<?xml version="1.0" encoding="utf-8"?>







    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom">
        <channel>
            <title>ADVANTLAW -&gt; News</title>
            <link>https://www.advantlaw.com/</link>
            <description></description>
            <language>it-it</language>
            <copyright>RYZE Digital</copyright>
            
            <pubDate>Sat, 15 Aug 2026 01:06:20 +0200</pubDate>
            <lastBuildDate>Sat, 15 Aug 2026 01:06:20 +0200</lastBuildDate>
            
            <atom:link href="https://www.advant-nctm.com/en/news/feed.xml" rel="self" type="application/rss+xml" />
            
                
                    <item>
                        <guid isPermaLink="false">news-10462</guid>
                        <pubDate>Wed, 17 Jun 2026 14:33:43 +0200</pubDate>
                        <title>Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation</title>
                        <link>https://www.advant-nctm.com/en/news/governance-dei-dati-personali-nei-club-calcistici-luso-dei-dati-come-leva-strategica-tra-gdpr-sicurezza-e-valore-generato</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The football club as a data ecosystem (and as a media company)</strong></p><p>From a personal data protection perspective, a medium-to-large football club is no longer just about “sport and ticketing”; it is a physical and digital ecosystem that generates value through <strong>data and proprietary content</strong>.</p><p>Here, privacy is not a “side issue” to be ticked off a list: it is part of the business model, as it&nbsp;builds trust, enables monetisation, enhances brand value and ensures operational continuity. The GDPR requires the club to know precisely <strong>what data is collected</strong>, where it is stored, who has access to it, on what legal basis it is processed and for how long, while clearly distinguishing among the various categories of data subjects (supporters, minors, players, technical and medical staff, employees, suppliers).</p><p>At the same time, many clubs now operate as fully-fledged <strong>media companies</strong>: they produce and distribute proprietary content, manage official thematic channels and, in some cases, “club-branded” digital or streaming platforms with a D2C (Direct-To-Consumer) approach.</p><p><strong>Types of data and “high-impact” risks</strong></p><p>The data that is most valuable from a business perspective is often also the most risky in terms of its potential impact on the fundamental rights of data subjects:</p><ul style="margin-left:7px;"><li data-list-item-id="e3065cb180fc12b73152340dd43bc1eab"><span><strong>Personal and contact data </strong>(memberships, ID badges, accreditation data, CRM data);</span></li><li data-list-item-id="e3c39997d4c1617458651135397ed6d73"><span><strong>Financial data </strong>(payments, refunds, invoicing);</span></li><li data-list-item-id="e026fb8b715866e5f6e6044297ff3d94b"><span><strong>Audio-visual recording data </strong>(matches, training sessions, events, editorial content);</span></li><li data-list-item-id="e47655b3cdbc7295d632f610d35c85ead"><span><strong>Access and physical/digital security data </strong>(turnstiles, access control, logs);</span></li><li data-list-item-id="eb4e66ea0f0b6a77447fb5d362f9844c3"><span><strong>Data relating to users’ digital behaviour </strong>(apps/websites, interactions, marketing campaigns);</span></li><li data-list-item-id="ede57e86901d7ad553471371e7bdffbdc"><span><strong>Health and performance data </strong>(fitness, injuries, wearables/GPS, performance analysis).</span></li></ul><p>An often underestimated “strategic” aspect is that many top-tier clubs now have <strong>entire teams of data analysts </strong>(or analytics departments) working on <strong>performance, injury prevention, match analysis and, above all, player scouting and recruitment</strong>.</p><p>When inferences about health or physical condition are drawn from performance data, or when health or biometric data are processed, the processing tends to become “high risk”. This requires stronger legal bases and conditions of lawfulness, compliance with the principles of data minimisation and proportionality, segregation of access rights and, often, a <strong>DPIA </strong>(and, if legitimate interest is used, a well-reasoned <strong>LIA</strong>).</p><p><strong>Privacy by design and by default (separation by domain, not by “function”)&nbsp;</strong></p><p>In a well-structured club, the golden rule is to design separate<strong> data domains </strong>and controls that are consistent with the relevant purposes and legal bases, whilst avoiding informal archives and “catch-all repositories”.</p><p>From a best-practice perspective, one might envisage at least:</p><ul style="margin-left:7px;"><li data-list-item-id="e53d7a1f88f4c3e677032764e6c227470"><span><strong>A medical/sports performance area</strong>: health and performance data;</span></li><li data-list-item-id="e213fd50316797c82c55b25388aaffbd3"><span><strong>A sporting operations area</strong>: contracts, team selection records, non-health-related technical statistics;</span></li><li data-list-item-id="e97c8133dfc165eda78bacbc943a86bf5"><span><strong>A media/marketing area</strong>: images and videos for communication, contact details and preferences, digital interaction data.</span></li></ul><p><strong>Privacy roles and the supplier chain (including broadcasters and media partners)</strong></p><p>As a rule, the club is <strong>the </strong>data<strong> controller </strong>for the processing of personal data relating to its sporting and commercial activities. However, the actual governance depends on the supply chain of the relevant service providers, such as, for example, ticketing, CRM, cloud services, contact centres, digital agencies, wearable tech, media content production and distribution.</p><p>Here, compliance hinges on contracts and responsibilities:</p><ul style="margin-left:7px;"><li data-list-item-id="e3cf0b73155e978e2b00f92ebedf08604"><span><strong>Data processor</strong>, where the supplier processes data on behalf of the club;</span></li><li data-list-item-id="e540d8b505c4f8343808b5434c38dcfa9"><span><strong>Joint controllers</strong>, where the purposes and means are determined jointly (e.g. initiatives with sponsors or co-marketing);</span></li><li data-list-item-id="ec5ebe6c083af5c16460d06daca46afb5"><span><strong>Independent controller</strong>, where the partner uses the data for its own purposes (a scenario that is not uncommon in the media, streaming and advertising sectors).</span></li></ul><p>From the “media company” perspective, it is also useful to consider <strong>the scope and distribution rights </strong>between the club’s own channels and third-party digital services (concepts such as “official club platform” versus “third-party digital service” help to avoid confusion between content governance and personal data governance).</p><p><strong>Legal bases and transparency: why consent is not a “wild card”</strong></p><p>A club should avoid the temptation of “universal consent”:</p><ul style="margin-left:7px;"><li data-list-item-id="ee08227dfd96c69fa899bf33444f5b326"><span>for many core processing activities (performance of a contract, legal obligations, security, sports management), consent is not the most appropriate basis;</span></li><li data-list-item-id="e8646a71507b402d791e0ae4149b01388"><span><strong>consent becomes crucial for direct marketing, commercial profiling, and non-essential cookies and tracking technologies</strong>.</span></li></ul><p>In practical terms, two things make all the difference:</p><ol><li data-list-item-id="e2a5caa602a1808cf92faf94c9d3643ae"><span><strong>Omnichannel privacy notices </strong>(stadium, ticketing, app, e-commerce, academy), which are consistent but not “one-size-fits-all”;</span></li><li data-list-item-id="e4b00c87c18ff9f19eaaceccb3938b5e1"><span><strong>Preference and consent management </strong>in CRM systems: granular consents, simple withdrawal mechanisms, cross-channel alignment.</span></li></ol><p><strong>The digital dimension of data processing activities</strong></p><p>This is where the most typical risks are concentrated: lack of transparency in profiling, excessive sharing with third parties, “indefinite” retention, and unregulated transfers outside the EU.</p><p>Italian Data Protection Authority’s Guidelines on cookies and tracking tools (10 June 2021) reiterate that, where required, consent must be freely given, specific, informed and documented, and discourage misleading practices.</p><p>For a club that offers users a seamless experience within an interconnected ecosystem – across apps, e-commerce, OTT services (streaming platforms and on-demand content) and other</p><p>digital initiatives – it is essential to avoid automated cross-device and cross-platform tracking across the various touchpoints. A data value-creation strategy is truly effective only when supported by robust data governance and when its logic remains transparent and explainable to users at all times.</p><p><strong>Minors and the youth sector</strong></p><p>The youth sector significantly increases the level of risk exposure, both because of the age of those involved and the nature of the data processed, which often relates to sport, education and, in some cases, health.