ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting
ment appropriate technical and organisational measures that are designed to implement data protection principles and to integrate the neces - sary safeguards into the processing in order to meet the requirements of the GDPR and protect the rights of data subjects. At the same time, the data controller shall implement appropriate tech - nical and organisational measures for ensuring that, by default, only personal data that is neces - sary for each specific purpose of the processing is processed. Data Protection Impact Assessment Pursuant to Article 35 of the GDPR, where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, par - ticularly processing using new technologies, and taking into account the nature, scope, context and purposes of the processing, the controller shall carry out an assessment of the impact of the envisaged processing operations on the pro - tection of personal data, prior to the processing. This activity is especially required in the follow - ing: • a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing, including profiling, and upon which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; • processing on a large scale of special cat - egories of data or of personal data relating to criminal convictions and offences; or • a systematic monitoring of a publicly acces - sible area on a large scale. The supervisory authorities have also identified a further criterion for assessing the need for a DPIA; in fact, they have identified nine risk fac - tors and provided for the obligation of such an
activity when a processing operation presents two or more of them. This approach was also used to draw up the blacklist of processing oper - ations that the supervisory authorities locally require to be subject to a DPIA. This assessment shall contain at least the fol - lowing: • a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the control - ler; • an assessment of the necessity and propor - tionality of the processing operations in rela - tion to the purposes; • an assessment of the risks to the rights and freedoms of data subjects; and • the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of per - sonal data and to demonstrate compliance with data protection principles. Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate such risk, the controller shall consult the super - visory authority prior to processing. Internal and External Privacy Policies A corollary of the transparency principle is the obligation for data controllers to inform data subjects about the processing of personal data, providing them with the information required by Articles 13 and 14 of the GDPR. For data col - lected directly from the data subject, this must be done at the time the data is obtained and at the time of the first contact with the data sub - ject, or within 30 days in the case of data that is not provided directly by the data subject. In the
229 CHAMBERS.COM
Powered by FlippingBook