Categories: Insights, Practice

Tag: Autorità Garante, Data Breach, EDPB


25 Feb 2021

Data Breach: The European Data Protection Authority Guidelines for handling data breaches.

The Italian Data Protection Authority, with the newsletter 472 of 25 January 2021, announced that on 14 January, the EDPB (“European Data Protection Board”) adopted new Guidelines (“Guidelines 01/2021 on Examples regarding Data Breach Notification”, the “Guidelines”) aimed at supporting companies and public administration in correctly addressing data breaches and defining risk management processes.

The document adds to the previous guidelines of Working Party 29 (“Guidelines on Personal data breach notification under Regulation 2016/679”) which, include a technical-theoretical analysis of what is prescribed by Regulation (EU) 2016/697 (the “Regulation”) about personal data breaches (or “Data Breach”).

Considering information security principles, recalling “Opinion 3/2014” and “Guidelines WP 250”, EDPB provides a classification of the type of breaches, namely:

  • “confidentiality breaches” – occur when there is an unauthorised disclosure of or access to personal data;
  • “integrity breaches” – occur when there is an unauthorised or accidental alteration of personal data;
  • “availability breaches” – occur when there is an accidental or loss of access to or destruction of personal data.

Aiming to provide useful guidance to data controllers and data processors on how to handle a personal data breach correctly, the Guidelines illustrate what to avoid (e.g. failure to encrypt data). They also contain numerous practical case studies involving hospitals, banks, businesses and online service companies of various kinds in different European countries.

These case studies describe the preventive measures that can be taken and suggest how to carry out a breach risk assessment, the potential measures that can be taken to reduce the risks and legal obligations that must be met.

EDPB launched a European public consultation on the document that will end on 2 March 2021.

Others insights related:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

6 Feb 2026

Pay equity and transparency: draft implementing decree presented

Italy is among the first Member States to have adopted the draft implementing legislative decree of EU Directive 2023/970, which yesterday received its initial approval from the Council…

30 Jan 2026

A conviction for stalking can justify dismissal for just cause

With Ordinance No. 32952 of 17 December 2025, the Italian Supreme Court, Labour Section, ruled that a final conviction for stalking and abuse can justify dismissal for just…

30 Jan 2026

We continue to be a Great Place to Work!

For the third consecutive year, De Luca & Partners has been awarded the prestigious Great Place to Work® certification, a significant recognition of the value we place on…

29 Jan 2026

Italian Supreme Court: Employer Monitoring and the Use of Corporate Chats for Disciplinary Purposes

Corporate chats “intended for work-related communications by employees accessing them through company accounts constitute work tools, pursuant to Article 4, paragraph 2, of Law No. 300 of 1970,…

28 Jan 2026

Anti-union conduct: the Supreme Court moves beyond formalism and focuses on substance

With order no. 789 of 14 January 2026, the Italian Supreme Court addressed the issue of anti-union conduct by employers in relation to information and consultation obligations on…

27 Jan 2026

DID YOU KNOW THAT… the use of artificial intelligence may justify a dismissal for objective justified reason?

With Judgment No. 9135 of November 19, 2025, the Labour Section of the Court of Rome held that the dismissal for objective justified reason (i.e. “giustificato motivo oggettivo”,…