</p><p>In Italy, the age at which a person may validly provide <strong>digital consent </strong>in relation to information society services <strong>is set at 14</strong>; below this age, parental authorisation is required.</p><p>This does not mean, however, that content and images may be used freely or indiscriminately. The correct approach remains to <strong>minimise the amount of data </strong>and clearly distinguish between what is necessary for sporting activities and what serves promotional purposes, by establishing specific policies on the use of images, official channels, retention periods and procedures for revocation.</p><p><strong>The stadium as a “data system”</strong></p><p>Video surveillance systems, access control, stewarding and crowd management also generate continuous streams of personal data.</p><p>Compliance is achieved through: visible privacy notices (including simplified versions), clearly defined purposes (security/public order), non-excessive data retention, restricted access to recordings, rules governing cooperation with the authorities, and clarity regarding the data protection responsibilities assumed by the company on a case-by-case basis.</p><p><strong>Cybersecurity and data breach management</strong></p><p>For clubs, the security of personal data is not merely an IT issue: a data breach affecting CRM, ticketing, payment or sports medicine systems can have legal, financial, reputational and sporting consequences.</p><p>A clearly defined process is required: detection, containment, risk assessment, recording, post-incident procedures and – where required – notification to the supervisory authority within 72 hours, and communication to data subjects.</p><p><strong>Privacy function, DPO and internal governance</strong></p><p>As complexity increases, a mature privacy function is required, integrated with other corporate functions:</p><ul style="margin-left:7px;"><li data-list-item-id="efed154cd504b2abec0bc27dc9fcf3203"><span><strong>DPO </strong>where applicable (regular and systematic monitoring on a large scale, special categories of data on a large scale, etc.);</span></li><li data-list-item-id="e1cf89923ed83a21d6438746240ed3194"><span><strong>A constantly updated record of processing activities</strong>;</span></li><li data-list-item-id="e9359046304990e88da84ae34912c0aa6"><span><strong>Data ownership </strong>by domain (Fans/Ticketing, Media/Content, Academy, Player Medical/Performance, Stadium Security): clarity on who decides, who authorises and who is accountable;</span></li><li data-list-item-id="e0d969736f77137d14f817741b56ccf15"><span><strong>Vendor governance</strong>: due diligence and audits on critical processing operations (e.g. ticketing, CRM, OTT, wearables, security).</span></li></ul><p class="text-justify"><strong>Conclusion: trust as an asset, data as a strategic lever</strong></p><p class="text-justify">In modern football, the trust among fans, families, players, sponsors and investors also depends on how the club manages its data. A club that treats personal data as an asset (rather than a risk to be addressed) achieves greater operational continuity, better fan engagement and more sustainable partnerships – precisely because it effectively operates as both a sports organisation and <strong>a media company</strong>.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/2/c/csm_Calcio_63783d8349.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10461</guid>
                        <pubDate>Wed, 17 Jun 2026 14:32:32 +0200</pubDate>
                        <title>Tracking pixels in e-mails: the Data Protection Authority&#039;s new rules</title>
                        <link>https://www.advant-nctm.com/en/news/tracking-pixel-nelle-e-mail-le-nuove-regole-del-garante</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>1. Introduction</strong></p><p>By Order No. 284 of 17 April 2026, published in the Official Gazette on 29 April 2026, the Data Protection Authority (<i>“<strong>Authority</strong>”</i>) adopted the first Guidelines specifically dedicated to the use of tracking pixels in electronic mail communications (“<i><strong>Guidelines</strong></i>”).</p><p class="text-justify">This measure comes at a time of growing attention to tools for monitoring users’ online behaviour and aims to provide a uniform interpretative framework regarding the application of Article 122 of Legislative Decree No. 196/2003 (“<i><strong>Privacy Code</strong>”</i>) and the provisions of Regulation (EU) 2016/679 (“<strong>GDPR</strong>”) to tracking systems embedded in emails.</p><p>According to the Authority, tracking pixels are particularly intrusive tools as they operate without the data subject’s knowledge. The Guidelines are based on the observation that such technologies enable the sender to determine whether a message has been opened, the number of views, the device used and, in some cases, further technical data relating to the recipient.</p><p><strong>2. Key points of the measure</strong></p><p><i>2.1 The classification of tracking pixels as tools subject to Article 122 of the Privacy Code</i></p><p>One of the main clarifications provided by the Authority concerns the legal nature of tracking pixels.</p><p>The Authority states that the insertion of the pixel and the subsequent collection of information generated by its activation constitute operations falling within the scope of Article 122 of the Privacy Code, as they involve both a form of <i>“storage of information on the terminal equipment of a data subject or user</i>” and subsequent <i>“access to information already stored</i>”.</p><p>Of particular significance is the passage in which the Authority states that tracking pixels must be regarded as covert tracking tools, as their presence is not normally detectable by the user and they operate automatically and invisibly.</p><p>The Guidelines also identify a number of parties that may be involved in the use of tracking pixels, including the sender of the message, the email service provider, the provider of mailing list rental services, the provider of tracking technology and the content creator. The Authority specifies that each of these parties is required, on a case-by-case basis and in accordance with the principle of accountability, to define their respective roles for the purposes of&nbsp;the legislation on the protection of personal data.</p><p>The measure also distinguishes between different types of email messages relevant for the purposes of</p><p>the application of the regulations: (i) newsletters, i.e. periodic communications of an informative nature; (ii) DEM (Direct Email Marketing), communications of a predominantly&nbsp;promotional or commercial nature; (iii) transactional emails and automated messages, sent in connection with specific user actions or ongoing transactions; and (iv) service emails, characterised by content designed to meet the specific needs of individuals or the community. This classification&nbsp;is relevant for the purposes of identifying the legal basis applicable to the processing associated with the use of tracking pixels.</p><p><i>2.2 The obligation to provide prior information</i></p><p>The Guidelines attach particular importance to transparency.</p><p class="text-justify">Indeed, according to the Authority, the use of tracking pixels in emails must be disclosed in advance to the email recipient, regardless of the purpose of the communication or the type of sender.</p><p>The Authority also emphasises that the use of tracking pixels requires all data controllers who already use them or intend to use them to adequately inform the data subjects, in accordance with the principles of fairness and transparency set out in the GDPR.</p><p>At an operational level, the measure allows for simplified, layered information procedures, allowing, for example, the use of summary notices accompanied by links to detailed documentation, as well as the use of digital tools such as chatbots, pop-ups, virtual assistants or other communication channels.</p><p><i>2.3 When consent is required</i></p><p>A central aspect of the Guidelines concerns identifying the cases in which the use of tracking pixels requires the user’s consent.</p><p>The Data Protection Authority reiterates that Article 122, paragraph 2-<i>bis</i>, of the Privacy Code introduces a general prohibition on accessing information stored on a user’s terminal equipment, storing information, or monitoring user activity through electronic communications networks; such prohibition may only be subject to derogation where the conditions set out in paragraph 1 of the same Article are met.</p><p class="text-justify">The main scenarios in which consent may not be required include:</p><ul style="margin-left:8px;"><li data-list-item-id="e4a6e74596e6766f2cb2d9ea303771998"><span>processing carried out solely for the purpose of aggregated statistical analysis of email opens, provided that appropriate anonymisation techniques are used;</span></li><li data-list-item-id="e19d89873ec344a78e600dc33d6908611"><span>activities necessary to ensure the security of authentication or account management processes;</span></li><li data-list-item-id="e2f2e435a9effa4ad0061e3f63f7558ce"><span>service or institutional communications where the sender has a legal obligation to send them or where there are specific requirements to protect users. By way of example, the Data Protection Authority refers to messages containing useful guidance on how to prevent phishing or fraud, communications regarding contractual or logistical/organisational changes, notifications relating to security incidents, official information campaigns, as well as reminders regarding deadlines and contractual or social security obligations.