Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

for collective redress mechanisms. However, data subjects may rely on the tools generally available under civil procedure law or those designed to protect their rights as consumers. 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation The use of IOT services is governed, from a data protection perspective, by the legislation already outlined in 1.1 Overview of Data and Privacy- Related Laws and whose obligations and rights are outlined in detail in 3.3 Rights and Obliga- tions Under Applicable Data Regulation . In addition, with regard to IOT services, the regu - lations adopted as part of the EU Data Strategy (in particular, the Data Act and the Data Govern - ance Act), which are outlined in 3.2 Interaction of Data Regulation and Data Protection , also apply andentail certain obligations to share and circulate information consisting of both personal and non-personal data. 3.2 Interaction of Data Regulation and Data Protection The interaction between data protection legisla - tion and that adopted as part of the EU Data Strategy (in particular, the Data Act and the Data Governance Act) forms a regulatory framework aimed at balancing the protection of personal data with the promotion of a data economy based on sharing and innovation. In particular: • The GDPR, as outlined in 1.1 Overview of Data and Privacy-Related Laws ,governs data protection and provides fundamental principles and rights to protect data subjects.

• The Data Governance Act (effective from September 2023) promotes a secure and trusted ecosystem for data sharing, creating data spaces and mechanisms for regulated access to data, including public data. • The Data Act (phase-in from 2024) regulates the mandatory sharing of data generated by IoT devices and imposes interoperability and access obligations on public and private enti - ties. In this context, the sharing of personal data – distinct from non-personal data – takes on par - ticular significance. Under the Data Act, such sharing may sometimes constitute a legal obli - gation and, in other cases, serve a public inter - est, thereby providing a legitimate basis for pro - cessing under the GDPR. However, compliance with key GDPR principles, such as data minimi - sation, security of processing, and transparency towards data subjects, must always be ensured. In summary, while the Data Act and the Data Governance Act complement the GDPR by intro - ducing rules to encourage data sharing, they also necessitate a thorough analysis of the legal basis and privacy implications. This includes the implementation of technical measures to sepa - rate personal from non-personal data and the use of accountability tools to document assess - ments – particularly in cases where data sharing is mandatory. 3.3 Rights and Obligations Under Pursuant to Article 37 of the GDPR, as interpret - ed by the supervisory authorities’ guidelines, the appointment of a DPO is mandatory for public administrations or where the main activities car - ried out by the data controller or data proces - sor consist of processing operations which, by Applicable Data Regulation Data Protection Officer (DPO)

227 CHAMBERS.COM

Powered by