> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Italy AGCOM + GDPR Sender Rules

> Italy's sender posture expanded from the country-requirements matrix: AGCOM's alphanumeric Sender-ID registry with pre-registration and the 3-character floor, the GDPR opt-in overlay on top, the Italian opt-out keyword family (FERMA / CANCELLA / FINE / ANNULLA), and the quiet-hours posture mapped to the Orbit surfaces you already own.

# Italy AGCOM + GDPR Sender Rules

Italy (`IT`) sits on two regimes at once. AGCOM — the Autorità per le
Garanzie nelle Comunicazioni, Italy's communications regulator — runs an
alphanumeric sender registry that pre-registers Sender IDs before
carriers will pass them, and it rejects Sender IDs shorter than 3
characters. On top of that registry, GDPR (with Italian implementing
data-protection guidance) layers an opt-in consent duty on marketing
sends. This page expands the IT posture from the
[country-requirements matrix](/compliance/country-requirements) so you
can close the Italian items deliberately instead of re-reading one JSON
blob per launch.

Italy is a **tenant-owned burden**. Orbit never mandates your posture —
it keeps the [country-rules reference](/compliance/country-requirements)
that feeds the send-time gates, and it gives you the consent ledger,
quiet-hours, and opt-out surfaces below. The legal posture is yours.

<Note>
  This page is documentation, not legal advice. AGCOM blocks
  unregistered alphanumeric senders at the carrier — traffic on a
  Sender ID with no approved IT entry does not deliver — and the
  opt-in duty under GDPR is enforced against the sender. Have counsel
  review your consent capture and FERMA handling; Orbit supplies the
  surfaces.
</Note>

***

## Accepted sender classes for Italy

Read the IT row of `GET /compliance/country-rules?country=IT` (see
[Country Compliance Requirements](/compliance/country-requirements)).
Consolidated:

| Rule | IT value | What it means for you |
| - | - | - |
| Sender types | `alphanumeric`, `long_code` | Both accepted. Alphanumeric is only usable on IT once it is registered with AGCOM — the registry regime is pre-registration, not dynamic. A long code bypasses the alphanumeric gate; other send gates still apply. |
| Registration | `required` | The send-time gate holds A2P SMS to IT on an alphanumeric sender until the IT entry is `approved`. File through [Sender-ID Registration](/compliance/sender-id-registration) and wait for approval before launch. |
| Sender-ID length | 3–11 characters | AGCOM rejects Sender IDs shorter than 3 characters even though the value parses — the same regulatory floor [Sender-ID Registration](/compliance/sender-id-registration) names alongside ANATEL (BR), OFCOM (UK), and BTRC (Bangladesh). Pick a brand name of at least 3 characters. |
| Marketing consent | GDPR — opt-in required | Italian marketing SMS (and any outbound marketing message treated as a commercial communication) is opt-in, not opt-out: consent must exist before dispatch. Record it in the consent ledger with `sms` scope. See the GDPR section below. |
| Opt-out keyword | Italian FERMA family mandatory | Every IT marketing message must accept the Italian opt-out vocabulary; the alias table maps `FERMA`, `CANCELLA`, `FINE`, `ANNULLA` to your suppression ledger. See the keyword section and [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table). |
| Quiet hours | Tenant-configured posture | Italy's marketing regime (the *consenso* tradition under GDPR) expects sends at reasonable hours, but no single statutory SMS window exists. Configure tenant quiet hours deliberately — see the quiet-hours section. |

***

## AGCOM's alphanumeric sender registry

AGCOM is the Italian communications regulator whose sender registry
drives the IT pre-registration regime. Italy moved to registry-based
alphanumeric sending: a Sender ID that appears as the "from" on an SMS
must be on file before the carriers pass it, and AGCOM blocks
unregistered alphanumeric senders at the carrier — this is not a
filtering posture you can negotiate with after the fact.