</span></li></ul><p>Conversely, consent is required when tracking is used for marketing purposes, profiling, or the individual optimisation of promotional campaigns.</p><p>The provision expressly refers to cases where individual measurement and analysis of email open rates are used to assess and improve the performance of promotional campaigns on the basis of observed behaviour, or when the open rate data is used to derive inferred information about the user’s potential tastes, interests and preferences for the purpose of creating commercial profiles.</p><p><i>2.4 Single consent and the right to granular withdrawal</i></p><p>One of the most innovative aspects of the Guidelines is the attempt to reconcile the need for protection with that for simplification.</p><p class="text-justify">The Data Protection Authority indeed recognises that consent to receive promotional communications and consent to the use of tracking pixels can be obtained through a single expression of consent.</p><p>This simplification is, however, accompanied by an important safeguard for the data subject: the possibility of subsequently withdrawing consent, even on a selective basis.</p><p>The Guidelines stipulate that the user may revoke consent only partially, specifically with regard to tracking associated with the receipt of tracking pixels, while continuing to receive email communications that do not contain tracking tools, if they so wish.</p><p>The Data Protection Authority also draws attention to the data controller’s obligation to duly record all choices made by the data subject, including any partial withdrawals, not least for the purposes of demonstrating consent, which the data controller may be required to do pursuant to Article 7(1) of the GDPR.</p><p><i>2.5 Privacy by design and data minimisation</i></p><p>The measure also focuses on the technical measures that data controllers should adopt to reduce the risks arising from tracking.</p><p>Among the suggested solutions is the use of pseudonymised and non-sequential identifiers, while keeping the correspondence between these identifiers and the recipients’ email addresses separate.</p><p>According to the Data Protection Authority, these measures help to reduce the exposure of email addresses by minimising the risk of data passing through the network being traceable.</p><p><strong>3. Practical implications</strong></p><p>The new Guidelines will have a significant impact on all operators using email campaigns, marketing automation platforms, newsletters and direct email marketing systems.</p><p>In particular, organisations will need to:</p><ul style="margin-left:7px;"><li data-list-item-id="e256f16286ac34f1fc50ebddb5ead708f"><span>check whether the tracking pixels used fall within the exemptions identified by the Data Protection Authority or whether they require consent to be obtained;</span></li><li data-list-item-id="e8c16fa52ce2af3376e7fe234171b4933"><span>update their personal data processing notices/privacy policies, cookie policies and consent collection procedures;</span></li><li data-list-item-id="e6e96713da647ad2ce2396b5b63443611"><span>implement mechanisms that allow users to withdraw their consent to tracking in a simple and granular manner;</span></li><li data-list-item-id="e422a0f828b8ad451557cdee99bf95d2b"><span>review their contractual relationships with email service providers, marketing automation</span><i><span>&nbsp;</span></i><span>platforms and tracking technology providers;</span></li><li data-list-item-id="e6e0dd45a78da680861da332d14a1be11"><span>assess the adoption of technical measures in line with the principles of “privacy by design” and “privacy by default”.</span></li></ul><p>The transitional arrangements set out in the measure are also particularly significant. The Data Protection Authority has recognised the complexity of the required adjustments, granting operators a <strong>period of six months </strong>from the date of publication in the Official Gazette. The Guidelines distinguish, in this regard, between new processing operations, for which consent must be obtained in advance at the time the email address is collected, and processing operations already underway, for which the data controller must promptly fulfil their information obligations with the first available communication and implement a mechanism allowing for the withdrawal of consent, even on a granular basis, identifying solutions characterised by maximum recognisability, visibility and ease of use for the benefit of the data subject. The Data Protection Authority specifies that this transitional regime is intended to be gradually phased out as new processing operations are undertaken and become subject to the rule requiring prior consent.</p><p><strong>4. Conclusions</strong></p><p>The new Guidelines mark an important step in the evolution of Italian legislation on tracking technologies.</p><p>The Authority confirms a broadly rigorous approach, classifying tracking pixels as tools subject to the special rules set out in Article 122 of the Privacy Code and reaffirming the central importance of the principles of transparency and control by the data subject.</p><p>At the same time, the Authority introduces certain operational simplifications – such as a single consent for promotional communications and tracking – and identifies specific cases of exemption that allow the efficiency of certain services to be maintained.</p><p>For businesses, public bodies, technology providers and digital marketing practitioners, the six-month compliance period provided for by the regulation therefore represents an opportunity to review the processes, tools and legal bases for data processing relating to the sending of electronic communications, in light of a regulatory framework that increasingly prioritises transparency and user awareness.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10458</guid>
                        <pubDate>Wed, 17 Jun 2026 14:20:55 +0200</pubDate>
                        <title>Cyber Resilience Act: the countdown has started</title>
                        <link>https://www.advant-nctm.com/en/news/cyber-resilience-act-il-conto-alla-rovescia-e-iniziato</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>With Regulation (EU) 2024/2847 (“<i><strong>Cyber Resilience Act</strong></i>” or “<i><strong>CRA</strong></i>”), the European Union is introducing a set of common rules aimed at strengthening the cybersecurity of digital products placed on the European market.</p><p>Software, hardware, connected devices and, more generally, products containing digital elements must be designed, developed and maintained with cybersecurity in mind throughout their entire lifecycle.</p><p>The Cyber Resilience Act came into force on 10 December 2024, but its effects will begin to be felt in the coming months.</p><p class="text-justify">Indeed, the CRA will be implemented gradually, with some provisions coming into force as early as 2026, while the regulatory framework will be fully applicable from 11 December 2027.</p><p>The first deadlines have already been set: from 11 June 2026, the rules relating to conformity assessment bodies will apply; from 11 September 2026, manufacturers will be required to report any actively exploited vulnerabilities or serious incidents affecting product security.</p><p class="text-justify"><strong>Who is affected and which products containing digital components are covered?</strong></p><p>The provisions of the Cyber Resilience Act are primarily addressed to manufacturers of products containing digital components, but they also apply to other economic operators in the supply chain, including importers, distributors, authorised representatives and, where applicable, open-source software maintainers. In some cases, the manufacturer’s obligations may also fall on importers or distributors, for example when they market a product under their own name or brand or substantially modify the product.</p><p>With regard to its material scope, the Cyber Resilience Act applies to products with digital elements made available on the European Union market. Broadly speaking, these are software or hardware products, including related remote data processing solutions, where their intended purpose or reasonably foreseeable use involves a direct or indirect, logical or physical data connection to a device or network.</p><p>The Cyber Resilience Act therefore covers, by way of example, IoT devices, routers, operating systems, applications, management software, hardware and software components, smart home products, wearable devices and, more generally, digital or connected products intended for distribution or use in the European market.</p><p>However, certain exclusions apply, for example, to products already regulated by specific sectoral legislation, to products developed exclusively for national security or defence purposes, and to certain cases relating to free and open-source software not supplied as part of a commercial activity.