineness altered by dubbing carried out through tools that do not make the alteration clearly perceptible. The statements attributed to him, referring to real news events, appear truthful on immediate viewing and do not display, contrary to the controller's assertion, "quel grado di esagerazione tale da rendere evidente che si tratti di un 'falso'" - that degree of exaggeration such as to make plain that this is a fake.

The real professional context made the processing particularly insidious with reference to his personal identity, in the Garante's assessment, and amplified the risk of turning him into a vehicle of disinformation, a risk the authority treated as confirmed by the volume of mocking and offensive messages he received through social media. Under the fairness principle, controllers must account at the design stage for the prejudice a processing operation, or the chosen means of carrying it out, may cause to the data subject, including the impact on those who consume the output.

On disclosure, the finding is specific. The processing was not accompanied by disclaimers sufficiently clear "quanto meno con riferimento alle conoscenze tecnologiche di un pubblico medio o comunque poco attento" - at least by reference to the technological knowledge of an average or in any case inattentive public. Context data combined with words spoken by the deepfake of a well known journalist would have required more explicit communications, made more evident at the various moments of broadcast, so as to reach less attentive users and those who joined after the programme had started.

That reasoning produced findings of violation under Article 5, covering lawfulness, fairness and transparency, and under Article 25 on data protection by design and by default, for the absence of technical and organisational measures adequate to implement the general principles effectively.

The Article 50 clock did not stop the case

The broadcaster's timing argument was factually correct and legally beside the point. Transparency duties for deepfakes sit in Article 50(4) of Regulation (EU) 2024/1689, and those obligations became applicable on 2 August 2026, ten days after this decision was adopted. The European Commission fixed the interpretation shortly before, publishing guidelines as Communication C(2026) 5054 final on 20 July 2026 alongside a finalised Code of Practice on Transparency of AI-Generated Content, with non-compliance exposure reaching 15 million euros or 3 percent of worldwide annual turnover.

Under those guidelines, deepfake material forming part of an evidently artistic, creative, satirical, fictional or analogous work attracts a narrower duty, disclosure in a manner that does not hamper enjoyment of the work. Striscia la Notizia would plainly qualify for that lighter regime. The Garante's decision demonstrates that qualifying for it settles very little, because the GDPR runs in parallel and asks a different question: not whether a label exists, but whether the processing of an identifiable person's image and voice was fair, transparent and designed with the subject's exposure in mind.

The Commission's free labelling icon set, published with a last update dated 10 June 2026, and the attestation fields Google added to the Display & Video 360 and Campaign Manager 360 APIs in late July, address the marking obligation. Neither addresses the standard the Italian authority applied here, which turns on whether an inattentive viewer, arriving mid-segment, could tell.

What the marketing industry takes from it

For advertisers and publishers producing synthetic media in Europe, three points in the decision carry directly.

The first concerns the adequacy standard. Disclosure was measured against the least attentive member of the audience, not the informed one. A static notice on a web page, a logo, and a title indication were treated as insufficient where the underlying footage was authentic broadcast material and the alteration was confined to the voice. That standard is stricter than the machine-readable marking most compliance tooling currently delivers.

The second concerns rights clearance. R.T.I. held a paid licence from La7, with invoicing and usage reporting, and the Garante did not dispute any of it. Clearing the footage did not clear the data protection question, because the person whose image was altered was not a party to the contract. Agencies buying stock, archive or licensed talent footage for AI-assisted edits face the same structural gap.

The third concerns public figure status. R.T.I. argued that a person of Mentana's prominence could reasonably expect his data to be used for satirical purposes. The authority did not adopt that reasoning, focusing instead on the insidiousness of placing a synthetic performance inside the subject's genuine professional setting.

The wider Commission position already separates commercial persuasion from creative work: advertising content sits outside the lighter artistic regime, and draft guidance excludes AI-generated imagery of celebrities implying involvement in activities they did not take part in. A brand deploying a synthetic spokesperson therefore starts from a heavier labelling duty than a satirical broadcaster, and now also inherits the design obligations applied here.

The Italian regulator has been active on both fronts. It warned a Milan-area startup in May 2026 over a Slack and Teams plug-in inferring employee stress, in one of the first European actions to invoke the GDPR and the AI Act together, and it fined data broker Lusha 2 million euros in July 2026 on lawfulness, fairness and transparency grounds.

Whether R.T.I. contests this order will determine how far the reasoning travels. Absent an appeal, it stands as the first European data protection decision to test the satire carve-out against a synthetic double of a working journalist, decided on principles that owe nothing to the AI Act and applied ten days before it took hold.

Timeline

Summary

Who: Italy's Garante per la Protezione dei Dati Personali, ruling on a complaint by Enrico Mentana, director of the La7 newscast, against R.T.I. - Reti Televisive Italiane S.p.A., publisher of Striscia la Notizia. The panel comprised Pasquale Stanzione, Ginevra Cerrina Feroni, Agostino Ghiglia and Luigi Montuori, with Cerrina Feroni as rapporteur.

What: A ban on further processing of the complainant's data in the manner described, except retention for judicial use, plus a formal warning and an entry in the authority's internal register. The Garante found breaches of Article 5 and Article 25 of the GDPR, holding that the disclaimers accompanying the AI-dubbed segments were not clear enough for an average or inattentive audience. No fine was imposed.

When: Adopted on 23 July 2026 as provvedimento n. 577, document reference 10281021, and published with a press release on 7 August 2026. The proceedings ran from a request for information on 28 March 2025 through a hearing on 27 February 2026.

Where: Italy, covering broadcasts of Striscia la Notizia on Canale 5 and distribution through the programme website, its social channels and the Mediaset Infinity platform.

Why: The authority held that using authentic footage of a journalist inside his own studio, altered by AI dubbing in a way not clearly perceptible, made the segments appear truthful to immediate viewing, amplified the risk of disinformation and failed the fairness and by-design obligations, notwithstanding the right of satire and the licence R.T.I. held from La7.