Categories: Insights, Practice

Tag: Autorità Garante, GDPR, Medico Competente


31 Aug 2020

Company Physician: Independent data controller

On 23 June 2020, the Italian Data Protection Authority (“Garante“) published the “2019 Annual Report” (the “Report“) listing activities carried out during the previous calendar year.

With the publication of the Report, the Data Protection Authority has confirmed what had already been stated in the note ref. no. 7797, dated 27 February 2019, concerning the subjective qualification of the Company Physician (as defined by art. 38 of Legislative Decree 81/2008, the “Decree”)

It is necessary to make a brief introduction to better understand the issue.

Article 4 of the (EU) Personal Data Protection Regulation (the “Regulation“) defines the Data Controller as (i) “the individual or legal person, public authority, service or other body which, individually or jointly with others, determines the personal data processing purposes and means” and the Data Processor as (ii) “the individual or legal person, public authority, service or other body which processes personal data on behalf of the data controller.”

Since the first interpretations and applications of the Regulation, the legal theory opened a debate on the Company Physician’s correct subjective qualification for data processing carried out during the functions and tasks assigned by the Decree.

The legal theory

Part of the theory suggested that the Company Physician was a Data Processor (under art. 28 of the Regulation), and the employer was the sole Data Controller which has the task of determining the purposes and means of the processing carried out by the professional. This theory was based on the relationship between the employer and the Company Physician was regulated by a contract by which the latter was expressly authorised by the employer to carry out employee personal data processing (including data belonging to special categories, formerly “sensitive” data).

Conversely, a different part of the theory stated the Company Physician was an independent Data Controller, as the processing purposes were established by the Decree and not by the employer.

The Data Protection Authority’s position

This latter idea was expressly confirmed by the Data Protection Authority, which qualifies the Company Physician as an independent Data Controller. The type of processing carried out by the professional (for example, health monitoring or preparing health records) is their prerogative and not the employer’s.

In terms of sanctions, according to the Data Protection Authority, the regulatory framework makes a precise distinction between the employer and Company Physician’s responsibilities.

Others Insights related:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

8 Apr 2026

Management of corporate email after termination of employment: the limits according to the Italian Data Protection Authority

The Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) has once again provided guidance on how employers should manage corporate email accounts after the…

8 Apr 2026

Oral dismissal: the burden of proof on the employee

With order no. 4077 of 23 February 2026, the Italian Supreme Court addressed the issue of oral dismissal, holding that an employee challenging the termination of the employment…

8 Apr 2026

DID YOU KNOW THAT… incompatibility between colleagues may justify the transfer of an employee? 

The Italian Supreme Court, with order no. 4198 of 25 February 2026, held that an employee’s transfer may be lawfully implemented also in the presence of a situation…

7 Apr 2026

The boundary between rest and inactivity in the management of working hours (AIDP – HR Online, 7 aprile 2026 – Vittorio De Luca, Alesia Hima)

In the organizational language of companies, terms such as “breaks,” “waiting times,” or “downtime” are often used. In operational practice, these expressions tend to be treated almost as…

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…