**The rules as they apply to your traffic:**

* **Pre-registration is required.** An alphanumeric Sender ID on an
  SMPP-routed channel into IT delivers only when the IT entry on your
  registration is `approved`. Before approval the send-time gate holds
  the traffic with `SENDER_ID_NOT_REGISTERED` or
  `SENDER_ID_NOT_APPROVED`; troubleshoot those codes with
  [Sender-ID Registration](/compliance/sender-id-registration).
* **The 3-character floor is regulatory.** AGCOM rejects Sender IDs
  shorter than 3 characters, the same floor enforced by ANATEL, OFCOM,
  and BTRC — the format rule is 3–11 characters, letters, digits, space,
  hyphen, and underscore. A two-letter abbreviation is not a viable IT
  sender.
* **The 2023 onboarding cadence.** AGCOM's registry onboarding follows
  the intake windows the registry opened in 2023 — submissions batch
  into those windows rather than clearing continuously. Budget approval
  lead time the way [Sender-ID Registration](/compliance/sender-id-registration)
  budgets pre-registration markets (days to weeks), submit well ahead
  of your launch date, and
  keep your [KYC documents](/compliance/documents-kyc) complete and
  current so a rejection-and-resubmit loop never consumes a whole
  window.

**Tenant-owned controls that map to the AGCOM rule:**

| AGCOM obligation | Orbit surface |
| - | - |
| Pre-register the alphanumeric Sender ID for IT | [Sender-ID Registration](/compliance/sender-id-registration) — `POST /compliance/sender-id-registrations` with a `country: "IT"` entry referencing your `doc_…` KYC documents; poll until `status: "approved"`. |
| Respect the 3-character floor | Sender-ID format validation on the registration flow — the floor is documented on [Sender-ID Registration](/compliance/sender-id-registration) alongside ANATEL/OFCOM/BTRC. |
| Pre-flight the sender before filing | `GET /compliance/check?sender_id=<id>&country=IT` — answers "can this Sender ID work in IT?" before you file. |

***

## GDPR opt-in overlay on the registry

AGCOM's registry is a sender-identity regime, not a consent regime.
The GDPR consent duty applies on top of it, under the parent EU
posture in the [GDPR Posture Guide](/compliance/gdpr-posture-guide) —
registering the sender never substitutes for consent.

* **Marketing SMS into IT is opt-in.** Consent must exist before
  dispatch; record it with `sms` scope per `(contact, channel)` through
  [Consent Management](/compliance/consent-management), with
  `lawful_basis` set.
* **Evidence and withdrawal.** The consent ledger is your
  proof-of-record — exportable through
  [Export Consent & Suppression Records](/compliance/consent-suppression-export) —
  and withdrawal lands on the suppression list every send reads.
* **Register and posture together.** A fully-registered AGCOM sender
  with no consent records is still a non-compliant IT posture; consent
  with an unregistered sender never delivers. Both surfaces close the
  IT row.

***

## Quiet-hours posture for Italian marketing

Italy's marketing-convention regime — the *consenso* posture around
GDPR — treats marketing sends at unreasonable hours as violations of
the consent you captured, but unlike FR's statutory 20:00–08:00 window
there is no single codified Italian SMS window to point at. The posture
is deliberate configuration, not a default Orbit sets for you.

| Surface | Behaviour for IT |
| - | - |
| Tenant quiet hours (deliberate) | [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — opt-in tenant control, default **OFF / fail-open**; configure a window covering Europe/Rome overnight hours if you want the platform to hold IT marketing sends. Nothing in Orbit defaults this on. |
| Platform default (fallback) | When no tenant window is set, drip/journey sends inherit the platform default 21:00–09:00 recipient local — a fallback that incidentally covers a conservative Italian window, not a tenant guarantee. |

Because the IT regime grounds this in consent context rather than a
fixed window, the defensible posture is: tenant quiet hours ON with a
window your counsel accepts for IT marketing, paired with the consent
records that make the rest of the day permissible.

***

## Italian-language opt-out keyword handling

The [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table)
includes the Italian opt-out vocabulary: `FERMA`, `CANCELLA`, `FINE`,
`ANNULLA`, matched with locale-insensitive case-folding and Unicode
normalisation — a recipient replying `ferma` or `Ferma.` matches the
same opt-out rule. The Italian opt-in counterpart (`INIZIA`, `SÌ`,
`SI`, `ISCRIVITI`) re-subscribes after a prior opt-out.