</p><p>The practical application of the Cyber Resilience Act therefore requires a case-by-case assessment, taking into account both the product and its distribution model, as well as the role played by the economic operator.</p><p><strong>Key obligations</strong></p><p>The Cyber Resilience Act requires manufacturers to integrate cybersecurity throughout the entire lifecycle of products containing digital elements. Such products must therefore be designed, developed, manufactured and maintained in such a way as to ensure a level of security appropriate to the risks.</p><p>Before placing the product on the market, the manufacturer must carry out an assessment of the cybersecurity risks of the product and take them into account at all relevant stages, from design to development, from production to delivery, right through to maintenance. The product must also comply with specific security requirements, including the reduction of exploitable vulnerabilities, secure-by-default configuration, protection against unauthorised access, safeguarding the confidentiality, integrity and availability of data, as well as the ability to receive security updates.</p><p>The manufacturer will also be required to prepare the technical documentation, carry out the applicable conformity assessment procedure, draw up the EU declaration of conformity and affix the CE marking. For many products, self-assessment may be sufficient, while for those considered important or critical from a cybersecurity perspective, more rigorous procedures may be required, including the involvement of notified bodies.</p><p>The manufacturer’s obligations do not end with the placing of the product on the market. The CRA requires the adoption of appropriate processes to identify, correct and document vulnerabilities even in the post-market phase.</p><p>From 11 September 2026, manufacturers will also be required to notify actively exploited vulnerabilities affecting the product and serious incidents affecting its security. For actively exploited vulnerabilities, an initial report must be made within 24 hours of the manufacturer becoming aware of them, followed by a formal notification within 72 hours and a final report. Similar obligations apply to serious incidents, in accordance with specific timeframes for reporting and the final report.</p><p>Importers and distributors are also subject to specific obligations. Before placing a product on the market or making it available, they must verify that the manufacturer has complied with the required obligations and that the product is accompanied by the required documentation and bears the CE marking. If they have reason to believe that a product does not comply or poses a cybersecurity risk, they must not place it, or make it available, on the market.</p><h2>&nbsp;</h2><p><strong>What to do now</strong></p><p>In light of the deadlines set out in the Cyber Resilience Act, it is essential to begin an assessment of products, internal processes and relationships with suppliers and business partners in good time.</p><p>Preparing in advance will therefore be essential to identify any compliance gaps and approach the upcoming deadlines with greater awareness.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/8/csm_ADV_II_Manufacturing-Industry-1_copy_45519edffe.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10456</guid>
                        <pubDate>Wed, 17 Jun 2026 14:12:27 +0200</pubDate>
                        <title>Minors online: what businesses need to know</title>
                        <link>https://www.advant-nctm.com/en/news/minori-online-cosa-le-imprese-devono-sapere</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>For minors, the internet is home. It is where they find information, study, communicate and build a significant part of their social lives.</p><p>But it is not always a safe place. It amplifies hate speech and disinformation, facilitates practices such as cyberbullying and the non-consensual sharing of sexual or explicit content, and can foster patterns of isolation or addiction. Artificial intelligence further exacerbates these risks: it enables the creation of deepfakes and AI-generated images without the consent of the person depicted; it allows the deployment of chatbots capable of influencing minors’ choices and behaviour; and it makes it possible to tailor content to the specific cognitive vulnerabilities of individual users.</p><p>There is now widespread consensus on the need to protect minors online. How effective protection can be achieved, however, is far less clear.</p><p>In Italy, as in the rest of Europe, the regulatory framework is fragmented and rapidly evolving, and many of the key issues remain unresolved.</p><p><strong>The regulatory framework</strong></p><p>Italy has no comprehensive regulatory framework specifically addressing minors in the digital environment.</p><p>The legal framework is made up of various legislative instruments operating at different but complementary levels and often requiring a holistic interpretation.</p><p>The main legislative instruments currently relevant are:</p><ul><li style="margin-left:7px;" data-list-item-id="eb9de2c84b39ef33b973298fc4d9e51c8"><span>Regulation (EU) 2016/679 (“</span><i><span><strong>GDPR</strong>”</span></i><span>) and Legislative Decree No. 196/2003 (</span><i><span>“<strong>Italian Privacy Code</strong>”</span></i><span>), applicable to data controllers processing the personal data of minors;</span></li><li style="margin-left:7px;" data-list-item-id="ec85d3c2d115fef857f2614d0a64a131c"><span>Regulation (EU) 2022/2065 (“</span><i><span><strong>Digital Services Act</strong></span></i><span>” or “</span><i><span><strong>DSA</strong></span></i><span>”), the European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA, and Commission Recommendation (EU) 2026/1035 on establishing a common framework for EU-wide age verification technologies, applicable to providers of intermediary services;</span></li><li style="margin-left:7px;" data-list-item-id="ed2cf510ed57f297b6313245cf1b93fc5"><span>Directive 2010/13/EU, as amended by Directive (EU) 2018/1808 (“</span><i><span><strong>Audiovisual Media Services Directive</strong></span></i><span>” or “</span><i><span><strong>AVMS Directive</strong></span></i><span>”), transposed in Italy by Legislative Decree No. 208/2021 (</span><i><span>“<strong>Consolidated Act on Audiovisual Media Services</strong>”&nbsp;</span></i><span>or </span><i><span>“<strong>TUSMA</strong>”</span></i><span>), applicable to video-sharing platform providers;</span></li><li data-list-item-id="eb575d147ef22b32e989b4c5a7fa4c582"><p class="text-justify"><span>Decree-Law No. 123/2023, converted into Law No. 159/2023 (</span><i><span>“<strong>Caivano&nbsp;Decree</strong></span></i><span>”) and AGCOM (Italian Communications Authority) Resolution No. 96/25/CONS, applicable to providers distributing pornographic content but increasingly serving as a technical benchmark for age verification; and</span></p></li><li data-list-item-id="ef2c5a3fa8fbec31e5156e272a04c5bcd"><span>Law No. 132/2025 (</span><i><span>“<strong>Italian Artificial Intelligence&nbsp;Act</strong></span></i><span>”), which includes a provision specifically addressing minors’ use of artificial intelligence systems.</span></li></ul><p>In addition to the legislative instruments outlined above, two further initiatives deserve mention: the G7 Common Principles for a Safer and More Secure Digital Space for Minors, adopted by the G7 Digital and Technology Ministers in 2026, which establish a shared framework covering age verification, safety by design, protection from illegal content, parental control tools, digital literacy and risk management, and Bill No. 1136 (<i>“<strong>Bill 1136</strong></i>”), currently under consideration by the Italian Parliament, which introduces specific provisions governing minors’ access to social media and video-sharing platforms, as well as age verification and digital consent.</p><p><strong>Three key issues</strong></p><p>Beyond the existing legal framework, three issues currently lie at the heart of the political and regulatory debate at both national and European level.</p><p><strong>The ban on access to social media</strong></p><p>One of the issues currently dominating the debate on the protection of minors online concerns the introduction of a minimum age for accessing social media.</p><p>In 2024, Australia introduced a ban on under-16s; France, Denmark and Spain are considering similar measures; in Italy, Bill 1136 proposes to prohibit minors under the age of 15 from opening accounts on social media (as well as on video-sharing platforms).</p><p>These measures address genuine concerns. The risk, however, is that attention is focused exclusively on the age threshold for access, while neglecting the characteristics of the services once minors are granted access. A comparison with more mature regulatory models is instructive. The UK’s Age-Appropriate Design Code and the California Age-Appropriate Design Code Act do not merely set age limits, but impose requirements relating to responsible design, risk assessment and provider accountability. From this perspective, the protection of minors depends not only on who can access the service, but also on how the service is designed.</p><p><strong>The digital age of consent&nbsp;</strong></p><p>Closely linked to the issue of minors’ access to social media is that of minors’ consent to the processing of their personal data.