ANACAM MAGAZINE - n. 3 luglio | settembre 2024

PRIVACY, data management and protection DATA PROTECTION COMPLIANCE IS NOT ONLY A LEGAL OBLIGATION, BUT ALSO AN OPPORTUNITY FOR COMPANIES TO CREATE VALUE ‘Processing’ shall mean any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, and thus any information relating to an identified or identifiable natural person, whether directly or indirectly. We can more simply consider that processing is the process that starts with the acquisition of data, continues with their use and storage, and ends with their deletion. Obviously, Anacam members may also find themselves processing personal data for a wide variety of purposes determined directly by them (e.g. management of labour relations; customer management; tax practices; marketing; website; etc.) or for purposes imposed by third parties that they have to fulfil on their behalf, as might happen, for example, in the context of a subcontract. Member companies may also have to deal with so-called special data if they take care of administrative tasks related to the removal of architectural barriers, the application of VAT benefits, or if they employ persons with rights under Law 104/92. Here are some of the pillars on which the regulatory framework is based and with which Anacam members must also deal. Distinction of roles and responsabilities The GDPR clearly identifies and distinguishes the roles and responsibilities of the entities involved in the ‘processing of personal data’ between the data controller, the one who determines the purposes and means of the processing of personal data; the data processor, the one who processes personal data on behalf of the owner of the processing (such as an external professional, a subcontractor, etc.); and the person appointed to data, the one (such as an employee) who acts under the authority of the owner of the processing and who is only assigned specific tasks related to the processing of data. The relationship between data controller and data processor must always be regulated by means of a written contract that obliges the processor to implement the documented instructions of the data controller and regulates both the duration, nature and purposes of the processing, the type of data to be processed, and the categories of data subjects. Risk analysis and privacy impact assessment Each data controller must conduct an adequate risk assessment, including by means of a specific assessment process, taking into account known or apparent risks and the technical and organisational (including security) measures necessary to mitigate those risks. Data safety The data controller and data processor are obliged to take technical and organisational measures to ensure a level of security appropriate to the risk of the processing (with the aim AS of 25 May 2018, European Regulation No. 2016/679 (hereinafter also referred to as the “Regulation” or GDPR) governs the protection of personal data and their free movement, superseding previous Italian legislative provisions where they are conflicting or incompatible. Legislative Decree No. 101 of 10 August 2018 then harmonised the Italian legislation with the GDPR by amending the Privacy Code. The Regulation is based on the so-called accountability principle, which requires data controllers to take appropriate and effective measures to protect personal data and demonstrate that they have done so. The GDPR introduces rules on information and consent, automated processing, data subjects’ rights, data transfer outside the EU and for the case of personal data breaches. It seems useful to go over some basics. ‘Personal data’ means any information concerning an identified (first name, surname...) or identifiable (cookie, IP address, geolocation...) natural person, either directly or indirectly. Personal data also include so-called special data, such as genetic data, biometric data, health data, data revealing racial origin, political or religious beliefs, trade union membership or sexual orientation. Such special data may only be lawfully processed in the cases explicitly provided for in the Regulation and in the manner regulated therein. 50 L’AVVOCATO RISPONDE DI COSTANZA NUCCI ED EDOARDO TOSCANI*

RkJQdWJsaXNoZXIy NDUyNTU=