GDPR
Regulation (EU) 2016/679 (GDPR) is the basis of European personal data protection law. In Italy it operates jointly with the Italian Privacy Code (Legislative Decree 196/2003) as amended by Legislative Decree 101/2018 adapting to GDPR.
The most relevant areas are:
- Legal bases and consent: consent, legal obligation, contract performance, legitimate interest (Article 6 GDPR)
- DPIA for high-risk processing (Article 35 GDPR)
- Roles: controller, joint controller, processor, sub-processor
- Article 28 GDPR contracting (Data Processing Agreement)
- Cross-border data transfers: Standard Contractual Clauses 2021 (Decision 2021/914), Transfer Impact Assessment post-Schrems II, EU-US Data Privacy Framework, Binding Corporate Rules, Article 49 derogations
- Cybersecurity and data breach notification (Articles 33-34 GDPR, 72 hours)
- Data subject rights: access, rectification, erasure, portability, objection, no automated decisions
The Italian Data Protection Authority (Garante) exercises sanctioning and supervisory powers. For Italian law firms, the 2018 Garante guidance and subsequent guidelines specifically govern lawyers' professional secrecy (Article 28 Italian Lawyers' Code of Conduct) and its interaction with GDPR.
LX20 advises Italian and international companies on GDPR mapping, DPIAs, DPA contracting, cross-border transfers, data breach management, dialogue with the Garante. The practice integrates with AI Act, DSA, DMA, Data Act, NIS2 for tech sector clients.
Related practices
Frequently asked questions
When is a DPIA mandatory?
Article 35 GDPR requires it when processing may pose a high risk to the rights and freedoms of natural persons, in particular for: large volumes, sensitive data, systematic monitoring, automated decisions, minors' data, profiling.
Can I transfer data to the US?
Yes, under the EU-US Data Privacy Framework for certified providers. Otherwise SCC 2021 with Transfer Impact Assessment post-Schrems II that evaluates the effective safeguards of the destination country, including against authority access powers.
What are the SCC 2021?
The Standard Contractual Clauses (EU Commission Decision 2021/914): standard clauses for cross-border data transfers. They replace the 2010 SCCs, with four modules (C-C, C-P, P-P, P-C). Annexes include a TIA template.
Are GDPR sanctions cumulable?
Yes. Sanctions up to 20 million euros or 4% of global turnover (Article 83(5) GDPR) apply per violation and can be cumulated for distinct conducts. The Garante may also issue corrective measures and orders to bring processing into compliance.
Can consent be withdrawn?
Yes, at any time (Article 7(3) GDPR). Withdrawal does not affect the lawfulness of processing based on consent before the withdrawal. The data subject must be informed of the right to withdraw before giving consent.
When is a DPO mandatory?
The Data Protection Officer (Articles 37-39 GDPR) is mandatory for: public authorities; controllers/processors whose core activity requires systematic monitoring of data subjects on a large scale; large-scale processing of special categories of data (sensitive, criminal).
How does lawyers'' professional secrecy interact with GDPR?
2018 Garante guidance and subsequent guidelines: professional secrecy (Article 28 Italian Lawyers' Code of Conduct) prevails as an autonomous legal basis and limits the exercise of certain data subject rights. Article 90 GDPR refers to national law for the regulation of legal professions.
What is pseudonymisation?
Processing that prevents data from being attributed to a specific data subject without additional information kept separately (Article 4 GDPR). It is a security measure, NOT anonymisation: pseudonymised data remain personal data.
When must I notify a data breach?
Within 72 hours of becoming aware, to the Garante (Article 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of data subjects. Communication to the data subject if high risk (Article 34).
Can I use cookies without consent?
Only essential technical cookies (Article 122 Legislative Decree 196/2003). For profiling, third-party, marketing, advertising cookies: prior, specific, free, informed and granular consent under the 2021 Garante guidelines.
EU Reg. 2016/679, Italian Privacy Code, Italian DPA, DPIA, cross-border data transfers, Schrems II, Data Privacy Framework, Article 28 GDPR, SCC 2021, data breach, DPO