Categories: Insights, Practice

Tag: Data Breach


2 Sep 2019

The form for notifying the Data Breach is ready

With Regulation 157 of 30 July 2019, which fully replaces all previous measures on the subject, the Guarantor for the Protection of Personal Data has provided the form for reporting computer incidents. Data Breach Pursuant to Article 33, paragraph 1, of the EU Regulation 2016/679 on the protection of personal data (the “GDPR“), the Data Controller is obliged, without undue delay and, where possible, within 72 hours of becoming aware of it, to notify the breach to the Supervisory Authority unless the breach of personal data is unlikely to pose a risk to the rights and freedom of individuals. In addition, the Data Controller who becomes aware of a possible violation is obliged to inform the owner in a timely manner so that he can take action. Notifications to the Guarantor made after the 72-hour period must be accompanied by the reasons for the delay. Furthermore, if the breach involves a high risk to the rights of the individuals, the holder must communicate it to all the persons concerned, using the most appropriate channels, unless he has already taken measures to reduce its impact. The Data Controller, regardless of the notification to the Guarantor, documents all breaches of personal data, for example by preparing a special register. This documentation allows the Control Authority to carry out any audits on the compliance with the regulations. Content of the notification to the Guarantor Pursuant to Article 33, paragraph 3, of the GDPR, the notification to the Guarantor must include the following information:
  • describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of records of the personal data concerned;
  • indicate the name and contact details of the Data Protection Officer (DPO) or other point of contact from whom more information can be obtained;
  • describe the likely consequences of the personal data breach;
  • describe the measures taken or proposed by the controller to remedy the personal data breach and also, where appropriate, to mitigate its possible adverse effects.
The above information is given in the form attached to the Regulation of 30 July 2019. Notification must be made via PEC to the following address  protocollo@pec.gpdp.it and must be digitally signed or signed by hand. In the latter case, the notification must be submitted together with a copy of the signatory’s identity document. The subject of the message must contain the words “NOTIFICATION OF VIOLATION OF PERSONAL DATA” and, optionally, the name of the data controller. In the event of a breach of the notification procedures, a financial penalty of up to €10 million or, in the case of companies, up to 2% of the total global annual turnover is applied.
Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

8 Apr 2026

Management of corporate email after termination of employment: the limits according to the Italian Data Protection Authority

The Italian Data Protection Authority (i.e. “Garante per la protezione dei dati personali”) has once again provided guidance on how employers should manage corporate email accounts after the…

8 Apr 2026

Oral dismissal: the burden of proof on the employee

With order no. 4077 of 23 February 2026, the Italian Supreme Court addressed the issue of oral dismissal, holding that an employee challenging the termination of the employment…

8 Apr 2026

DID YOU KNOW THAT… incompatibility between colleagues may justify the transfer of an employee? 

The Italian Supreme Court, with order no. 4198 of 25 February 2026, held that an employee’s transfer may be lawfully implemented also in the presence of a situation…

7 Apr 2026

The boundary between rest and inactivity in the management of working hours (AIDP – HR Online, 7 aprile 2026 – Vittorio De Luca, Alesia Hima)

In the organizational language of companies, terms such as “breaks,” “waiting times,” or “downtime” are often used. In operational practice, these expressions tend to be treated almost as…

17 Mar 2026

Equal pay: green light for the decree on pay equality and wage transparency (People are People, 16 marzo 2026 – Claudia Cerbone, Martina De Angeli)

Claudia Cerbone and Martina De Angeli, professionals at the De Luca & Partners firm, author this article dedicated to the draft legislative decree approved last February 5 by…

16 Mar 2026

Illegitimacy of staff leasing due to violation of the principle of temporariness (Top 24 Lavoro, 27 febbraio 2026 – Vittorio De Luca, Alessandra Zilla)

With judgment no. 4493 of December 19, 2025, the Court of Milan addressed the issue of indefinite-term labor supply (so-called staff leasing). In particular, the Court clarified that,…