</p><p>Article 8 of the GDPR sets the age at which a minor may validly consent at 16, while allowing Member States the option to set lower thresholds, which in any case must not be below 13. Italy has exercised this option, setting the age for a minor’s consent at 14.</p><p>If approved in its current form, however, Bill 1136 would raise the age of consent for minors to 16.</p><p>The issue is further complicated by the fact that age thresholds are not uniform even within the same legal system. The Italian Artificial Intelligence Act, for example, allows minors to access and use AI systems independently from the age of 14 onwards. Accordingly, an operator managing a service with social components and AI-based features may find itself applying different rules to the same user base.</p><p><strong>Service design and the functioning of algorithms</strong></p><p>The third aspect of the debate — and probably the most sensitive — concerns the design of digital services and the functioning of algorithmic systems.</p><p>From this perspective, the regulatory debate is gradually shifting from content control to accountability for design choices that encourage compulsive use of services. These include infinite scroll, notifications deliberately designed to capture users’ attention, recommender systems optimised to maximise time spent on the platform, autoplay features, and intermittent reward mechanisms. The European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA expressly classify these techniques as incompatible with a high level of protection for minors. This is the principle of “safety by design”, which requires minors’ protection to be integrated from the service development stage, rather than addressed <i>ex post</i> on individual pieces of content.</p><p>The scope of these obligations varies, however, depending on the type of service provided. Transparency obligations relating to recommender systems and the ban on profiling-based advertising apply to all online platform providers. The obligations to assess and mitigate systemic risks, on the other hand, are more stringent for very large online platforms (“<strong>VLOPs</strong>”) and very large online search engines (“<strong>VLOSEs</strong>”), which are required to carry out periodic risk assessments and adopt mitigation measures&nbsp;that are reasonable, proportionate and effective.</p><p><strong>Age verification</strong></p><p>Setting a minimum age for access to social media and for digital consent&nbsp;risks remaining a dead letter unless supported by truly reliable age verification mechanisms.</p><p>From this perspective, Commission Recommendation (EU) 2026/1035 establishes a common framework for age verification technologies, based on an interoperable, privacy-respecting model utilising digital identities and advanced cryptographic protocols. The system — developed by the European Commission as an open-source solution and already being trialled in some Member States, including Italy — is based on zero-knowledge proofs: the user downloads an app, verifies their age using an electronic ID or a pre-installed banking app, and receives a digital credential that can be submitted to online platforms. The aim is to enable verification that a specific age threshold has been met without disclosing additional information about the user’s identity: the platform receives only a true/false response (e.g., “over 18: yes”), without access to the user’s name, date of birth or other personal data. Once certification is complete, the link between the user and the certificate provider is severed, preventing any tracking of online activities. In Italy, Bill 1136 provides for a verification system based on a national digital mini-wallet, which constitutes a national implementation of the European solution: not an alternative or parallel system, but a tailored application of the same technical blueprint made available by the Commission as open source, consistent with the requirements of the Recommendation and the implementation timetable set out therein.</p><p><strong>Obligations for businesses</strong></p><p>Against this background, while these issues remain unresolved and the regulatory framework continues to evolve, what should businesses providing information society services intended for, or otherwise accessible to, minors do?</p><p>The answer depends on the nature of the service provided, as well as on the size of the business.</p><p>Providers of online platforms (including social media providers and video-sharing platform providers) must not only comply with the ban on advertising based on the online profiling of minors, but also design their platforms so as to ensure an effective level of protection for minors. This entails, among other things, the adoption of protective default settings, configuring recommender systems that do not maximise user attention and engagement, eliminating features that encourage compulsive behaviour, and providing parental control tools. Furthermore, VLOPs and VLOSEs must identify, analyse and assess the systemic risks their services may pose to minors and adopt reasonable, proportionate and effective mitigation measures, which may include adjusting algorithmic systems, the introduction of age verification tools and specific content moderation measures.</p><p>It is important to note that merely stating in the terms and conditions that a platform is intended for adults does not exempt providers from these obligations. Where effective measures are not implemented to prevent access by minors, the service is deemed to be accessible to minors.</p><p class="text-justify">In addition to the obligations applicable to all online platform providers, providers of video-sharing platforms subject to Italian jurisdiction are also required, under TUSMA, to implement age verification systems for content that may impair the physical, mental or moral development of minors, as well as parental control tools. Providers of video-sharing platforms (and website operators) distributing pornographic content in Italy are also subject to a ban on access by under-18s to the pornographic content distributed, and are required to verify users’ age, in accordance with the procedures laid down by AGCOM.</p><p>Furthermore, should Bill 1136 be enacted, social media providers and video-sharing platform providers would be subject to two additional obligations.</p><p>The first concerns the prohibition on the creation of accounts for minors under the age of 15, rendering void any contracts already concluded with minors who have not yet reached that age at the time&nbsp;</p><p>the law enters into force. The second is the obligation to verify users’ ages via a national digital mini-wallet implementing the European age verification solution, again in accordance with procedures laid down by AGCOM.</p><p>And what about those providers of information society services other than online platforms (such as e-commerce services) or entities that process personal data of minors? For these entities, there is currently no explicit obligation to verify age. Data protection law requires appropriate measures to ensure that a minor’s consent is valid, but it does not prescribe a specific age verification system nor define the technical means by which such verification must be carried out. In the absence of an express statutory obligation, however, it is advisable to carry out a risk assessment — similar in principle to that required under the Commission’s Guidelines for online platform providers — to determine whether, having regard to the nature of the service, the categories of personal data processed and the reasonably foreseeable presence of minors among users, age verification mechanisms compliant with the European technical solution or equivalent standards should be implemented.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/4/1/csm_ADV_Education_1_08a812c0b7.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10349</guid>
                        <pubDate>Thu, 28 May 2026 14:02:26 +0200</pubDate>
                        <title>Trade Secrets and the Digital Omnibus: Protecting Know-How While Data Circulates by Operation of Law</title>
