Categories: Insights, Publications · News, Publications

Tag: GDPR


29 Oct 2024

Data Breach: Lessons for Companies from Recent Investigations (Il Sole 24 Ore Radiocor – Vittorio De Luca, Martina De Angeli)

The revelations from the investigation conducted by the Milan Prosecutor’s Office and the investigative unit of the Carabinieri of Varese—exposing unlawful activities involving the acquisition of confidential, sensitive, and personal information—have dominated Italy’s political and public debate in recent hours. These developments call for serious reflection.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has responded by establishing an interdepartmental task force to promptly identify appropriate actions and implement stronger protections for databases. This task force aims, among other objectives, to define adequate technical and organizational security measures for database access by authorized personnel, as well as for the operations performed by those responsible for their management and maintenance.

As we await further updates, here’s what companies need to know and do in similar situations:

  • Internal investigations, containment, and evaluation.
    Upon discovering a data breach, it is critical to identify the incident, evaluate its scope and impact on personal data, and determine its cause to address any vulnerabilities.
  • Notification obligations.
    • To the Data Protection Authority: Organizations must notify the breach to the Garante within 72 hours of becoming aware of it unless the breach is unlikely to pose a risk to the rights and freedoms of individuals.
    • To the affected individuals: If the breach creates a high risk for the people involved, they must be informed without undue delay.
  • Violation register.
    Maintain a record of the breach, including its nature, effects, and corrective measures taken. This is essential for compliance and subsequent audits.
  • Implement corrective measures.
    Take steps to enhance data security and prevent future breaches, such as revising security protocols and initiating employee training programs.
  • Review and update policies.
    After addressing the breach, it is essential to review and strengthen the company’s data protection policies and response plans.
  • Continuous monitoring.
    Activate systems to monitor data processes continuously to detect and respond to any future incidents promptly.
  • Training.
    Security measures must be supported by proper employee training to ensure effective implementation in daily operations.

It is essential to emphasize that, if a data breach has occurred, pre-existing measures were insufficient and must be reassessed and enhanced. This is a fundamental goal of the Data Breach procedure.

As highlighted earlier, recent developments should prompt reflection. Information and data are increasingly valuable assets, and ensuring their technical and organizational security is a critical priority for businesses. Companies must view investments in advanced, continually updated security measures as vital, not optional. These efforts ultimately benefit business performance and corporate reputation.

Press Review:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

20 May 2026

Webinar “May 1st Decree: Key Updates and what’s New” –  HR Coffee with De Luca & Partners

On the occasion of our webinar “An HR Coffee with De Luca Partners,” the speakers Silvia Zulato, Senior Associate, and Alessandro Riccardo Polli from the Labour Consulting Division…

12 May 2026

Legitimate dismissal for false attendance reporting and misuse of access system data (Camera di Commercio Francese in Italia – Vittorio De Luca, Silvia Zulato)

With Order No. 7985 of 31 March 2026, the Italian Supreme Court – Labour Section – confirmed the lawfulness of a dismissal for just cause imposed on an…

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…

27 Apr 2026

Management of corporate email after termination of employment: the Italian Data Protection Authority extends the right of access to all emails in the individual email account 

“An employee may access the messages in their corporate email account and the documents stored on their computer after the termination of employment. Any limitations must be justified by specific…

27 Apr 2026

Unemployment benefits and resignation following transfer beyond 50 km: distance alone is not sufficient, employer’s breach must be proven  

With order no. 10559 of 21 April 2026, the Italian Supreme Court addressed the issue of unemployment benefits (i.e. “NASpI”) in the context of resignations for just cause following…

27 Apr 2026

DID YOU KNOW THAT… the probationary period clause is null and void if the duties are described in generic terms? 

The Court of Milan, with judgment no. 683 of 3 April 2026, reaffirmed that a probationary clause (i.e. “patto di prova”) is valid only if it contains a specific indication of the duties subject to…