Pay transparency and personal data protection: privacy implications of Italy’s implementation of the pay transparency Directive
On 7 June 2026, Italian Legislative Decree No. 96/2026 (the "Decree") entered into force, transposing into Italian law Directive (EU) 2023/970 on strengthening the application of the principle of equal pay for men and women for equal work or work of equal value through pay transparency and enforcement mechanisms.
The new legal framework introduces obligations affecting both the recruitment process and existing employment relationships. Applicants are granted the right to receive information on the initial pay level or its range prior to employment, while employers are prohibited from requesting or otherwise obtaining information concerning applicants’ pay history. Employees are also entitled to obtain, within two months of submitting a request, information on the average pay levels, broken down by sex, of workers performing the same work or work of equal value, as well as the criteria used to determine pay progression (1).
The Decree is relevant not only from an employment law perspective but also from a data protection standpoint. The new rules materially increase the circumstances in which remuneration-related personal data are collected, used, disclosed and otherwise processed, requiring employers, in their capacity as data controllers, to ensure that the relevant processing operations comply with the principles and obligations laid down in Regulation (EU) 2016/679 (the "GDPR").
Pay information as personal data
Information relating to remuneration, pay levels, pay components and pay progression constitutes personal data within the meaning of Article 4(1) GDPR where it relates to an identified or identifiable employee, including where identification may occur indirectly through additional information available within the organisation.
In this regard, the Decree confirms that information concerning pay levels and the gender pay gap, where it involves the processing of personal data, must be processed in accordance with the GDPR and may not be further processed for purposes incompatible with those connected with the implementation of the principle of equal pay.
The key change introduced by the Decree, however, does not concern the legal qualification of pay information, which already constituted personal data prior to the entry into force of the Decree, but rather the increased circulation of such information within organisations. The exercise of the new rights granted to employees, together with the reporting obligations imposed on employers, inevitably entails additional processing of remuneration-related personal data. This makes it necessary to implement appropriate technical and organisational measures to ensure data accuracy, integrity and confidentiality, as well as to minimise the risk of unauthorised access, disclosure or further use.
The risk of employee identification
One of the most sensitive issues concerns the risk that the information disclosed may allow the remuneration of a specific employee to be identified, either directly or indirectly. For this reason, the Decree provides that, where the disclosure of pay information could lead to the identification of an individual employee, access to such information must be restricted to employee representatives, the National Labour Inspectorate and the competent equality bodies. These entities may assist employees in exercising the rights granted under the Decree, without disclosing individual remuneration levels.
This provision requires a case-by-case assessment, in line with the GDPR principles of data minimisation, confidentiality and privacy by design. The risk of identification depends not only on the dataset disclosed but also on the organisational context of the employer. In small organisations, or in departments employing only a limited number of highly specialised workers, even aggregated or statistical data may allow the remuneration of a particular employee to be inferred.
For this reason, employers should adopt internal procedures governing the handling of such requests, designate the authorised personnel responsible for processing and disclosing the requested information, and introduce preliminary disclosure controls aimed at preventing the direct or indirect identification of employees.
Recruitment processes
The Decree also introduces significant changes to recruitment procedures. Applicants must receive information regarding the initial pay level or its range, as well as the provisions of the relevant collective bargaining agreement, either in the job advertisement or, in any event, before the job interview takes place. At the same time, employers are prohibited from requesting information regarding an applicant’s previous remuneration or obtaining such information indirectly through third parties.
From a data protection perspective, these obligations require employers to review the entire recruitment process in light of the principles of lawfulness, fairness, transparency and data minimisation. It will not be sufficient merely to remove salary history questions from application forms. Employers should also review interview practices and the instructions provided to recruitment agencies to ensure that information which may no longer lawfully be collected is not requested or otherwise obtained. Where external recruiters are engaged, organisations should also verify the role of such providers under the GDPR and ensure that the relevant contractual arrangements, including any data processing agreements and documented instructions to processors, are consistent with the new legal requirements.
Gender pay gap reporting obligations
The Decree also introduces specific reporting obligations concerning the gender pay gap (2), which will apply progressively depending on the number of workers.
Employers with at least 250 employees shall collect and report the relevant data by 7 June 2027 and annually thereafter. Employers with between 150 and 249 employees shall submit their first report by the same date and subsequently every three years. Employers with between 100 and 149 employees will be required to comply for the first time by 7 June 2031, with reporting obligations recurring every three years. Employers with fewer than 100 employees may report on a voluntary basis, unless otherwise required under national law.
From an operational perspective, preparing such reports is far more than a mere compliance exercise. The quality, accuracy and reliability of the reported data depend on the adoption of consistent criteria for identifying workers performing the same work or work of equal value, as well as on effective coordination between HR, legal, data protection and, where appropriate, IT functions.
What should employers do?
Compliance with the Decree requires organisations to review the processes through which remuneration-related personal data are managed. In particular, employers should verify that their records of processing activities, privacy notices addressed to employees and job applicants, retention rules, internal policies and instructions to authorised personnel accurately reflect the new processing operations introduced by the legislation. Equal attention should be paid to service providers processing remuneration-related personal data on behalf of the employer, ensuring that the relevant data processing agreements adequately describe the subject matter, duration, nature and purposes of the processing, the categories of personal data and data subjects concerned, and the applicable security and confidentiality obligations.
Organisations should also establish internal procedures for handling employees’ requests, identify the business functions responsible for responding to such requests, adopt standardised response templates, and implement safeguards designed to prevent disclosures that could result in the direct or indirect identification of individual employees, including access restrictions, need-to-know controls and prior assessment of re-identification risks.
Overall, the Decree provides an opportunity to rethink the governance of remuneration-related personal data. Whereas such data were traditionally confined to payroll and administrative functions, the new legal framework places them at the centre of a broader transparency regime involving HR, legal, data protection and management functions. Against this background, GDPR compliance should not be regarded as a mere ancillary requirement to pay transparency legislation, but rather as an essential condition for ensuring that the new transparency obligations are implemented lawfully, fairly and in accordance with the principle of accountability.
[1] Employers with fewer than 50 employees are not required to make available the criteria governing pay progression.
[2] In particular, employers will be required to submit to the Monitoring Body established within the Italian Ministry of Labour and Social Policies (Ministero del Lavoro e delle Politiche Sociali – MLPS) the following information: the gender pay gap; the gender pay gap in complementary or variable components of remuneration; the median gender pay gap; the median gender pay gap in complementary or variable components of remuneration; the proportion of female and male workers receiving complementary or variable components of remuneration; the proportion of female and male workers in each pay quartile; and the gender pay gap between workers by categories of workers, broken down by ordinary basic salary or wage and complementary or variable components of remuneration.