Categories: Insights, Publications · News, Publications

Tag: GDPR


29 Oct 2024

Data Breach: Lessons for Companies from Recent Investigations (Il Sole 24 Ore Radiocor – Vittorio De Luca, Martina De Angeli)

The revelations from the investigation conducted by the Milan Prosecutor’s Office and the investigative unit of the Carabinieri of Varese—exposing unlawful activities involving the acquisition of confidential, sensitive, and personal information—have dominated Italy’s political and public debate in recent hours. These developments call for serious reflection.

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has responded by establishing an interdepartmental task force to promptly identify appropriate actions and implement stronger protections for databases. This task force aims, among other objectives, to define adequate technical and organizational security measures for database access by authorized personnel, as well as for the operations performed by those responsible for their management and maintenance.

As we await further updates, here’s what companies need to know and do in similar situations:

  • Internal investigations, containment, and evaluation.
    Upon discovering a data breach, it is critical to identify the incident, evaluate its scope and impact on personal data, and determine its cause to address any vulnerabilities.
  • Notification obligations.
    • To the Data Protection Authority: Organizations must notify the breach to the Garante within 72 hours of becoming aware of it unless the breach is unlikely to pose a risk to the rights and freedoms of individuals.
    • To the affected individuals: If the breach creates a high risk for the people involved, they must be informed without undue delay.
  • Violation register.
    Maintain a record of the breach, including its nature, effects, and corrective measures taken. This is essential for compliance and subsequent audits.
  • Implement corrective measures.
    Take steps to enhance data security and prevent future breaches, such as revising security protocols and initiating employee training programs.
  • Review and update policies.
    After addressing the breach, it is essential to review and strengthen the company’s data protection policies and response plans.
  • Continuous monitoring.
    Activate systems to monitor data processes continuously to detect and respond to any future incidents promptly.
  • Training.
    Security measures must be supported by proper employee training to ensure effective implementation in daily operations.

It is essential to emphasize that, if a data breach has occurred, pre-existing measures were insufficient and must be reassessed and enhanced. This is a fundamental goal of the Data Breach procedure.

As highlighted earlier, recent developments should prompt reflection. Information and data are increasingly valuable assets, and ensuring their technical and organizational security is a critical priority for businesses. Companies must view investments in advanced, continually updated security measures as vital, not optional. These efforts ultimately benefit business performance and corporate reputation.

Press Review:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…

30 Jul 2026

Did you know that… an employee’s natural incapacity does not prevent the time limit for challenging a dismissal from running?

In judgment no. 23486 of 18 July 2026, the Joint Chambers of the Italian Supreme Court (i.e. “Corte di Cassazione”) held that the natural incapacity of an employee…

22 Jul 2026

An employee may not steer clients toward a competitor before resigning (Camera di Commercio Francese in Italia, 22 July 2026 – Vittorio De Luca, Silvia Zulato)

With Order No. 1723 of 26 May 2026, the Italian Supreme Court (Corte di Cassazione) confirmed the liability of an employee who, prior to the termination of his…

20 Jul 2026

Access to Naspi (Top24 Lavoro Ai – Il Sole 24 Ore, 20 July 2026 – Vittorio De Luca e Alessandra Zilla)

Regulatory Framework  The New Social Insurance for Employment (NASpI), introduced by Legislative Decree No. 22 of 4 March 2015, is the primary income support scheme for employees who…