WalletWallet API
Back to Blog

Digital Membership Cards for Italian Associations: The Rules and the Build

What Italian law actually requires of cultural association membership cards, what changed on 1 January 2026, and how to issue member cards to Apple Wallet and Google Wallet without writing code.

2026-08-06 By Alen Todorov

In Italy, access to a cultural association’s activities almost always runs through a membership card. Someone joins, receives a card, and shows it at the door. This guide explains which rules actually produce that mechanism, what changed for cultural associations on 1 January 2026, and how to issue the card straight into Apple Wallet and Google Wallet without writing code.

It is written for whoever runs the membership side of an association, and for the agency or developer they hand the job to. Nothing in the walkthrough needs code. The Italian version, linked at the top of the page, is the one to forward to a board or a commercialista.

One caveat: this is a technical article written by the people who build the card infrastructure, not tax or legal advice. The rules cited here explain why a given technical flow makes sense. For an association’s actual fiscal position, its commercialista is the right call.

Evening under the arcades in Turin

Why an Italian association checks a card at the door

The starting point is not a rule about cards but article 148, comma 1 of the TUIR (DPR 917/1986), the Italian income tax code:

Activity carried out toward members or participants, in conformity with institutional purposes, by associations, consortia, and other non-commercial associative bodies is not considered commercial.

The boundary that matters is the boundary of the membership base. Institutional activity aimed at members sits outside the commercial sphere; the same activity aimed at someone who is not a member sits inside it, even when it is the same room, the same evening, and the same fee.

Everything else follows from that. Mandatory membership before entering the venue, the check at the door, the distinction between a members-only event and one open to the public.

Comma 3 of the same article extends non-commercial treatment to corrispettivi specifici, meaning what a member pays beyond the base membership dues for activities carried out in direct implementation of institutional purposes: courses, workshops, guided visits, screenings. For most associations this is the commercially significant part, because dues are small and activity fees are where the money actually is.

Comma 8 makes all of it conditional on specific statutory clauses, among them a ban on distributing profits, devolution of assets on dissolution, uniform governance of the membership relationship with temporary participation excluded, elective and democratic offices, and membership shares that cannot be transferred except on death.

That exclusion of temporary participation is the technical reason the problem cannot be solved with a ticket valid for one evening. The membership relationship runs for a anno sociale, a membership year, and the card is the practical representation of that relationship.

What changed on 1 January 2026

Titolo X (articles 79 to 89) of the Codice del Terzo Settore, D.Lgs. 117/2017, came into force on 1 January 2026, after the European Commission’s comfort letter of 7 March 2025 cleared the reform’s tax provisions.

For cultural associations the consequence is direct. Article 89, comma 4 of the Codice del Terzo Settore amends article 148, comma 3 of the TUIR by removing culturali (cultural) and di formazione extra-scolastica della persona (extra-scholastic personal training) associations from the list of bodies whose specific fees are de-commercialised. The amendment was drafted in 2017, but its effect was tied to the start date of Titolo X, so it only began to bite in 2026.

In practice, a cultural association that stays outside the RUNTS (the national Third Sector register) loses de-commercialisation of the specific fees its members pay. The route that preserves a favourable regime is registering in the RUNTS as an ETS, typically as an associazione di promozione sociale, which moves the body under article 85 of the Code: activities carried out toward its own iscritti, associati, and their cohabiting family members against specific fees, in direct implementation of institutional purposes, are not treated as commercial.

The Agenzia delle Entrate published its guidance on the new regime in circolare n. 1/E of 19 February 2026, covering non-commerciality criteria, the fiscal qualification of entities, flat-rate regimes, and the transition from ONLUS status to the RUNTS.

The point that matters when designing the system: whichever of the two routes an association takes, the benefit stays anchored to member status. After 2026 an association has to be able to demonstrate, with more precision than before, who was a member in good standing on a specific date.

VAT did not change

Article 4, comma 4 of DPR 633/1972 continues to exclude members’ specific fees for institutional activity from the scope of VAT.

The switch from an exclusion regime to an exemption regime, set out in article 5, comma 15-quater of DL 146/2021, was postponed to 1 January 2036 by D.Lgs. 4 December 2025, n. 186, published in the Gazzetta Ufficiale on 12 December 2025 and in force the following day. Operations stay excluded through 31 December 2035.

The difference matters: exclusion means being outside the VAT system, exemption means being inside it, with a VAT number and the compliance that follows, and it would have pulled in bodies that today sit outside entirely. The postponement runs ten years.

For cultural associations, direct-tax treatment changed in 2026 while VAT treatment stayed as it was.

