Categories: Insights, Publications · News, Publications

Tag: GDPR


29 Oct 2024

Data Breach: Lessons for Companies from Recent Investigations (Il Sole 24 Ore Radiocor – Vittorio De Luca, Martina De Angeli)

The revelations from the investigation conducted by the Milan Prosecutor’s Office and the investigative unit of the Carabinieri of Varese—exposing unlawful activities involving the acquisition of confidential, sensitive, and personal information—have dominated Italy’s political and public debate in recent hours. These developments call for serious reflection.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has responded by establishing an interdepartmental task force to promptly identify appropriate actions and implement stronger protections for databases. This task force aims, among other objectives, to define adequate technical and organizational security measures for database access by authorized personnel, as well as for the operations performed by those responsible for their management and maintenance.

As we await further updates, here’s what companies need to know and do in similar situations:

  • Internal investigations, containment, and evaluation.
    Upon discovering a data breach, it is critical to identify the incident, evaluate its scope and impact on personal data, and determine its cause to address any vulnerabilities.
  • Notification obligations.
    • To the Data Protection Authority: Organizations must notify the breach to the Garante within 72 hours of becoming aware of it unless the breach is unlikely to pose a risk to the rights and freedoms of individuals.
    • To the affected individuals: If the breach creates a high risk for the people involved, they must be informed without undue delay.
  • Violation register.
    Maintain a record of the breach, including its nature, effects, and corrective measures taken. This is essential for compliance and subsequent audits.
  • Implement corrective measures.
    Take steps to enhance data security and prevent future breaches, such as revising security protocols and initiating employee training programs.
  • Review and update policies.
    After addressing the breach, it is essential to review and strengthen the company’s data protection policies and response plans.
  • Continuous monitoring.
    Activate systems to monitor data processes continuously to detect and respond to any future incidents promptly.
  • Training.
    Security measures must be supported by proper employee training to ensure effective implementation in daily operations.

It is essential to emphasize that, if a data breach has occurred, pre-existing measures were insufficient and must be reassessed and enhanced. This is a fundamental goal of the Data Breach procedure.

As highlighted earlier, recent developments should prompt reflection. Information and data are increasingly valuable assets, and ensuring their technical and organizational security is a critical priority for businesses. Companies must view investments in advanced, continually updated security measures as vital, not optional. These efforts ultimately benefit business performance and corporate reputation.

Press Review:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Oct 2026

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13…

1 Oct 2026

NASpI and Reinstatement: the Employee’s Election Causes Loss of the Benefit 

Headnote   In its recent judgment No. 24981 of 3 September 2026, the Italian Supreme Court held that, where a dismissal is set aside with an order of reinstatement…

1 Oct 2026

Did you know that… testimony given in court may have disciplinary relevance and, in the most serious cases, justify dismissal? 

The Italian Supreme Court, Labour Section, by order no. 25687 of 22 September 2026, addressed the issue of the disciplinary relevance of statements made by an employee in…

29 Sep 2026

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need…

24 Sep 2026

The concept of “territorial scope” in a non-compete agreement (Top24 Lavoro Ai – Il Sole 24 Ore, 24 September 2026 – Vittorio De Luca and Alessandro Ferrari)

Interpretative issues in light of the most recent case law on the nullity of non-compete agreements due to the indeterminacy of territorial scope By an order issued on…

16 Sep 2026

Did you know that… repeated violations of company procedures may justify the dismissal of a store manager?

The Italian Supreme Court (Labour Section), in Order No. 25231 of 11 September 2026, upheld the lawfulness of the dismissal for just cause of a store manager who…