Alessandro Del Ninno
News
Web scraping and collective redress: the Court of Milan admits the privacy class action against Meta.
DATA PROTECTION
29/07/2026

The Court of Milan, Civil Section XIV – Specialised Business Section ‘A’, Case No. 1251/2026, has declared admissible the representative action brought by a consumers’ association against Meta, seeking compensation for damages allegedly suffered by Facebook users as a result of the mass collection of personal data carried out by third parties using web scraping techniques.

At this stage, the decision concerns solely the admissibility of the action. Meta’s actual liability and the existence of the alleged damages will have to be determined in the subsequent proceedings on the merits.

According to the argument accepted for the purposes of admissibility, the platform’s liability could stem from the inadequacy of the technical and organisational measures adopted to prevent or limit the unauthorised extraction of users’ data. The claim therefore concerns not only the security obligations laid down in the GDPR, but also the principles of data protection by design and by default, as set out in Article 25 of the Regulation.

The order of the Court of Milan represents one of the first significant points of convergence, in Italian case law, between the liability regime provided for by the GDPR and the rules governing consumer representative actions.  The issue takes on particular significance in light of the recent Guidelines 03/2026 on web scraping in the context of generative artificial intelligence, which highlight the need to assess the risks associated with the online availability of personal data and to put in place adequate measures against automated mass data collection activities. In relation to the same incident, Meta had already been the subject of a penalty decision by the Irish Data Protection Commission.

The order raises at least three points of particular interest. Firstly, the Court recognised the consumer association’s standing to bring proceedings without the need to obtain a specific mandate in advance from each data subject. This conclusion is based on the very purpose of representative action, which is designed to ensure effective and high-level protection of consumers’ collective interests. Secondly, the decision is in line with the case law of the Court of Justice of the European Union on compensation for damage resulting from breaches of the GDPR. The loss of control over one’s personal data may constitute non-pecuniary damage eligible for compensation without it being necessary to demonstrate that a minimum threshold of seriousness or tolerability has been exceeded. It remains necessary, however, to establish, for each category of data subject, the actual existence of the damage and the causal link with the alleged breach. Finally, the requirement for the homogeneity of rights asserted collectively may be met even where the same conduct gives rise to different harmful consequences. It is possible to identify sub-groups of users affected by specific types of harm, provided that the relevant damages can be assessed using sufficiently uniform and standardisable criteria.

The ruling significantly broadens the scope of the risk associated with breaches of data protection legislation. In addition to administrative sanctions and possible corrective measures imposed by supervisory authorities, there may also be civil liability pursued on a collective basis, with potentially very significant economic, reputational and organisational consequences.

This risk does not apply solely to large digital platforms. It may affect any business that makes personal data available online, manages portals or restricted areas, uses application programming interfaces, exposes databases accessible from outside the organisation, or processes large quantities of information susceptible to automated extraction.