Data Protection and Privacy 2025

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Nicolò Maria Salvi and Davide Baldini, ICT Legal Consulting

4.4 Transfer of Personal Data in Asset Deals The value of personal data and consent data - bases as a corporate asset is often underesti - mated in corporate transactions. In this context, with regards to the sector in question, the main activity may consist of verifying the lawfulness and correctness of the processing of personal data that makes up a company’s databases; this can be done by verifying the correctness and completeness of the information that the data controller had to provide to the data subjects pursuant to Articles 13 and 14 of the GDPR, and by examining the evidence of compliance with this information notice obligation. Furthermore, where the processing of personal data is based on consent (eg, in the case of processing for promotional purposes or in the context of scientific research), it is essential to verify the correctness and ability to prove the consents collected from the data subjects and the effective capacity of the systems to receive any requests for withdrawal and/or opposition. 5. International Considerations 5.1 Restrictions on International Data Transfers European data protection legislation requires that any transfer of personal data that is under - going processing or is intended for processing after transfer to a third country or to an interna - tional organisation (including for onward trans - fers of personal data from the third country or an international organisation to another third country or to another international organisation) shall take place only if the level of protection of natural persons guaranteed by the GDPR is not undermined.

(eg, the principle of minimisation). In this sense, unencrypted or clear monitoring of the URLs surfed by employees is unlawful because, in terms of security purposes, the same results can be achieved by implementing filters that inhibit the surfing of potentially risky websites. On this point, see also the Guidelines adopted by the GPDP on 1 March 2007. Whistle-Blowing and the Transparency Decree The national legislation on whistle-blowing was updated to transpose Directive (EU) 2019/1937 through the Legislative Decree No. 2023/24 which made discipline uniform between the private and public sectors. With regard to the protection of personal data, the general princi - ples dictated by the GDPR remain valid, con - cerning the obligations to set up reporting and management processes in compliance with the principles of privacy by default and by design and with the need to ensure the confidentiality of the reporter (resulting in the inadequacy, for instance, of the email channel), carry out a DPIA on the processing, train and instruct the people who access the data and manage the reports, etc. Further obligations (mainly informative) are also imposed by Legislative Decree No 104/2022 (the so-called “Transparency Decree”), which prescribes the need to carry out a DPIA and to provide additional information to data subjects in the event of “the use of automated decision- making or monitoring systems designed to provide indications relevant to the recruitment or assignment, management or termination of the employment relationship, the assignment of tasks or duties, as well as indications affecting the monitoring, assessment, performance and fulfilment of contractual obligations of workers.”

235 CHAMBERS.COM

Powered by