{"id":24437,"date":"2020-08-31T12:55:18","date_gmt":"2020-08-31T10:55:18","guid":{"rendered":"https:\/\/www.delucapartners.it\/news\/company-physician-independent-data-controller\/"},"modified":"2026-04-07T18:04:05","modified_gmt":"2026-04-07T16:04:05","slug":"company-physician-independent-data-controller","status":"publish","type":"post","link":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/","title":{"rendered":"Company Physician: Independent data controller"},"content":{"rendered":"\n<p>On 23 June 2020, the Italian Data Protection Authority (&#8220;<strong><em>Garante<\/em><\/strong>&#8220;) published the &#8220;2019 Annual Report&#8221; (the &#8220;<strong><em>Report<\/em><\/strong>&#8220;) listing activities carried out during the previous calendar year.<\/p>\n\n\n\n<p>With the publication of the Report, the Data Protection Authority has confirmed what had already been stated in the note ref. no. 7797, dated 27 February 2019, concerning the subjective qualification of the Company Physician (as defined by art. 38 of Legislative Decree 81\/2008, the <strong><em>&#8220;Decree&#8221;)<\/em><\/strong><\/p>\n\n\n\n<p>It is necessary to make a brief introduction to better understand the issue.<\/p>\n\n\n\n<p>Article 4 of the (EU) Personal Data Protection Regulation (the &#8220;<strong><em>Regulation<\/em><\/strong>&#8220;) defines the Data Controller as (i) <em>&#8220;the individual or legal person, public authority, service or other body which, individually or jointly with others, determines the personal data processing purposes and means&#8221;<\/em> and the Data Processor as (ii) <em>&#8220;the individual or legal person, public authority, service or other body which processes personal data on behalf of the data controller.&#8221;<\/em><\/p>\n\n\n\n<p>Since the first interpretations and applications of the Regulation, <strong>the legal theory opened a debate on the Company Physician\u2019s correct subjective qualification <\/strong>for data processing carried out during the functions and tasks assigned by the Decree.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The legal theory<\/strong><strong><\/strong><\/h2>\n\n\n\n<p>Part of the theory suggested that the Company Physician was a Data Processor (under art. 28 of the Regulation), and the employer was the sole Data Controller which has the task of determining the purposes and means of the processing carried out by the professional. This theory was based on the relationship between the employer and the Company Physician was regulated by a contract by which the latter was expressly authorised by the employer to carry out employee personal data processing (including data belonging to special categories, formerly &#8220;sensitive&#8221; data).<\/p>\n\n\n\n<p>Conversely, a different part of the theory stated the Company Physician was an independent Data Controller, as the processing purposes were established by the Decree and not by the employer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Data Protection Authority\u2019s position<\/strong><strong><\/strong><\/h2>\n\n\n\n<p>This latter idea was expressly confirmed by the <strong>Data Protection Authority, which qualifies the Company Physician as an independent Data Controller.<\/strong> The type of processing carried out by the professional (for example, health monitoring or preparing health records) is their prerogative and not the employer\u2019s.<\/p>\n\n\n\n<p><strong>In terms of sanctions, according to the Data Protection Authority,<\/strong> the regulatory framework<strong> makes a precise distinction between the employer and Company Physician\u2019s responsibilities.<\/strong><\/p>\n\n\n\n<p><strong>Others Insights related:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.delucapartners.it\/en\/insights\/prassi\/faqs-of-the-data-protection-authority-on-the-data-protection-officer-of-personal-data\/\">FAQs of the Data Protection Authority on the Data Protection Officer of Personal Data<\/a><\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On 23 June 2020, the Italian Data Protection Authority (&#8220;Garante&#8220;) published the &#8220;2019 Annual Report&#8221; (the &#8220;Report&#8220;) listing activities carried out during the previous calendar year. With the publication of the Report, the Data Protection Authority has confirmed what had already been stated in the note ref. no. 7797, dated 27 February 2019, concerning the [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":24438,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[177,190,203],"tags":[1433,943,1434],"class_list":{"0":"post-24437","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","6":"hentry","7":"category-insights","9":"category-practice","10":"tag-autorita-garante-en","11":"tag-gdpr-en","12":"tag-medico-competente-en"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Company Physician: Independent data controller - De Luca &amp; Partners<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts\/24437\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Company Physician: Independent data controller - De Luca &amp; Partners\" \/>\n<meta property=\"og:description\" content=\"On 23 June 2020, the Italian Data Protection Authority (&#8220;Garante&#8220;) published the &#8220;2019 Annual Report&#8221; (the &#8220;Report&#8220;) listing activities carried out during the previous calendar year. With the publication of the Report, the Data Protection Authority has confirmed what had already been stated in the note ref. no. 7797, dated 27 February 2019, concerning the [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/\" \/>\n<meta property=\"og:site_name\" content=\"De Luca &amp; Partners\" \/>\n<meta property=\"article:published_time\" content=\"2020-08-31T10:55:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-07T16:04:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"588\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Melismelis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Melismelis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/\"},\"author\":{\"name\":\"Melismelis\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#\\\/schema\\\/person\\\/00d0832a12e3889dce887a31e29d65f8\"},\"headline\":\"Company Physician: Independent data controller\",\"datePublished\":\"2020-08-31T10:55:18+00:00\",\"dateModified\":\"2026-04-07T16:04:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/\"},\"wordCount\":403,\"publisher\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Privacy-dati-dipendente-4.jpg\",\"keywords\":[\"Autorit\u00e0 Garante\",\"GDPR\",\"Medico