ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting
Lawfulness of Processing Any processing of personal data must be based on at least one of the following legal bases pro - vided for in Article 6(1) of the GDPR: • the data subject has freely given specific, informed and unambiguous consent to the processing of their personal data; • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; • processing is necessary for compliance with a legal obligation to which the controller is subject; • processing is necessary in order to protect the vital interests of the data subject or of another natural person; • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; or • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, particularly where the data subject is a child. In this case, the data con - troller is required to carry out an assessment of the legitimate interest pursued in relation to the rights and freedoms of the data subject by conducting a balancing activity that may possibly be challenged by the supervisory authority or the court. Data Protection by Design and by Default Both at the time of the determination of the means for new processing and at the time of the processing itself, the data controller shall imple -
virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale or the processing on a large scale of special categories of data and personal data relating to criminal convic - tions and offences. In addition, the European guidelines make it clear that data controllers and data processors must document their assess - ments as to whether or not to designate a DPO and periodically review this assessment, unless it is evident that an organisation is not required to designate a DPO. The tasks of the DPO are set out in Article 39 of the GDPR and consist of: • informing and advising the controller or the processor and the employees who carry out processing of their obligations pursuant to European data protection legislation; • monitoring compliance with European data protection legislation and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, raising aware - ness and training staff involved in processing operations, and the related audits; • providing advice where requested as regards the Data Protection Impact Assessment (DPIA) and monitoring its performance; • co-operating with the supervisory authority; and • acting as the contact point for the supervisory authority on issues relating to processing, and to consult, where appropriate, with regard to any other matter. In the performance of their tasks, the DPO shall have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of process - ing.
228 CHAMBERS.COM
Powered by FlippingBook