Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

second case, the information does not need to be provided to the data subject when: • the data subject already has the information; • the provision of such information proves impossible or would involve a disproportion - ate effort; • obtaining or disclosure is expressly laid down by the law to which the controller is subject and which provides appropriate measures to protect the data subject’s legitimate interests; or • the personal data must remain confiden - tial subject to an obligation of professional secrecy. Data Subjects’ Rights Data subjects have certain rights under the GDPR in order to allow them to have continuous and effective control over their personal data. In particular, data subjects have the right to: • request access to their data (by receiving a copy of it) or to all information relating to the processing of their personal data (the pur - pose of processing, the recipients to whom the data is disclosed, any transfers outside the EEA, etc); • obtain the rectification of inaccurate or incomplete personal data; • obtain the deletion of their personal data in the cases provided for in Article 17 of the GDPR; • obtain the restriction of processing in the cases provided for in Article 18 of the GDPR; • obtain their personal data in a structured and commonly used format or to request the transmission of such personal data to another data controller, where the legal basis of the processing is the consent of the data subject or the performance of a contract;

• object to processing based on legitimate interest or the performance of a task carried out in the public interest or in the exercise of official authority; • not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the subject or similarly significantly affects them; • withdraw the consent given; and • lodge a complaint with a supervisory author - ity. Anonymisation, De-identification and Pseudonymisation Anonymisation and pseudonymisation are two processing operations aimed respectively at excluding or reducing the ability of information to be attributed to a specific data subject. The former makes such subsequent re-identification impossible and therefore aims to exclude the applicability of data protection provisions on the resulting output (the so-called anonymised data). The second is instead a security measure expressly referred to in Article 32 of the GDPR and defined as “the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional informa - tion, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the per - sonal data are not attributed to an identified or identifiable natural person.” Automated Individual Decision-Making As anticipated, the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the subject or

230 CHAMBERS.COM

Powered by