Categories: Insights, Publications


26 Apr 2018

GDPR: security measures to support data protection (Newsletter Norme & Tributi n. 123 – Camera di Commercio Italo-Germanica – Vittorio De Luca, Luciano Vella)

The European Regulation on the protection natural persons with regard to the processing of personal data has abolished the minimum security measures that were at the basis of the “privacy policy” system and listed in Annex B of Legislative Decree No. 196/03. Pursuant to Article 32 of the Regulation, in fact, the Data Controller and Processor – taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing – must implement suitable measures to “guarantee a level of security appropriate to the risk”. This is because the Data Controller and Processor must be able to guarantee and demonstrate that they have done everything possible to limit the occurrence of a risk, in compliance with the principle of “accountability” which leaves them full freedom to identify the appropriate technical and organisational measures. To this end, both the Data Controller and the Data Processor cannot do without a gap analysis and a risk assessment, that is a preliminary assessment of the various risks. Should there be a risk of negative impact on the rights and fundamental freedoms of the data subject, this risk must be analysed through a specific evaluation process (e.g. impact assessment). In this sense, on the basis of the foregoing, the protocols relating to the Special Part of Model 231 on IT crimes must be kept updated, also in order to be able to demonstrate the status of compliance with the European data protection regulation.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Oct 2026

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13…

1 Oct 2026

NASpI and Reinstatement: the Employee’s Election Causes Loss of the Benefit 

Headnote   In its recent judgment No. 24981 of 3 September 2026, the Italian Supreme Court held that, where a dismissal is set aside with an order of reinstatement…

1 Oct 2026

Did you know that… testimony given in court may have disciplinary relevance and, in the most serious cases, justify dismissal? 

The Italian Supreme Court, Labour Section, by order no. 25687 of 22 September 2026, addressed the issue of the disciplinary relevance of statements made by an employee in…

29 Sep 2026

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need…

24 Sep 2026

The concept of “territorial scope” in a non-compete agreement (Top24 Lavoro Ai – Il Sole 24 Ore, 24 September 2026 – Vittorio De Luca and Alessandro Ferrari)

Interpretative issues in light of the most recent case law on the nullity of non-compete agreements due to the indeterminacy of territorial scope By an order issued on…

16 Sep 2026

Did you know that… repeated violations of company procedures may justify the dismissal of a store manager?

The Italian Supreme Court (Labour Section), in Order No. 25231 of 11 September 2026, upheld the lawfulness of the dismissal for just cause of a store manager who…