Categories: Insights, Publications


19 Apr 2018

Privacy at work. New legislation entering into force on May 25, 2018 (Guida al Lavoro de Il Sole 24 Ore, 20 April 2018 – Vittorio De Luca, Elena Cannone, Antonella Iacobellis, Luciano Vella, Lucio Portaro)

The European Regulation on the Protection of Personal Data is entering into force.

Starting from 25 May , 2018, the European Regulation will be fully operative, introducing many news on the matter of privacy; news that companies will have to deal with on a daily basis. First of all, the accountability principle is introduced: more freedom for Data Controllers and Data Processors in the choice of the measures to be adopted but also greater responsibility, especially in view of the penalties established to protect compliance with the Regulations, which has become more severe. Second of all, the new Regulations redefine their territorial scope of application: in fact, companies outside Europe but processing personal data of parties located within the European Union will also be subjected to the application of the Regulation. In addition, the methods in which data are transmitted outside the European Union are carefully regulated. The new legislation, in addition to reaffirming some fundamental rights already known, establishes new ones, such as the so-called right to data portability and the so-called right to be forgotten which, although already known in practice, has been officially regulated for the first time. Another new aspect, which was much discussed, is the mandatory appointment, under certain conditions, of a Data Protection Officer (DPO) tasked with supervising the correctness of the fulfilments in this regard and of acting as a point of contact between the various parties involved (Data Controller, Data Subjects, and Supervisory Authorities). Moreover, again in order to strengthen compliance with the Regulation, if data processing may put at risk the rights of Data Subjects, the Data Controller, prior to processing the data, shall carry out a potential impact assessment (PIA), focused on the analysis of the probability and severity of the risk. Furthermore, from the provision of the Regulation, the system of notifications and communications of possible violations of personal data (so-called Data Breach), is well regulated. In short, the Regulation represents a clear response by the European legislator to the evolution that the concept of “privacy” is undergoing, especially in light of the ongoing industrial revolution. It will, however, have to deal with the legal institutions existing in our system, first of all art. 4 of the Workers’ Statute and Whistleblowing Law 179/2017.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

20 May 2026

Webinar “May 1st Decree: Key Updates and what’s New” –  HR Coffee with De Luca & Partners

On the occasion of our webinar “An HR Coffee with De Luca Partners,” the speakers Silvia Zulato, Senior Associate, and Alessandro Riccardo Polli from the Labour Consulting Division…

12 May 2026

Legitimate dismissal for false attendance reporting and misuse of access system data (Camera di Commercio Francese in Italia – Vittorio De Luca, Silvia Zulato)

With Order No. 7985 of 31 March 2026, the Italian Supreme Court – Labour Section – confirmed the lawfulness of a dismissal for just cause imposed on an…

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…

27 Apr 2026

Management of corporate email after termination of employment: the Italian Data Protection Authority extends the right of access to all emails in the individual email account 

“An employee may access the messages in their corporate email account and the documents stored on their computer after the termination of employment. Any limitations must be justified by specific…

27 Apr 2026

Unemployment benefits and resignation following transfer beyond 50 km: distance alone is not sufficient, employer’s breach must be proven  

With order no. 10559 of 21 April 2026, the Italian Supreme Court addressed the issue of unemployment benefits (i.e. “NASpI”) in the context of resignations for just cause following…

27 Apr 2026

DID YOU KNOW THAT… the probationary period clause is null and void if the duties are described in generic terms? 

The Court of Milan, with judgment no. 683 of 3 April 2026, reaffirmed that a probationary clause (i.e. “patto di prova”) is valid only if it contains a specific indication of the duties subject to…