Competente\"],\"articleSection\":[\"Insights\",\"Insights\",\"Practice\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/\",\"url\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/\",\"name\":\"Company Physician: Independent data controller - De Luca &amp; Partners\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Privacy-dati-dipendente-4.jpg\",\"datePublished\":\"2020-08-31T10:55:18+00:00\",\"dateModified\":\"2026-04-07T16:04:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Privacy-dati-dipendente-4.jpg\",\"contentUrl\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Privacy-dati-dipendente-4.jpg\",\"width\":1000,\"height\":588},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/insights\\\/company-physician-independent-data-controller\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Company Physician: Independent data controller\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/\",\"name\":\"De Luca & Partners\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#organization\",\"name\":\"De Luca & Partners\",\"url\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/De-Luca-Partners.png\",\"contentUrl\":\"https:\\\/\\\/www.delucapartners.it\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/De-Luca-Partners.png\",\"width\":600,\"height\":56,\"caption\":\"De Luca & Partners\"},\"image\":{\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.delucapartners.it\\\/en\\\/#\\\/schema\\\/person\\\/00d0832a12e3889dce887a31e29d65f8\",\"name\":\"Melismelis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g\",\"caption\":\"Melismelis\"},\"sameAs\":[\"https:\\\/\\\/www.delucapartners.it\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Company Physician: Independent data controller - De Luca &amp; Partners","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts\/24437\/","og_locale":"en_US","og_type":"article","og_title":"Company Physician: Independent data controller - De Luca &amp; Partners","og_description":"On 23 June 2020, the Italian Data Protection Authority (&#8220;Garante&#8220;) published the &#8220;2019 Annual Report&#8221; (the &#8220;Report&#8220;) listing activities carried out during the previous calendar year. With the publication of the Report, the Data Protection Authority has confirmed what had already been stated in the note ref. no. 7797, dated 27 February 2019, concerning the [&hellip;]","og_url":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/","og_site_name":"De Luca &amp; Partners","article_published_time":"2020-08-31T10:55:18+00:00","article_modified_time":"2026-04-07T16:04:05+00:00","og_image":[{"width":1000,"height":588,"url":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg","type":"image\/jpeg"}],"author":"Melismelis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Melismelis","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#article","isPartOf":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/"},"author":{"name":"Melismelis","@id":"https:\/\/www.delucapartners.it\/en\/#\/schema\/person\/00d0832a12e3889dce887a31e29d65f8"},"headline":"Company Physician: Independent data controller","datePublished":"2020-08-31T10:55:18+00:00","dateModified":"2026-04-07T16:04:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/"},"wordCount":403,"publisher":{"@id":"https:\/\/www.delucapartners.it\/en\/#organization"},"image":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#primaryimage"},"thumbnailUrl":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg","keywords":["Autorit\u00e0 Garante","GDPR","Medico Competente"],"articleSection":["Insights","Insights","Practice"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/","url":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/","name":"Company Physician: Independent data controller - De Luca &amp; Partners","isPartOf":{"@id":"https:\/\/www.delucapartners.it\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#primaryimage"},"image":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#primaryimage"},"thumbnailUrl":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg","datePublished":"2020-08-31T10:55:18+00:00","dateModified":"2026-04-07T16:04:05+00:00","breadcrumb":{"@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#primaryimage","url":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg","contentUrl":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/02\/Privacy-dati-dipendente-4.jpg","width":1000,"height":588},{"@type":"BreadcrumbList","@id":"https:\/\/www.delucapartners.it\/en\/insights\/company-physician-independent-data-controller\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.delucapartners.it\/en\/"},{"@type":"ListItem","position":2,"name":"Company Physician: Independent data controller"}]},{"@type":"WebSite","@id":"https:\/\/www.delucapartners.it\/en\/#website","url":"https:\/\/www.delucapartners.it\/en\/","name":"De Luca & Partners","description":"","publisher":{"@id":"https:\/\/www.delucapartners.it\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.delucapartners.it\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.delucapartners.it\/en\/#organization","name":"De Luca & Partners","url":"https:\/\/www.delucapartners.it\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.delucapartners.it\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/01\/De-Luca-Partners.png","contentUrl":"https:\/\/www.delucapartners.it\/wp-content\/uploads\/2026\/01\/De-Luca-Partners.png","width":600,"height":56,"caption":"De Luca & Partners"},"image":{"@id":"https:\/\/www.delucapartners.it\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.delucapartners.it\/en\/#\/schema\/person\/00d0832a12e3889dce887a31e29d65f8","name":"Melismelis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/abc81b0c708aea145c773c368ae5bc3f1f3fd0d40a61429cb96d09523d41ab66?s=96&d=mm&r=g","caption":"Melismelis"},"sameAs":["https:\/\/www.delucapartners.it"]}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts\/24437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/comments?post=24437"}],"version-history":[{"count":2,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts\/24437\/revisions"}],"predecessor-version":[{"id":31086,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/posts\/24437\/revisions\/31086"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/media\/24438"}],"wp:attachment":[{"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/media?parent=24437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/categories?post=24437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.delucapartners.it\/en\/wp-json\/wp\/v2\/tags?post=24437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}