Categories: Insights, Publications · News, Publications

Tag: GDPR


29 Oct 2024

Data Breach: Lessons for Companies from Recent Investigations (Il Sole 24 Ore Radiocor – Vittorio De Luca, Martina De Angeli)

The revelations from the investigation conducted by the Milan Prosecutor’s Office and the investigative unit of the Carabinieri of Varese—exposing unlawful activities involving the acquisition of confidential, sensitive, and personal information—have dominated Italy’s political and public debate in recent hours. These developments call for serious reflection.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has responded by establishing an interdepartmental task force to promptly identify appropriate actions and implement stronger protections for databases. This task force aims, among other objectives, to define adequate technical and organizational security measures for database access by authorized personnel, as well as for the operations performed by those responsible for their management and maintenance.

As we await further updates, here’s what companies need to know and do in similar situations:

  • Internal investigations, containment, and evaluation.
    Upon discovering a data breach, it is critical to identify the incident, evaluate its scope and impact on personal data, and determine its cause to address any vulnerabilities.
  • Notification obligations.
    • To the Data Protection Authority: Organizations must notify the breach to the Garante within 72 hours of becoming aware of it unless the breach is unlikely to pose a risk to the rights and freedoms of individuals.
    • To the affected individuals: If the breach creates a high risk for the people involved, they must be informed without undue delay.
  • Violation register.
    Maintain a record of the breach, including its nature, effects, and corrective measures taken. This is essential for compliance and subsequent audits.
  • Implement corrective measures.
    Take steps to enhance data security and prevent future breaches, such as revising security protocols and initiating employee training programs.
  • Review and update policies.
    After addressing the breach, it is essential to review and strengthen the company’s data protection policies and response plans.
  • Continuous monitoring.
    Activate systems to monitor data processes continuously to detect and respond to any future incidents promptly.
  • Training.
    Security measures must be supported by proper employee training to ensure effective implementation in daily operations.

It is essential to emphasize that, if a data breach has occurred, pre-existing measures were insufficient and must be reassessed and enhanced. This is a fundamental goal of the Data Breach procedure.

As highlighted earlier, recent developments should prompt reflection. Information and data are increasingly valuable assets, and ensuring their technical and organizational security is a critical priority for businesses. Companies must view investments in advanced, continually updated security measures as vital, not optional. These efforts ultimately benefit business performance and corporate reputation.

Press Review:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

8 Apr 2026

Management of corporate email after termination of employment: the limits according to the Italian Data Protection Authority

The Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) has once again provided guidance on how employers should manage corporate email accounts after the…

8 Apr 2026

Oral dismissal: the burden of proof on the employee

With order no. 4077 of 23 February 2026, the Italian Supreme Court addressed the issue of oral dismissal, holding that an employee challenging the termination of the employment…

8 Apr 2026

DID YOU KNOW THAT… incompatibility between colleagues may justify the transfer of an employee? 

The Italian Supreme Court, with order no. 4198 of 25 February 2026, held that an employee’s transfer may be lawfully implemented also in the presence of a situation…

7 Apr 2026

The boundary between rest and inactivity in the management of working hours (AIDP – HR Online, 7 April 2026 – Vittorio De Luca, Alesia Hima)

In the organizational language of companies, terms such as “breaks,” “waiting times,” or “downtime” are often used. In operational practice, these expressions tend to be treated almost as…

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 March 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

10 Mar 2026

The transfer of the employee is lawful when there is incompatibility with the company environment (Camera di Commercio Italo-Francese, 10 March 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 4198 of 25 February 2026, the Italian Supreme Court (Court of Cassation) – Labour Section – reaffirmed that a situation of environmental incompatibility may justify…