Categories: Insights, Publications


26 Apr 2018

GDPR: security measures to support data protection (Newsletter Norme & Tributi n. 123 – Camera di Commercio Italo-Germanica – Vittorio De Luca, Luciano Vella)

The European Regulation on the protection natural persons with regard to the processing of personal data has abolished the minimum security measures that were at the basis of the “privacy policy” system and listed in Annex B of Legislative Decree No. 196/03. Pursuant to Article 32 of the Regulation, in fact, the Data Controller and Processor – taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing – must implement suitable measures to “guarantee a level of security appropriate to the risk”. This is because the Data Controller and Processor must be able to guarantee and demonstrate that they have done everything possible to limit the occurrence of a risk, in compliance with the principle of “accountability” which leaves them full freedom to identify the appropriate technical and organisational measures. To this end, both the Data Controller and the Data Processor cannot do without a gap analysis and a risk assessment, that is a preliminary assessment of the various risks. Should there be a risk of negative impact on the rights and fundamental freedoms of the data subject, this risk must be analysed through a specific evaluation process (e.g. impact assessment). In this sense, on the basis of the foregoing, the protocols relating to the Special Part of Model 231 on IT crimes must be kept updated, also in order to be able to demonstrate the status of compliance with the European data protection regulation.

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

29 May 2026

Notification of dismissal: ordinary e-mail is sufficient if the employee has knowledge of it

With the recent order no. 13731 of May 11, 2026, the Court of Cassation ruled on the validity and effectiveness of a dismissal notification sent via e-mail. The…

29 May 2026

Did you know that… the so-called “1 May Decree” introduces new measures concerning fair pay, employment incentives, and work performed through digital platforms? 

The Official Gazette has published Decree-Law No. 62 of 30 April 2026, entitled “Urgent Provisions on Fair Pay, Employment Incentives and the Fight Against Digital Labour Exploitation”, which…

29 May 2026

Video-surveillance and data protection: the Italian Data Protection Authority reaffirms transparency obligations

With Decision No. 167/2026 of 12 March 2026, the Italian Data Protection Authority (“Garante per la protezione dei dati personali”) once again addressed the issue of video surveillance,…

20 May 2026

Webinar “May 1st Decree: Key Updates and what’s New” –  HR Coffee with De Luca & Partners

On the occasion of our webinar “An HR Coffee with De Luca Partners,” the speakers Silvia Zulato, Senior Associate, and Alessandro Riccardo Polli from the Labour Consulting Division…

12 May 2026

Legitimate dismissal for false attendance reporting and misuse of access system data (Camera di Commercio Francese in Italia – Vittorio De Luca, Silvia Zulato)

With Order No. 7985 of 31 March 2026, the Italian Supreme Court – Labour Section – confirmed the lawfulness of a dismissal for just cause imposed on an…

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…