Categories: Insights, Practice

Tag: DPIA, Garante Privacy, GDPR


28 Oct 2018

The European Data Protection Board “dialogues” with the Italian Data Protection Authority with regard to the DPIA

Background

Opinion 12/2018 adopted on 25 September 2018 by the European Data Protection Board or “EDPB”, has recently been made public. The EDPB is the body that is mainly in charge of ensuring a uniform and consistent application of EU Regulation 679/2016 on the protection of natural persons with regard to the processing of personal data (”GDPR”) in all member States. The EDPB succeeded the previous “Working Party 29” or “WP29” and has broader powers and new duties.

As part of its work of aligning the various internal practices, in the last few months the Supervisory Authorities of the member States submitted to the EDPB their list of “types of data processing” which require a prior “data protection impact assessment” (DPIA) as a condition for legality of the processing.

The Italian case

The list submitted by the Italian Data Protection Authority defines six types of processing that require that a DPIA be conducted beforehand. Specifically, these are:(i) processing of biometric data; (ii) processing of genetic data; (iii) processing carried out using innovative technologies; (iv) monitoring of employees; (v) “further processing of personal data” and (vi) processing that refers to a “specific legal basis”.

The EDPB answered the Italian Data Protection Authority with its own observations, some of which were of a general nature while others were of a detailed “prescriptive” nature.

Specifically regarding the processing of biometric and genetic data or processing carried out using new technologies, the EDPB considers that this type of processing is not in and of itself able to create a clear risk to the rights and freedoms of the data subjects. In its opinion, for a DPIA to be required, the presence of at least one more of the nine cases listed in the “Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679” adopted by Working Party 29 and commonly referred to as the WP248 guidelines (e.g.: processing that enables judgement of an individual based on profiling; systematic monitoring; matching of various data sets) is necessary.

On the other hand, the EDPB agrees with the Italian Data Protection Authority when the latter claims that systematic monitoring of individuals that are in and of themselves vulnerable, such as employees, constitutes processing that requires a DPIA.

Prospects

In conclusion, it will be interesting to see how the Italian Data Protection Authority will proceed: if it decides not to follow the “prescriptions” provided by the EDPB, Italy could be the first to be involved in a new dispute resolution mechanism by the Board, with the so-called “consistency mechanism” pursuant to Articles 63, 64 and 65 of the GDPR.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

6 Feb 2026

Pay equity and transparency: draft implementing decree presented

Italy is among the first Member States to have adopted the draft implementing legislative decree of EU Directive 2023/970, which yesterday received its initial approval from the Council…

30 Jan 2026

A conviction for stalking can justify dismissal for just cause

With Ordinance No. 32952 of 17 December 2025, the Italian Supreme Court, Labour Section, ruled that a final conviction for stalking and abuse can justify dismissal for just…

30 Jan 2026

We continue to be a Great Place to Work!

For the third consecutive year, De Luca & Partners has been awarded the prestigious Great Place to Work® certification, a significant recognition of the value we place on…

29 Jan 2026

Italian Supreme Court: Employer Monitoring and the Use of Corporate Chats for Disciplinary Purposes

Corporate chats “intended for work-related communications by employees accessing them through company accounts constitute work tools, pursuant to Article 4, paragraph 2, of Law No. 300 of 1970,…

28 Jan 2026

Anti-union conduct: the Supreme Court moves beyond formalism and focuses on substance

With order no. 789 of 14 January 2026, the Italian Supreme Court addressed the issue of anti-union conduct by employers in relation to information and consultation obligations on…

27 Jan 2026

DID YOU KNOW THAT… the use of artificial intelligence may justify a dismissal for objective justified reason?

With Judgment No. 9135 of November 19, 2025, the Labour Section of the Court of Rome held that the dismissal for objective justified reason (i.e. “giustificato motivo oggettivo”,…