The law does not require a card, it requires a members’ register

No Italian rule requires a membership card as an object, neither cardboard nor digital. What the rules require is a register and a procedure.

Article 15 of the Codice del Terzo Settore lists the mandatory social books. Under comma 1, Third Sector entities must keep, beyond the records required by articles 13, 14 and 17 comma 1:

  • the libro degli associati o aderenti, the register of members;
  • the book of assembly proceedings and resolutions, into which minutes drawn up as a public deed must also be transcribed;
  • the book of proceedings and resolutions of the administrative body, the control body, and any other social bodies.

The first two are kept by the administrative body. Members have the right to inspect them per the statute. Third Sector social books are exempt from stamp duty and from the vidimazione requirement.

Article 23 governs admission: a new member is admitted by resolution of the administrative body on the applicant’s request, and that resolution is communicated to the applicant and annotated in the register of members. A rejection must be reasoned and communicated within sixty days, and the applicant may ask the assembly to rule on the matter within sixty days of that communication.

Article 21 requires the statute to state the requirements for admitting new members and the relevant procedure, on non-discriminatory criteria consistent with the general-interest activity carried out.

The register is what proves membership legally, and the card is what proves it at the door. They are two representations of the same fact and they have to agree.

A card printed in January stays identical to itself even after the member has lapsed, while a card connected to the system holding the register can be updated or revoked the moment the underlying record changes.

What a membership card has to be able to do

Translated into technical requirements, the rules above produce this list:

  1. Identify the member uniquely, in a way that links back to their row in the register.
  2. Carry an expiry aligned to the membership year, because participation is neither temporary nor perpetual.
  3. Be verifiable at the door in seconds, by a volunteer, on a weak connection.
  4. Be revocable when a member lapses, withdraws, or is expelled.
  5. Be renewable without issuing a new object.
  6. Carry the minimum of personal data, per the minimisation principle in article 5(1)(c) of Regulation (EU) 2016/679.

The card is a copy of personal data living on the member’s phone, outside the association’s control. The barcode should carry an opaque identifier, not a codice fiscale and not an email address. The sensitive fields stay in the association’s own system, where that identifier resolves them.

The available options

Printed card. Cheap for the first year and free to issue in software terms. It has none of properties 4, 5 and 6: it cannot be revoked, it can only be renewed by reprinting, and once handed over it never updates. For an association that has to demonstrate who was a member in good standing on a given date, it is the worst possible starting point.

A dedicated app. Solves the problem on paper, but it asks the member to install an app for a card they will use six times a year, and the association to maintain two app store listings. For a body with 300 or 800 members the cost-to-benefit ratio does not work.

Apple Wallet and Google Wallet handled directly. Technically the right destination, because the wallet is already installed on every phone and the card fits inside it with an expiry, a barcode, and push updates. The problem is the entry cost: an Apple Developer account at 99 EUR a year, a Pass Type ID certificate to renew, the WWDR chain, a Google Wallet issuer account, and pass signing. For a volunteer-run association that is a real barrier, and more to the point one that returns every year when the certificate expires.

Loyalty marketing platforms. Products exist that issue wallet passes as part of a retail marketing suite. They work, but they are sized and priced for commercial chains, and the piece the association needs (issue, renew, revoke) is a fraction of what gets paid for.

WalletWallet, which is the product we build, covers exactly that piece. A card is built in a browser and issued to Apple Wallet and Google Wallet at once, with no Apple Developer account and no Google issuer, because passes are signed with our Pass Type ID and certificate chain. The free plan covers 1,000 passes a month, which for the overwhelming majority of Italian cultural associations means free outright: a body with 850 members a year stays well under the threshold even counting renewals and reissues. The rest of this guide is that flow, and there is a REST API underneath it for associations that already run a membership database.

Issuing the card

The right moment to issue is the administrative body’s admission resolution, not the payment. Payment of dues can precede admission; it is the annotation in the register that makes someone a member. If the association records the two events separately, issue on the second.

The card itself is built in the Pass Editor, with the finished card rendered beside the form as you type.

The WalletWallet Pass Editor with an Italian membership card being filled in

The fields map onto the tessera the way an association already thinks about it:

  • Logo Text and Organization Name carry the association’s name.
  • Primary Fields hold the member’s name, which is what a volunteer reads at the door.
  • Secondary Fields hold the card number and the end of the membership year.
  • Back Fields take everything that does not belong on the front: the anno sociale, the membership category, the registered office, links to the statute and the privacy notice.
  • The barcode takes the opaque member identifier.
  • Expiration bounds the card to the membership year without any further step.

