51 processing would be undermined if the legal basis were incorrectly identified. This would expose the processor to heavy sanctions. Finally, every processing operation must guarantee the data subjects the rights provided for in Articles 13-22, such as the right to information on how the data are processed, the right to access their personal data, the right to cancellation of their data, and data portability. In particular, the information obligations take the form of the so-called ‘privacy policy’, indicating (a) the identity and contact details of the data controller and, where applicable, of its representative; (b) the contact details of the Data Protection Officer (DPO), where applicable; (c) the purposes of the processing as well as the legal basis of the processing; (d) any legitimate interests pursued by the data controller or by third parties; (e) any recipients or any categories of recipients of the personal data; (f) the intention to transfer the personal data to a third country and what makes such transfer legitimate (e.g. the existence of an adequacy decision by the European Commission); (g) the storage period of the personal data; (h) the rights of the data subject; (i) whether the disclosure of the personal data is compulsory; (l) the existence of an automated decision-making process, including profiling, and significant information on the logic used, as well as the importance and the expected consequences of such processing for the data subject. This translates operationally into the planning of treatments, the allocation of responsibilities and the implementation of documentation and contractual arrangements tailored to the specifics of the case. Data Protection Officer Finally, the Regulation’s empowering approach is expressed in the appointment (in several cases mandatory) of a DPO (or Data Protection Officer) who is responsible for raising awareness and training staff, monitoring risks in data management, and acting as a point of contact for data subjects and for the Data Protection Authority for any question relating to the application of the Regulation. The DPO must notify personal data breaches to supervisory authorities and data subjects within 72 hours. It seems clear that, in order to protect the data subject’s right to confidentiality and correct data processing, the GDPR has imposed a complex regulatory system supplemented by the provision of heavy financial penalties that are imposed by the Authority and that, depending on the case, can reach up to EUR 20,000,000.00 or, for companies, up to 4% of the total annual worldwide turnover of the previous year, whichever is higher. However, compliance activity in this area, while complex, can contribute to the development of one’s business and the creation of value by enabling the data to be used effectively and appropriately, for example for marketing activities and/or contacting new and existing customers. * Lawyers from the Studio Legale Berliri Nucci Veroni of preventing accidental or unlawful destruction, loss, modification, disclosure, unauthorised access). Register of processing operations The data controller and data processor must prepare a register, the minimum contents of which are set out in Article 30 of the Regulation, in order to allow the exact identification and instant verification of existing processing operations. This document must be in written form, including electronic form, and must be produced at the request of the Privacy Guarantor. Respect for the principles and rights of persons The processing of personal data must be lawful, fair and transparent to the data subjects and, therefore, data may only be collected for specific and legitimate purposes, to the extent strictly necessary, and may only be stored for as long as necessary for the specific purposes. The legislation specifies that processing is lawful only if and to the extent that at least one of the following conditions is met: (a) the data subject has given consent; (b) processing is necessary for the performance of a contract to which the data subject is party or for the performance of precontractual measures; (c) processing is necessary for compliance with a legal obligation to which the data controller is subject; (d) processing is necessary in order to protect the vital interests of the data subject or another natural person; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. The identification, among these, of the correct legal basis necessary for data processing to be considered legitimate is the result of an assessment process that must be carried out on a case-by-case basis and on the basis of various factors and individual peculiarities. Indeed, the lawfulness of the
RkJQdWJsaXNoZXIy NDUyNTU=