ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting
1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws The Italian regulatory framework on the protec - tion of personal data and privacy is dictated by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, repealing Direc - tive 95/46/EC (GDPR). To the extent that such protection is not mentioned by the GDPR, it is regulated by Legislative Decree No 196/2003 (the “Privacy Code”). Further detailed rules are contained in Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the pro - cessing of personal data and the protection of privacy in the electronic communications sec - tor, as transposed into Italian law by the Privacy Code. With reference to the protection of natural per - sons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection and prosecution of criminal offences or the execution of criminal penalties, the regulatory framework is instead governed by EU Directive 2016/680, transposed into the Italian legal system through Legislative Decree No 51/2018. Finally, other specific indications and/or interpre - tations are contained in the decisions, recom - mendations and guidelines issued by the nation - al supervisory authorities and the European Data Protection Board (eg, in Italy, the requirements for system administrators).
1.2 Regulators As mentioned in 1.1 Overview of Data and Privacy-Related Laws , supervisory authorities have limited regulatory power, mainly through the adoption of guidelines and opinions interpreting legal provisions. However, supervisory authori - ties (in Italy, the Garante per la Protezione dei Dati Personali, or GPDP) also have supervisory powers to monitor compliance with data pro - tection legislation, and benefit from investigative powers that include, ex multis, the possibility of requesting information from data controllers and data processors or conducting on-site checks and inspections. In this context, the supervisory authority may request access to the documentation adopted (privacy policy, consents, internal policies and procedures, records of processing activities, etc) and to systems and databases. The inspections of the GPDP may be triggered by the authority itself (based on an inspection plan adopted and published every six months, or following noti - fication of a personal data breach), or by data subjects or other third parties (in the case of complaints or reports). Any decisions that are eventually adopted are published. Data protection legislation may also be applied by the courts in the case of appeals lodged by individuals (particularly in the case of claims for damages or appeals against decisions of the supervisory authority). 1.3 Enforcement Proceedings and Fines As mentioned in 1.2 Regulators , GPDP inspec - tions may be triggered by the authority itself (on the basis of an inspection plan adopted and published every six months, or following the notification of a personal data breach) or by data subjects or other third parties (in the case of complaints or reports).
223 CHAMBERS.COM
Powered by FlippingBook