One button issues it to both wallets at once.

The Generate button in the Pass Editor

Getting the card to the member

Issuing produces a share page.

The Share tab showing a QR code and a share link for the issued card

The page detects the device: on an iPhone it offers Add to Apple Wallet, on Android Save to Google Wallet, and on a desktop it shows a QR to scan with the phone. Put that one link in the admission confirmation email and the member does the rest, with no attachment and no separate instructions per platform.

The membership list

Every card issued on the account sits in the Pass Manager, searchable by name, card number or serial.

The Pass Manager listing five Aurora APS membership cards

Each row carries the three operations the membership year actually needs.

The Share, Edit and Revoke actions on a membership card row

Renewal

Renewal is an edit rather than a reissue. Open the card with Edit, change the end of the membership year and the expiry, and save. The card already on the member’s phone updates in place, so nobody is asked to install anything again and no January turns into a distribution campaign.

On iPhone the lock screen shows the change message with the new value substituted, for example “Tessera rinnovata, valida fino al 31/12/2027”. On Google Wallet the notification is generic and the updated card is visible on opening it.

Saving a card whose contents have not actually changed sends no notification and counts nothing against the plan, so working through the roster at renewal time is safe even if some members were already renewed.

The same edit covers a change of category during the year, from ordinary member to supporting member.

Revocation

When a member lapses for non-renewal, withdraws, or is expelled, Revoke on that row invalidates the card. On Apple Wallet the pass is rebuilt voided with a past expiry, so it loses its barcode and files under the member’s expired passes. On Google Wallet the object is set to expired. On both, the card stays in the member’s wallet marked invalid until they remove it themselves, because neither wallet lets an issuer reach in and delete something from a phone.

Revocation cannot be undone. If the member rejoins later, issue a new card.

It is worth revoking even when the expiry would have run out anyway, because it makes the state explicit instead of leaving it to be inferred from a date.

Verification at the door

The barcode carries the member’s opaque identifier. Anything that reads a QR will read it, including our free pass scanner, which takes a camera frame or a screenshot and returns the barcode format and the exact decoded value.

The free WalletWallet pass scanner with the camera view open, ready to read a pass barcode

It is enough to test a card and confirm what a reader will see, and the fastest way to check that the value you put in the barcode is the value that comes back out.

For the door itself, the check has to end at the register rather than at the card. If the two ever diverge, for example because a member was expelled yesterday and has not opened their phone since, the register is the one that has to win.

Obligations the card does not discharge

The card is the visible part of a set of obligations that remain with the association:

  • The privacy notice, which has to cover the data the card carries and the fact that it lives on the member’s own device.
  • Modello EAS, under article 30 of DL 185/2008 as converted by L. 2/2009, for associative bodies relying on the article 148 TUIR and article 4 DPR 633/1972 treatment. Filed within 60 days of formation, updated by 31 March of the year following any change, and re-filed within 60 days completing the Perdita dei requisiti section when the qualifying requirements are lost.
  • Social books kept under article 15 of the Codice del Terzo Settore.

None of these obligations is discharged by issuing a card, digital or printed. The card makes them easier to meet, because it keeps the underlying data aligned.

Implementation checklist

  1. Confirm with the association’s commercialista which regime applies after 1 January 2026, and specifically whether RUNTS registration is the right route.
  2. Define the opaque member identifier and make sure it carries no personal data.
  3. Issue on the admission resolution, not on the payment.
  4. Set the expiry to the end of the membership year.
  5. Send the share link in the confirmation email, with no attachment.
  6. Work the annual renewal through the membership list as edits, not reissues.
  7. Revoke when a member comes off the register.
  8. Make door verification query the register, not the card.
  9. Update the privacy notice with the data the card carries and the fact that it lives on the member’s device.

If you already have a membership system

Everything above is also available as a REST API, which is the right path when the association already runs a membership database and wants the card to follow it without anyone opening a dashboard. Each card keeps a serial number, shown in the list under the card number, and it is the identity of that card for its whole life. Three calls cover the rest:

  • POST /api/passes issues it, and returns the serial number and the share link to put in the admission email.
  • PUT /api/passes/<serial> replaces its contents, which is the annual renewal and the change of category, and is free and silent when the body is unchanged.
  • DELETE /api/passes/<serial> revokes it.

Store the serial number next to the member’s row and the three calls line up with the three moments in the register. The full request and response shapes are in the docs.

Getting started

To issue the first tessera, sign up and open the Pass Editor.

Build your first wallet pass

Turn one JSON request into a pass that installs in Apple Wallet and Google Wallet, with live updates that reach both.