ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting
Access to public sector data Another important innovation concerns access to data held by the public sector. Businesses may request such data for specific purposes but must adhere to clear procedures and use the information solely in accordance with agreed terms. Voluntary data sharing In the context of voluntary data sharing, the DGA requires companies to observe principles of fair - ness and non-discrimination, avoiding unfair practices, particularly toward SMEs. Regarding personal data, the regulation complements the GDPR, making it necessary to adopt measures such as data minimisation, anonymisation, or pseudonymisation. Documentation and compliance Finally, companies must maintain accurate doc - umentation of data-sharing procedures and the contracts entered into, notify their activities to the competent authorities, and undergo inspec - tions to ensure compliance. Data Act The Data Act, progressively applicable from 2024, introduces a series of significant obliga - tions for businesses, aimed at facilitating data sharing and access while fostering a more com - petitive and equitable ecosystem. For enterpris - es, this regulation represents a major shift in data management, presenting new responsibilities as A central element of the Data Act is the manage - ment of data generated by IoT devices. Manu - facturers of connected devices, such as smart appliances or connected vehicles, must ensure that users have access to the data produced by their devices. This means that users – whether well as opportunities for innovation. Management of IoT-generated data
individuals or other companies – will have the right to obtain these data in a readable format and share them with third parties. Manufacturers will be prohibited from imposing restrictions or creating technical barriers that limit the use of these data by other entities. Mandatory data sharing with public authorities In exceptional circumstances, such as public health emergencies, natural disasters, or energy crises, companies may be required to provide data to public authorities to address the situ - ation. This data sharing must be transparent, limited to specified purposes, and prevent unau - thorised use of the data. Technical requirements for compatibility and interoperability Businesses will be required to ensure the com - patibility and interoperability of data. This entails adopting standardised formats that allow differ - ent systems to communicate and share infor - mation seamlessly. Companies must invest in technological infrastructure that enables efficient data management across various platforms. Privacy and security safeguards Respect for privacy and data security remains a top priority. Regarding personal data, the regulation complements the GDPR, obliging businesses to process data in compliance with legal bases and to apply measures such as pseudonymisation or anonymisation to protect users’ information. Ensuring data security during management and sharing is equally critical, with obligations to implement systems that prevent unauthorised access or breaches. Contractual transparency and fairness Companies must ensure that contracts govern - ing data access are clear and non-discriminato -
232 CHAMBERS.COM
Powered by FlippingBook