                        <link>https://www.advant-nctm.com/en/news/trade-secrets-e-digital-omnibus-proteggere-il-know-how-mentre-i-dati-circolano-per-obbligo-di-legge</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The issue, in brief</strong></p><p>The Digital Omnibus — the legislative package through which Brussels is streamlining the EU’s digital rules — has been moving in the same direction for years: more sharing, more portability, fewer silos. A legitimate objective, but one with a side effect that many companies have not yet fully grasped: every data-sharing obligation creates an additional window through which know-how that has not been — or cannot be — patented may escape.</p><p>The package includes two main texts: one amending existing rules on data, cybersecurity, and privacy (the “digital acquis”), still under negotiation; and another concerning artificial intelligence, for which a provisional political agreement was reached on 7 May 2026. The dates of official publication remain subject to completion of the formal process.</p><p><strong>What changes in practice</strong></p><p>The most relevant amendments to the digital acquis for those handling sensitive information include:</p><p>– <strong>Public data and large operators.</strong> Public administrations may impose special conditions on Very Large Enterprises and DMA gatekeepers reusing public-sector data, in order to prevent privileged access to data from reinforcing already dominant positions.</p><p>– <strong>Data intermediaries.</strong> The mandatory regime under the Data Governance Act would become voluntary, with lighter separation requirements. More actors in the chain means more points of contact.</p><p>– <strong>Cloud switching.</strong> Simplified regimes for certain categories, but with explicit safeguards regarding trade secrets and risks of exposure to third-country jurisdictions.</p><p>– <strong>Smart contracts for data sharing.</strong> The essential requirements under Article 36 of the Data Act would be removed: fewer technical constraints, greater reliance on contractual governance.</p><p><strong>The starting point: the Data Act</strong></p><p>Already applicable since 12 September 2025, the Data Act grants users of connected devices the right to have their data shared with third parties. For manufacturers, this exposes a delicate perimeter: the data may contain operational logic, configuration parameters, performance information — everything that makes up know-how without ever having been labelled as such. Moreover, the Data Act disapplies the sui generis protection of databases in this context, shifting the burden of protection onto trade secrets.</p><p>Consider a practical example. A manufacturer of connected industrial equipment receives a request from a customer to share 18 months of operational logs with an independent maintenance provider that directly competes with its after-sales service. Those logs contain calibration parameters and control sequences developed over years of R&amp;D and never patented. The Data Act does not allow for a blanket refusal, but it does permit the manufacturer to require proportionate technical measures before sharing the data (Article 4(6)): NDAs with anti-reverse-engineering clauses, sensitive data disclosed only in aggregated form, and contractual prohibitions on using the data to develop competing services (Article 6(2)(e)). If the third party refuses those measures, the manufacturer may block the sharing, but must provide written reasons and notify the competent authority. These two steps are not optional: they are the formal conditions for a lawful refusal.</p><p>The Regulation also provides for the possibility of refusing disclosure where sharing would make serious economic harm highly likely. The threshold is high, and the practical problem is that the harm must be demonstrated before the disclosure occurs, based on data that has not yet left the company. Those who have not documented the value of their trade secrets will find themselves without arguments when they are most needed.</p><p><strong>The Digital Omnibus novelty: the jurisdictional factor</strong></p><p>If approved in its proposed form, the amendment to the Data Act would introduce a new basis for refusing disclosure: the risk of unlawful acquisition by entities operating in third countries with insufficient safeguards — or with formally equivalent safeguards lacking effective enforcement.</p><p>This represents a concrete shift in perspective. Today, many leaks do not originate from cyberattacks or disloyal employees: they arise because data lawfully shared reaches a legitimate recipient operating in a jurisdiction where a local authority may require disclosure — and where obtaining an injunction is slow or impossible. The secret is lost because of a structural systemic issue, not because of malicious intent. The proposal seeks to turn this asymmetry into a legal lever: refusal is legitimate, but it must be justified in writing and notified to the competent authority.</p><p><strong>Five things to do now</strong></p><p>– <strong>Map data from a competitive standpoint.</strong> Not for GDPR purposes: which datasets, if analysed, reveal proprietary processes or logic? Which fall within the scope of the Data Act?</p><p>– <strong>Build a trade secret registry.</strong> A trade secret exists if it is not generally known, has economic value because it is secret, and is protected through reasonable measures. NDAs, access controls, audit logs, internal policies: everything documented and updated.</p><p>– <strong>Structure responses to data-sharing requests.</strong> What is needed is a process, not a case-by-case assessment. Clear criteria are required regarding when to refuse disclosure, how to justify the refusal, and how to notify it.</p><p>– <strong>Conduct a jurisdictional assessment of data flows.</strong> Who receives the data? Where do they operate? Where are their subcontractors located? What is the actual level of enforcement in those jurisdictions?</p><p>– <strong>Monitor the legislative process.</strong> The Digital Omnibus for the digital acquis will evolve. Those working with sensitive data need to know how, and when.</p><p>The direction of the Digital Omnibus will not change: more circulation, more portability. But companies that have built their competitive advantage on data and unpatented processes cannot wait for the legislation to stabilise. The trade secret that survives is the one already structured as such before someone asks for it to be shared.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Intellectual Property</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10252</guid>
                        <pubDate>Fri, 24 Apr 2026 15:30:23 +0200</pubDate>
                        <title>What changes under the new ACN determination on categorisation?</title>
                        <link>https://www.advant-nctm.com/en/news/cosa-cambia-con-la-nuova-determinazione-acn-sulla-categorizzazione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><i>Practical guidance on the new NIS compliance requirements to be fulfilled by 30 June 2026.</i></p><p>Italy’s National Cybersecurity Agency (“ACN”) has today published Determination No. 155238/2026 (“the Determination”), which sets out the relevance categories, as well as the process, procedures and criteria for the listing, characterisation and categorisation of activities and services.&nbsp;</p><p>The Determination introduces two categorisation models, set out in its Annexes 1 and 2 respectively. Both are structured around ten macro-areas, each with a name, description and pre-assigned relevance category. The four relevance categories established by the Determination are: high impact, medium impact, low impact and minimal impact.&nbsp;</p><p>Essentially, the two annexes identify the same macro-areas, which differ only in the relevance category assigned to them.</p><p>As regards the scope of application, Annex 1 applies to (i) NIS entities operating in the following sectors: energy; transport; healthcare; drinking water; wastewater; space; postal and courier services; waste management; manufacturing, production and distribution of chemicals; production, processing and distribution of food; manufacturing; and (ii) entities providing local public transport services. Annex 2 applies to all other NIS entities not falling within those sectors.</p><p>In practice, the Determination requires NIS entities, through the ACN Portal, to list and categorise all internal and external activities and services and assign them to the relevant macro-areas of the model set out in the applicable annex. For each activity or service, entities must specify three elements: the corresponding macro-area, the name and description, and the relevance category.</p><p>The Determination also allows entities a degree of discretion. NIS entities may assign a specific activity or service to a different category from that pre-assigned to the macro-area, based on their assessment of the impact that a potential compromise could have on their ability to properly carry out NIS-related activities and services. In such case, the entity must retain the documentation supporting that assessment. By contrast, where the entity does not carry out activities or provide services attributable to one or more macro-areas, it is not required to report them.</p><p>The Determination also lays down two coordination provisions. The first concerns entities that have already classified data and services for the Public Administration in accordance with ACN Directorial Decree No. 21007/24: for such entities, that model continues to apply, rather than the model introduced by the Determination. The second concerns activities and services subject to the national cyber security framework, for which the relevance category is predetermined as “high impact”, without applying the standard procedure.</p><p>For matters not expressly governed by the Determination, the provisions of the NIS Decree shall apply. The Determination shall apply from 1 May 2026.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10220</guid>
                        <pubDate>Tue, 14 Apr 2026 10:20:07 +0200</pubDate>
                        <title>NIS2: ACN adopts new determinations on relevant suppliers, categorization of activities and services, and deadlines for new NIS entities registered in 2026</title>
