The case, explained
GDPR Sanction Deadlines: The Supreme Court on the Dies A Quo
7 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
The recent intervention by the Supreme Court of Cassation regarding sanctions for personal data protection violations marks a fundamental procedural turning point. According to reports in specialized publications such as Diritto Bancario and Agenda Digitale, the Court clarified the temporal boundaries within which the Data Protection Authority can notify violations, resolving a long-standing debate on the start of the 120-day term. Unlike previous articles in this column focused on specific violations such as log usage or scraping, this contribution analyzes an administrative-procedural issue: the limitation period for notifying an offense. Through case law analysis and the reconstruction of a twin case starring the tireless Gaio Sventura, we will explore how legal certainty must balance with the complexity of the Authority's technical investigations. The Cassation ruling defines the exact moment when the time available to the Authority begins to run, a topic that closely affects every company managing a data breach notification.

In brief
The article examines the Cassation orientation regarding sanctioning forfeiture under the GDPR. The Court established that the 120-day deadline for notifying sanctions does not run from the mere news of the event, such as a data breach notification, but from the definitive assessment of the elements of the offense. It illustrates a case where a sanction was initially annulled for untimeliness and later reinstated, delving into the distinction between the pre-investigative phase and the sanctioning procedure to ensure the controller's defense.
The facts
The case originates from a sanction imposed by the Data Protection Authority on a company following a data breach notification spontaneously made by the data controller. According to reports from publications such as Diritto Bancario and Agenda Digitale, the Authority proceeded with the formal notification of the offense more than 120 days after receiving the initial communication. In the lower court proceedings, the Tribunal upheld the company's objection, declaring the injunction null and void for untimely notification, ruling that the deadline should have started immediately after the breach was reported. The case reached the Supreme Court of Cassation following an appeal by the Authority. The Supreme Court, in its recent ruling, overturned the lower court decision, clarifying that the mere receipt of news of an offense or a self-report does not necessarily coincide with the moment of definitive assessment of the violation, which instead requires a complex evaluation of the subjective and objective elements of the case.

The rules in play
The legal framework is based on the integration of general administrative sanction regulations and the GDPR.
- Article 14 of Law 689/1981 establishes that the notification must be served within precise deadlines from the assessment, a concept that case law must define based on the complexity of the investigation.
- Article 166 of the Privacy Code (Legislative Decree 196/2003) and the Authority's internal regulation set the mandatory deadline for notification at 120 days following the assessment.
- Article 83 of the GDPR requires administrative fines to be effective and dissuasive, but their application must respect the principles of legality and legal certainty provided by the national legal system. The function of these rules is to ensure that the administration cannot keep a subject under investigation for an indefinite period, while allowing the Authority to perform necessary technical checks before formalizing the charge.
Case law analysis
The Supreme Court's jurisprudence has consolidated a rigorous orientation on the distinction between the phase of acquiring news and the actual assessment. The judges clarified that the dies a quo for the 120-day term cannot be mechanically equated with the date the Authority receives the data breach report. On the contrary, the assessment is considered complete only when the Authority has gained full awareness of the existence of the violation, its severity, and the controller's liability. This process may include requests for additional documentation and technical audits that are not subject to limitation periods, provided the investigative activity is carried out within reasonable times. The pivotal principle is that the limitation period has a guarantee function for the citizen but cannot be used to paralyze the Authority's action before it has the minimum elements to formulate a well-founded charge.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Do not consider the Authority's silence after a data breach notification as an implicit dismissal, but constantly monitor the status of the proceedings.
- Precisely document every interaction with the Authority, as the date of the last clarification provided could become the decisive moment for the forfeiture calculation.
- Evaluate the untimeliness objection not just on the total time elapsed, but on the appropriateness of the time spent on the investigation relative to the technical complexity of the case.
References: Articolo 14 Legge 689/1981Articolo 166 D.Lgs. 196/2003Regolamento UE 2016/679 (GDPR)
Related cases

Frequently asked questions
When does the 120-day count for the Authority's fine begin?
The deadline does not start from the receipt of the news (like the data breach notification), but from the moment the Authority has completed the assessment of all elements of the offense.
What happens if the Authority responds after a year?
If the delay is due to a complex investigative phase or requests for clarification, the sanction may still be legitimate; if, however, there was unjustified inertia, the sanction can be challenged for forfeiture.
Can a GDPR sanction be annulled for delayed notification?
Yes, if the notification of the charge occurs beyond 120 days from the definitive assessment, the order is null for violation of the mandatory deadlines provided by law.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free