Operational notes Regulation

Pay Transparency: From 7 June 2027 the Gap Must Be Declared, Payslips Included

6 min read

A brass two-pan balance scale, perfectly level, resting on a wooden shelf
The pay gap is measured in balance, but weighing it means opening every single payslip.

On 7 June 2027, companies with at least 250 employees must submit their first annual report on the gender pay gap; those with between 150 and 249 employees face the same date, but only every three years. This follows from Article 9 of Legislative Decree no. 96 of 7 May 2026 (Official Gazette no. 125 of 1 June 2026, in force since 7 June 2026), which transposes Directive (EU) 2023/970 on pay transparency. From today, 24 July 2026, that is under eleven months away. The point almost no HR department has yet grasped isn’t the deadline itself: it’s that producing that report means cross-referencing, person by person, payslip, job grade, gender, bonuses, and pay progression after parental leave. It is the most sensitive body of data a company holds after its trade secrets — and the very decree that requires calculating it, in Article 11, also requires protecting it.

The thresholds in full, not just “150 employees”

The decree sets out three bands, not two (Article 9): above 250 employees, an annual report from 7 June 2027; between 150 and 249, the same first deadline of 7 June 2027, but then every three years; between 100 and 149, a later start, 7 June 2031, again on a three-year cycle. Below 100 employees there is no reporting obligation. But for every company, with no minimum threshold, another obligation is already active today, not in 2027.

The right that is already law, today

That is Article 7: any worker may request in writing the average pay levels, broken down by gender, for categories of workers performing equal work or work of equal value; a reply is due within two months, and the employer may discharge the duty by publishing the data on an internal network or a restricted area of the company website. The same article bans clauses that prevent a worker from disclosing their own pay: “workers may not be prevented from disclosing their own remuneration.” Anyone still enforcing salary-secrecy clauses in individual contracts has been acting unlawfully since 7 June 2026.

The scenario that keeps recurring

This is a pattern we see recur often, not the account of one specific case — a typical model of how these deadlines get handled when they arrive at the last minute. HR has to prepare the first report within a few months; the file with name, role, salary, bonus and gender for every employee already exists in the payroll system, but cross-referencing it by quartile and category takes work the office has no time to do by hand. The most common shortcut: upload the payroll export to a cloud people-analytics tool, or email it to an external consultant, to “get it done faster”. The report comes out on time. But the file that produced it — names, salaries, gender, leave history for each person — has already left the company perimeter, without anyone deciding so at policy level. It is the same pattern already seen when a confidential price list ends up pasted into a public chatbot to close a deal faster: the data changes, the mechanism stays identical.

The paradox the rule itself points to

This is where the decree proves wrong anyone who thinks the only risk is missing the deadline. Article 11, headed precisely “Data protection”, requires that access to individual pay information stay restricted to workers’ representatives, the Labour Inspectorate and the territorial equality adviser, and only where disclosure would not identify the individual worker; the data cannot be used for purposes other than implementing equal pay; all of it subject to the GDPR (Regulation (EU) 2016/679). The legislator does not simply ask for a number: it draws, itself, a tight perimeter around the data needed to calculate it. A company that meets the deadline by routing everyone’s payslips through an unvetted external SaaS tool, or as an email attachment to a consultant, obtains the report — and breaches, in the same moment, the spirit of the very article that made it mandatory. It is the same caution the Italian data protection authority has already shown over employees’ emotional data read from workplace chats: pay data and emotional data about workers share the same principle — if it isn’t needed by whoever processes it, it shouldn’t pass through their hands.

The 5% and the burden of proof

The report doesn’t end up in a drawer. Article 10 requires a joint assessment with workers’ representatives whenever the data reveals “an average pay difference between female and male workers of at least 5%” within a category, if the employer fails to justify it “on the basis of objective, gender-neutral criteria” within six months. If the dispute reaches court, Article 12 refers to the Equal Opportunities Code (Legislative Decree 198/2006): its Article 40 shifts the burden of proof onto the employer as soon as the worker provides factual elements — even purely statistical ones — suggestive of gender discrimination. From that moment, it is the company that must prove the gap does not exist, or is justified — under pressure, if the objective criteria weren’t already written down beforehand.

What to do now

  1. Map every source of pay data: payroll, HR systems, spreadsheets held by external consultants, time-and-attendance systems — the same map needed for the GDPR record of processing activities, using the same approach applied to shadow AI: map it, don’t ban it.
  2. Define who sees what, inside and outside the company, aligning the internal perimeter with Article 11: if the rule itself restricts access to representatives and the inspectorate, day-to-day access for HR, the payroll provider and consultants should be restricted to at least the same level.
  3. Prepare objective, gender-neutral criteria now for job grading and progression — skills, seniority, responsibility, performance — before a gap emerges and has to be justified within six months, not improvised once the inspectorate’s letter has already arrived.
  4. Document the training of whoever processes this data: it is the material proof, in an inspection or a dispute, that processing was under control from the outset, not tidied up afterwards.

How we solve it

The thread is the same one running through every article in this series: a company’s most sensitive data cannot pass through tools the company itself does not fully control. That’s why we build pay-gap analysis with a dedicated, closed AI, disconnected from the open web, in the two modes of our offering: on-premises, within the client’s own environment, or from our dedicated cloud — an environment reserved for the single client, dedicated VPN access, a data centre resident in Italy, premises we staff directly. Either way, payroll never leaves the company’s own perimeter, and the perimeter Article 11 sets out on paper — who sees what, for what purpose — is built into the architecture, not promised in a policy. It’s the principle our platform is built on, the same one guiding every operational trial: you start from data that stays yours.

Do you need to prepare the first gender pay gap report and aren’t sure how to move the data without letting it leave the perimeter? Half an hour with one of our experts is enough for the first map.

Sources