                        <link>https://www.advant-nctm.com/en/news/nis2-acn-ha-adottato-le-nuove-determinazioni-su-fornitori-rilevanti-categorizzazione-di-attivita-e-servizi-e-scadenze-per-i-nuovi-soggetti-nis</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 13 April 2026, the Italian National Cybersecurity Agency (“ACN”) published on its website two new determinations issued by the Director General of ACN:</p><ul><li data-list-item-id="e5ae2f3ed975048c397b78f6d3077e8e5"><span><strong>ACN Determination No. 127437 of 13 April 2026</strong></span>, which updates and replaces the previous ACN Determination No. 379887 of 19 December 2025 and introduces the obligation to carry out the new process for listing and categorizing activities and services, as well as listing relevant NIS suppliers during the annual information update;</li><li data-list-item-id="e8d3b93953cbb57918bcbb1068866b7b2"><span><strong>ACN Determination No. 127434 of 13 April 2026</strong></span>, which sets the deadlines by which entities newly included in the NIS list during 2026 must comply with obligations concerning the notification of significant incidents and the adoption of security measures.</li></ul><p><strong>List of relevant NIS suppliers</strong></p><p>ACN Determination No. 127437/2026 introduces the obligation to indicate relevant NIS suppliers as part of the broader annual information update process.</p><p>A relevant NIS supplier is an entity that provides services or products to a NIS entity and meets at least one of the following criteria:</p><ol><li data-list-item-id="ec7b4a484f7217c25090df6dd60b61f0e">the supply relates to the activities or services referred to in Annex I, points 8 and 9, of the NIS Decree, including DNS service providers, top-level domain name registry operators, cloud service providers, data center service providers, content delivery network (CDN) providers, as well as managed service providers and managed security service providers;</li><li data-list-item-id="e9894b24125ef418aa94fb001f7923409">disruption or compromise of the supply would have a significant impact on the NIS entity’s ability to deliver the activities or services falling within the scope of NIS, also because adequate alternative suppliers are not available (non-substitutable suppliers).</li></ol><p>To comply with this obligation, NIS entities must use the “NIS Service / Annual Information Update” on the ACN Portal and indicate, for each relevant supplier:</p><ul><li data-list-item-id="e208c4cbd9ba691e27508812ae890b3c4">company name;</li><li data-list-item-id="e19da10ae9e42d7b8a64a1a1d7ed2013b">tax identification number;</li><li data-list-item-id="e52e7fe3dd759ddf520a93fdf9b5696e8">country of registered office;</li><li data-list-item-id="e2d7dafd3faa662c6b02735cbb8738b0b">CPV (Common Procurement Vocabulary) codes relating to the supplies received by the NIS entity;</li><li data-list-item-id="edd8fcb1eb6d6f6f75dbbda2a868aa531">the relevance criterion applied.</li></ul><p><strong>Listing and categorization of activities and services</strong></p><p>One of the main operational innovations concerns the obligation for NIS entities to communicate the list of their activities and services, assigning each of them a corresponding relevance category. Legislative Decree No. 138/2024 (“NIS Decree”) provides that this requirement must be fulfilled from 1 May to 30 June each year, via the ACN digital platform, starting from the receipt of the first notification of inclusion in the list of NIS entities.</p><p>ACN Determination No. 127437/2026 specifies that this activity must be carried out through the “NIS Service / Categorization” on the ACN Portal. In practice, the Point of Contact must complete the list of the organization’s activities and services and assign to each a relevance category according to the model that will be established by ACN in the coming days, with the publication of a determination containing the categorization model, together with supporting materials to assist in carrying out a simplified Business Impact Analysis (BIA).</p><p>It is important to note that, after the 30 June deadline, the categorized list of activities and services will be considered final and no longer amendable, except in cases of delay due to documented technical-operational issues not attributable to the entity.</p><p>Furthermore, financial entities subject to the DORA Regulation and also falling within the scope of NIS are exempt from this specific requirement, without prejudice to the possibility of voluntary compliance.</p><p>The categorized list of activities and services submitted by NIS entities may be subject to compliance checks by ACN, carried out on a sample basis and also by comparison with data submitted by comparable entities. ACN must provide feedback within 90 days of submission, a deadline that may be extended once by up to an additional 60 days in case of further review. Where additional information, clarifications, or amendments are requested, the NIS entity must respond within 30 days; in case of failure to respond or late response, the list may be rejected. In the absence of a negative outcome communicated within the prescribed timeframe, the list shall be deemed validated.</p><p><strong>Deadlines for entities included in the NIS list for the first time in 2026</strong></p><p>ACN Determination No. 127434/2026 concerns entities that were included for the first time in the list of NIS entities during 2026. For these entities, ACN has set the deadlines for compliance with obligations relating to security measures and incident notification. In particular:</p><ul><li data-list-item-id="e6aa6cd3c15279f7e343d395a700a3846">the deadline for the adoption of the security measures set out in Annexes 1 and 2 of ACN Determination No. 379907/2025 is 31 July 2027;</li><li data-list-item-id="e889c4266c16d93cbeca8ed40e3f79368">the obligation to notify significant incidents described in Annexes 3 and 4 of ACN Determination No. 379907/2025 applies from 1 January 2027.</li></ul><p>An additional provision concerns top-level domain name registry operators and domain name registration service providers included in the NIS list during 2026. For these entities, ACN Determination No. 127434/2026 provides that the obligations referred to in Article 4(1) of ACN Determination No. 379907/2025 must be fulfilled by 31 July 2027.</p><p>If you need assistance and support in complying with the obligations under the NIS framework, please contact your trusted advisors.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9682</guid>
                        <pubDate>Wed, 29 Oct 2025 17:01:06 +0100</pubDate>
                        <title>Italy’s AI Regulations Take Effect: Should Other Countries Follow?</title>
                        <link>https://www.advant-nctm.com/en/news/italys-ai-regulations-take-effect-should-other-countries-follow</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Italy has become the first country in the European Union to pass a national law on AI before the EU’s own AI Act takes effect. The law, approved by the Senate in the middle of last month, builds on discussions that began in April las year. Impact Newswire reports that the Italian government wants to create more elaborate rules for both public and private AI use, focusing on accountability, ethics and transparency.&nbsp;</p><p>The law includes 28 articles that define how AI can be used in different sectors. It also introduces rules for protecting minors under 14, requiring parental consent before any data linked to them can be processed. Italian lawmakers say the goal is to make AI systems fair and safe for citizens while allowing companies to keep innovating responsibly.</p><p>According to <strong>Giulio Uras</strong>:</p><p>“The Italian government’s effort has been both remarkable and, for once, genuinely timely. It sets a clear benchmark for EU countries aiming to complement the AI Act at the national level. Its approach is founded on three key pillars: innovation, transparency, and criminal protection.&nbsp;</p><p>On innovation, the Italian law conveys a clear and forward-looking policy direction. By authorising the secondary use of pseudonymised personal data for research purposes, it adopts a functional and proportionate regulatory model designed to foster scientific and technological development. This approach implicitly acknowledges that Europe’s ability to compete in the global AI landscape depends on avoiding an overly dogmatic interpretation of fundamental rights (particularly in the field of data protection) that could unduly restrict legitimate research and innovation.&nbsp;</p><p>As for transparency, the Italian law is more debatable. The law extends disclosure obligations across several sectors (including employment and intellectual professions) without following the AI Act’s risk-based approach. Such a broad rule may overburden low-risk systems and, paradoxically, stifle innovation.</p><p>The criminal protection provisions yield mixed results. The new offense addressing deepfakes(Art. 612-quater of the Italian Criminal Code) effectively targets a growing threat. More broadly, introducing criminal law safeguards was undoubtedly necessary, as it reinforces protection against the unlawful use of AI to obtain unfair profits or inflict harm. However, criminal provisions are effective only when they can be concretely enforced. In this regard, the drafting technique adopted for the new aggravating circumstance (Art. 61, no. 11-decies of the Italian Criminal Code) raises issues of legal clarity and operational effectiveness, which may ultimately limit its enforceability in practice.</p><p>The real challenge for EU Member States that wish to follow Italy’s example will be to do so without adding unnecessary layers of bureaucracy or new burdens on businesses. Otherwise, the drive for innovation risks being lost in translation.”&nbsp;</p><p><i>Full article published in TechRound</i>.&nbsp;<br>&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/6/csm_Prova_2_dd566079a8.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9608</guid>
