Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

similarly significantly affects them. It does not apply if the decision is: • necessary for entering into, or the perfor - mance of, a contract between the data sub - ject and a data controller; • authorised by the law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or • based on the data subject’s explicit consent. In the first and last cases, the data controller shall implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests, at least the right to obtain human inter - vention on the part of the controller, to express their point of view and to contest the decision. In addition, the data controller shall provide the data subject with information about the exist - ence of automated decision-making, including profiling, and with meaningful information about the logic involved, as well as the significance and the envisaged consequences of such process - ing for the data subject. “Injury” or “Harm” in Data Protection Law From a data protection perspective, it is neces - sary to pay attention to the risk to the rights and freedoms of natural persons in terms of physical, material or non-material damage, particularly where the processing may give rise to discrimi - nation, identity theft or fraud, financial loss, rep - utational damage, the loss of confidentiality of personal data protected by professional secrecy, the unauthorised reversal of pseudonymisation, or any other significant economic or social dis - advantage. In addition to the obligations dictated by the GDPR, it is also necessary to consider addition -

al regulations adopted as part of the EU Data Strategy. Data Governance Act (EU Regulation No 2022/868) – DGA The Data Governance Act (DGA), effective from September 2023, introduces a European regula - tory framework aimed at fostering data manage - ment based on trust, transparency, and inter - operability. Businesses must implement specific measures to comply with these new rules, par - ticularly concerning data sharing and use across various economic sectors. Firstly, companies must ensure that data man - agement and sharing are transparent and secure. It is essential to clearly inform data subjects about how their data will be used, by whom, and for what purposes, while simultaneously imple - menting technical and organisational measures A significant role is played by data intermediar - ies, entities that facilitate the sharing of infor - mation between businesses or between public and private entities. Those intending to operate as intermediaries must register with an official registry, demonstrate independence and neu - trality, and use standard contracts to govern data-sharing operations. Creation of European data spaces The DGA also promotes the establishment of European data spaces dedicated to specific sectors such as healthcare, energy, or mobility. Companies participating in these spaces must adopt standardised formats to ensure interoper - ability and collaborate to facilitate access to data in compliance with sector-specific regulations. to protect the data from breaches. Key roles of data intermediaries

231 CHAMBERS.COM

Powered by