GDPR and the Coronavirus in Italy

The COVID-19 outbreak has affected the lives of millions of individuals across the globe. Among those affected are the residents of my native Italy who are currently under a mandatory lockdown (nationwide travel restrictions have been enacted) until April 3rd. In this time of crisis, however, it's important to not forget that data ...

Whistleblowing: Italian DPA fines “La Sapienza” University € 30,000

The Italian DPA fined La Sapienza University in Rome € 30,000 for having spread the names of two individuals who had reported potential wrongdoings online. In doing so, the DPA stressed the importance of employers adopting adequate technological procedures for ensuring the the anonymous reporting of potentially illicit behaviour, also known as whistleblowing. Specifically the ...

Successful kick-off of the Data Protection as a Corporate Social Responsibility project

Yesterday, 6 February 2020, the Data Protection as a Corporate Social Responsibility project kick-off meeting was held within the European Centre on Privacy and Cybersecurity (ECPC) within the Faculty of Law at Maastricht University.  The project aims to trigger virtuous data protection competition between companies by creating an environment that identifies and promotes data protection as ...

Launching the Data Protection as a Corporate Social Responsibility research project at ECPC

There’s no better day than today, European Data Protection Day, to announce the 6 February kickoff meeting of the Data Protection as a Corporate Social Responsibility Research Project that I am leading at the European Centre on Privacy & Cybersecurity (ECPC) at Maastricht University.  In our data-centric global economy businesses need to consider privacy and data protection as assets rather than simply ...

Sector-specific codes of conduct contribute to application of GDPR

In a note from the Presidency to the Permanent Representatives Committee (Part 2)/Council, published on 19 December 2019, "Council position and findings on the application of the General Data Protection Regulation (GDPR)", the Presidency underlined the usefulness of Codes of Conduct, writing that: "Drafting sector-specific codes of conduct in accordance with Article 40 of ...

Joint Controllership: A collection of recent guidance

Article 26 GDPR on Joint controllers determines that, "Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the ...

Italian Garante: Not permissible to keep a former employee’s mail account active after the termination of the employment relationship

The Italian DPA (Garante) has stated that it is not allowed for a company to keep the email account of a former employee active following termination of the employment relationship and to access the emails contained in the inbox. The Decision  of the Garante follows a complaint from an individual who complained that their privacy ...

Brexit and data protection: What’s next?

On 12 December 2019 in the UK general election, Boris Johnson secured his position as UK Prime Minister, with his Conservative party winning its first substantial majority in decades. The results of the election have set the way for the UK to exit the European Union by its scheduled exit date of 31 January 2020.  The results ...

Italian DPA: Second semester inspection plan focuses on whistleblowing

The Italian Data Protection Supervisory Authority recently published the measure whereby it decided on the audit plan for this six-month period, citing one of the processing activities that could be inspected: “1. For the period from July to December 2019, the auditing activity initiated and carried out by the Data Protection Supervisory Authority, including through the Guardia di ...

CSA CODE OF CONDUCT for GDPR COMPLIANCE: CSA EMEA Congress 2019

This week I attended the CSA EMEA Congress 2019 where I presented on the CSA Code of Conduct for GDPR Compliance, also in my quality of Co-Chair of the CSA PLA WG. My presentation covered the fundamentals of the GDPR and the CSA Code of Conduct and discussed the game-changers and pillars of the Code ...