When an Italian opt-out fires, the suppression entry it writes is
channel-scoped to `all`, not `sms` — the same propagation behaviour as
the English `STOP` alias. A recipient's `FERMA` knocks that contact off
SMS, WhatsApp, and RCS simultaneously: the opt-out is a request to stop
being contacted, not a request to stop SMS. If you have pruned the
seeded Italian rules in the dashboard, re-add them under
**Messages → SMS → Opt-out Rules** before launching IT traffic.

***

## Posture-FAQ tuple for Italy

When you answer "what does Italy need?" against the
[Posture FAQ](/compliance/posture-faq), the IT-specific tuple is:

* **Default quiet-hours window**: platform fallback 21:00–09:00
  (fail-open fallback only — configure tenant hours deliberately).
* **Opt-in required before marketing**: yes (GDPR, per the
  [GDPR Posture Guide](/compliance/gdpr-posture-guide)).
* **Sender registration level**: `required` (AGCOM pre-registration;
  3-character minimum Sender-ID length).
* **Opt-out keyword family**: Italian `FERMA`, `CANCELLA`, `FINE`,
  `ANNULLA`.
* **Official law**: [GDPR (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj);
  AGCOM is the Italian regulator for sender registration.

***

## Worked configuration to a defensible IT posture

Narrowed from the generic launch checklist in
[Country Compliance Requirements](/compliance/country-requirements) to
the IT row:

<Steps>
  <Step title="Look up the IT row">
    Call `GET /compliance/country-rules?channel=sms&region=EU` and read
    the IT row's `sender_types`, `registration`, `content_restrictions`,
    and `stop_requirement`.
  </Step>

  <Step title="Pick a sender type">
    Alphanumeric Sender ID (pre-registered with AGCOM) or a long code —
    both are accepted in IT. Pick an alphanumeric brand of at least 3
    characters.
  </Step>

  <Step title="Pre-flight then file the Sender ID">
    `GET /compliance/check?sender_id=<id>&country=IT` to confirm the
    sender is viable, then `POST /compliance/sender-id-registrations`
    with a `country: "IT"` entry. Budget for the AGCOM registry
    onboarding cadence — days to weeks, batched into the registry
    windows. See [Sender-ID Registration](/compliance/sender-id-registration).
  </Step>

  <Step title="Capture marketing opt-in first">
    Record a consent entry with `sms` scope before any IT marketing
    send; IT is opt-in under GDPR, not opt-out. See
    [Consent Management](/compliance/consent-management) and the
    [GDPR Posture Guide](/compliance/gdpr-posture-guide).
  </Step>

  <Step title="Set tenant quiet hours deliberately">
    Turn on tenant quiet hours covering a window your counsel accepts
    for IT marketing (a conservative start is 21:00–09:00 Europe/Rome).
    Orbit defaults this off. See
    [Quiet-Hours Configuration](/guides/quiet-hours-configuration).
  </Step>

  <Step title="Wire the Italian opt-out family">
    Confirm `FERMA`, `CANCELLA`, `FINE`, `ANNULLA` are mapped into the
    alias table and write suppression entries. See
    [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table).
  </Step>

  <Step title="Launch">
    With the IT sender `approved`, consent captured, quiet hours set,
    and the Italian aliases wired, start sending.
  </Step>
</Steps>

***

## Related references

* [Country Compliance Requirements](/compliance/country-requirements) —
  the full matrix this page expands one row of.
* [GDPR Posture Guide](/compliance/gdpr-posture-guide) — the parent EU
  consent and data-residency posture behind IT's opt-in rule.
* [Sender-ID Registration](/compliance/sender-id-registration) — the
  submit-and-track flow for the IT `required` registration, the 3–11
  character format rules, and the lead-time table.
* [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) —
  the Italian FERMA and verb-form aliases.
* [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — the
  tenant-owned opt-in control you use to cover the IT window.
* [Consent Management](/compliance/consent-management) — where the IT
  marketing opt-in record lives.
* [Send Gates](/compliance/send-gates) — the send-time enforcement the
  IT `required` registration feeds.
