In a significant judgment, the Consiglio di Stato (Council of State) (Sixth Chamber, Judgment No. 9614 of 2 December 2024) addressed one of the most sensitive issues affecting today’s digital markets: the legal nature of personal data and the relationship between consumer protection, informed consent and the economic value of the information provided by users in exchange for access to digital services.
The proceedings originated from a decision of the AGCM (Italian Competition Authority) imposing a fine of EUR 10 million on Apple for engaging in two practices found to be in breach of Italian consumer protection legislation (Legislative Decree No. 206 of 6 September 2005).
The infringements consisted of:
failing to provide users with adequate information regarding the collection and commercial use of their personal data; and implementing pre-ticked consent mechanisms for marketing purposes, combined with particularly burdensome procedures for withdrawing such consent.
Beyond the outcome of the specific proceedings, what makes the judgment particularly significant is the broader reasoning adopted by the Court, which brings together consumer protection law, competition law, data protection and the digital economy.
The Consiglio di Stato (Council of State) starts from a principle that has become increasingly difficult to dispute: in today’s digital economy, personal data constitute a strategic resource capable of generating both direct and indirect economic value, representing one of the core assets underlying the business models of online platforms and digital services.
A user’s decision to provide personal data in order to create an account on a digital platform can no longer be regarded as a neutral aspect of the contractual relationship. Rather, it forms part of a genuine economic exchange and therefore constitutes a commercial decision within the meaning of Article 21 of the Italian Consumer Code, even where access to the service does not involve any immediate monetary payment.
This approach had already been recognised by the Consiglio di Stato (Council of State) in its landmark Facebook judgment (Sixth Chamber, Judgment No. 2631 of 29 March 2021), where the Court acknowledged that the provision of personal data may itself possess economic value and influence consumers’ commercial decisions, thereby requiring a particularly high standard of transparency. The present judgment builds upon that line of authority, reinforcing the view that, within the digital economy, the transfer of personal data constitutes an essential component of the relationship between users and digital platforms and therefore requires substantive rather than merely formal protection. Accordingly, infringements relating to the processing of personal data are not sanctionable solely under the General Data Protection Regulation (GDPR).
Where such conduct occurs within the economic relationship between platform and user, it may also constitute:
an unfair commercial practice under consumer protection legislation;
an infringement of competition law; and conduct capable of distorting competition within digital markets.
Against this background, the Consiglio di Stato (Council of State) recognises that personal data now possess a dual legal nature.
On the one hand, they constitute a legal asset intrinsically linked to the individual and deserving of enhanced protection under both European and national law.
On the other hand, they represent an economic asset with significant commercial value.
It is precisely this dual nature that requires a higher level of legal protection and greater scrutiny of the manner in which users are informed and enabled to make genuinely free and informed choices.
The judgment therefore embraces a substantive concept of transparency.
It is no longer sufficient for information merely to be formally available within lengthy privacy notices or contractual documentation.
Rather, information must be genuinely understandable and capable of enabling individuals to make informed decisions.
This approach has important practical implications.
Businesses operating in the digital economy—and, more broadly, any organisation whose activities rely substantially on the processing of personal data—are required to rethink their approach to compliance.
Compliance can no longer be regarded simply as a documentary exercise but must instead become an integral component of the services provided.
Privacy notices must be clear and accessible, while consent mechanisms should be designed to eliminate any form of undue influence or manipulation.
Default settings must likewise respect users’ freedom of choice, ensuring transparent interaction between individuals and digital environments.
In this respect, the judgment is entirely consistent with the principle of privacy by design enshrined in Article 25 GDPR.
The protection of fundamental rights cannot be addressed only after the fact through complex privacy notices or corrective measures.
Instead, it must be embedded from the outset in the design of digital systems, interfaces and operational processes.
The issue is therefore no longer one of formal compliance alone, but of ensuring effective protection through the concrete implementation of the privacy by design principle.
Viewed from a broader perspective, however, the judgment appears to carry an even more profound message.
The Consiglio di Stato (Council of State) seems to extend to private digital businesses a principle traditionally associated with administrative law: transparency as a condition for the legitimacy of decision-making.
This recalls the famous statement by Filippo Turati, according to which the public administration should be a “glass house”.
Historically, this principle served to protect citizens from the exercise of public power.
Today, the Administrative Court appears to apply the same logic to digital platforms and private operators which, through the use of personal data, exercise considerable influence over users’ choices and materially affect their economic decisions.
The “glass house” envisaged by the judgment is therefore no longer confined to public administration.
It also becomes an obligation incumbent upon digital businesses.
Neither Italian law nor EU law prohibits companies from generating value through the processing of personal data.
However, both require that this activity be conducted transparently, fairly and with users’ informed awareness, through understandable information and systems designed to respect individuals’ rights.
From this perspective, the judgment represents a clear warning to businesses.
The management of personal data can no longer be viewed as a mere regulatory formality but must instead be regarded as an integral component of corporate legal responsibility and organisational governance.
Far from constituting a limitation on commercial activity, transparency emerges as a prerequisite for the legitimacy of digital business models and as an essential foundation for building trust between digital businesses and their users.