                        <pubDate>Mon, 06 Oct 2025 12:07:14 +0200</pubDate>
                        <title>NIS: The CSIRT Contact Person must be appointed by 31 December</title>
                        <link>https://www.advant-nctm.com/en/news/nis-entro-il-31-dicembre-deve-essere-designato-il-referente-csirt</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 19 September, the ACN (National Cybersecurity Agency) adopted Determination ACN No. 250916, which updates and replaces the previous Determination ACN No. 333017 of 22 July 2025.</p><p>The most significant change is the introduction of the <i>CSIRT Contact Person</i>.</p><p><strong>Who is the CSIRT Contact Person?</strong></p><p>The CSIRT Contact Person is the individual responsible for managing communications with <i>CSIRT Italia</i> (the national Computer Security Incident Response Team) and for transmitting notifications of significant incidents (as defined in Determination ACN No. 164179) as well as voluntary reports of relevant cybersecurity information.</p><p>To ensure prompt and continuous communication with the CSIRT, the regulation allows the appointment of one or more deputies to the CSIRT Contact Person. These deputies support the Contact Person in their duties and can act on their behalf in cases of absence or impediment.</p><p>Unlike the Point of Contact and the Deputy Point of Contact, the CSIRT Contact Person (and their deputy) may also be an external individual (for example, a consultant).</p><p>In any case, designated persons must possess basic skills in cybersecurity and incident management, along with an in-depth knowledge of the information systems and networks of the NIS entity for which they operate.</p><p>The designation must be carried out by the Point of Contact through a dedicated procedure. This procedure will be active from 20 November 2025 and must be completed by 31 December 2025 via the service portal accessible through the ACN website.</p><p>At first glance, the introduction of the CSIRT Contact Person represents an important support tool for NIS entities, as it allows them to delegate the management of incident notifications to external individuals. This relieves NIS entities from particularly burdensome and time-consuming activities for which it may be preferable to rely on external consultants with specific expertise.</p><p>This is particularly useful for:</p><ul><li><span>NIS entities that lack adequate internal structures or resources to manage the requirements related to incident notification;</span></li><li><span>foreign organizations under national jurisdiction (for example, providers of public electronic communications networks and publicly available electronic communications services) that may face challenges due to language barriers or time zone differences.</span></li></ul><p>If you need assistance and support in fulfilling the obligations under the NIS framework, <a href="https://www.advant-nctm.com/esperienza/aree-di-attivita/it-e-data/compliance-digitale" target="_blank"><strong><u>click here</u></strong></a></p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/5/8/csm_ADV_Start-up_2_3dd5708e68.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9085</guid>
                        <pubDate>Thu, 05 Jun 2025 12:06:28 +0200</pubDate>
                        <title>Metadata, the Italian Data Protection Authority intervenes on the Extension of the Retention Period Beyond 21 Days</title>
                        <link>https://www.advant-nctm.com/en/news/metadati-il-garante-interviene-sullestensione-del-periodo-di-conservazione-oltre-i-21-giorni</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">With Decision No. 243 of April 29, 2025, the Italian Data Protection Authority (“<i><strong>IDPA”</strong></i>) imposed an administrative fine of €50,000 on the Lombardy Region (“<i><strong>Region</strong></i>”) for having retained, without the necessary procedural safeguards, metadata generated by email management systems for 90 days and Internet browsing logs for 365 days. In particular, the Region failed to comply with the obligations set out in Article 4(1) of Law No. 300/1970 (“<i><strong>Workers’ Statute</strong></i>”) and did not conduct a data protection impact assessment (DPIA) pursuant to Article 35 of the GDPR.</p><p class="text-justify">In this Decision, the IDPA reiterated that metadata generated by email management systems and Internet browsing logs are personal data and that their generalized collection, as it enables remote monitoring of work activity, requires the employer, under certain circumstances, to follow the procedures set out in Article 4(1) of the Workers’ Statute.</p><p class="text-justify">The IDPA’s Position Paper dated June 6, 2024, had already established this position, specifying that metadata generated by employee email systems may be retained only for limited periods, generally not exceeding 21 days. If retention exceeds 21 days, it is necessary—according to the IDPA—to follow the procedures under Article 4(1) of the Workers’ Statute. This is unless the data controller can concretely demonstrate specific technical or organizational reasons (e.g., related to the cybersecurity of the email service) that justify the extension of the retention period beyond 21 days.</p><p class="text-justify">Such reasons were not found in this case.</p><p class="text-justify">The Region, moreover, through three external providers, was able to combine IP addresses, MAC addresses, and employee identities, thus having full access to information that enabled potential profiling and individual monitoring of employees. The IDPA considered such processing disproportionate and excessive relative to the principles of data minimization and storage limitation. It therefore mandated, among other things, the anonymization of attempts to access blacklisted websites, the reduction of Internet browsing log retention from 365 to 90 days (with retention beyond this limit allowed only after anonymization), restricted access to data to expressly authorized personnel, and encryption of data enabling the association between device and employee.</p><p class="text-justify">The IDPA also clarified that, considering the fact that processing metadata from employee email systems potentially involves “high risks” to the rights and freedoms of the individuals concerned (since it entails systematic monitoring of employees—deemed vulnerable due to their subordinate employment status), conducting a DPIA is mandatory, and failure to do so constitutes a violation of Article 35 of the GDPR.</p><p class="text-justify">The IDPA’s stance is thus clear: metadata should not be retained for more than 21 days, and doing so without following the procedures under Article 4(1) of the Workers’ Statute is only legitimate in the presence of proven technical reasons related to the functioning and cybersecurity of the service (which cannot be based on generic IT security concerns of the employer’s networks and systems). Where such reasons are lacking, it is necessary, depending on the case, to reach an agreement with union representatives or obtain authorization from the competent Labor Inspectorate. In all cases, a DPIA and a Legitimate Interest Assessment (LIA) must be conducted and documented, relevant information notices on the processing of personal data and internal policies and procedures updated, and appropriate technical and organizational measures adopted to ensure an adequate level of personal data protection.</p><p class="text-justify">If you need assistance and support in complying with the obligations related to the collection and retention of metadata generated by corporate email systems, contact your trusted professionals.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8979</guid>
                        <pubDate>Tue, 13 May 2025 15:09:54 +0200</pubDate>
                        <title>New digital accessibility obligations</title>
                        <link>https://www.advant-nctm.com/en/news/nuovi-obblighi-di-accessibilita-digitale</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The requirement for compliance with accessibility obligations for digital services made available to consumers will be binding from 28 June 2025. Relevant regulatory sources include: Legislative Decree 82/2022, which transposed Directive (EU) 2019/882, known as the “European Accessibility Act” (EAA); Law 4/2004, as amended and supplemented, known as the “Stanca Act” (which first introduced accessibility obligations for public authorities); Law 120/2020, which extended the subjective scope of the Stanca Act to the private sector as well, with a focus on businesses that provide essential services of general interest through digital channels.</p><p><i><strong>Who is obliged to comply with the regulations?</strong></i></p><p>Digital accessibility obligations apply specifically to:&nbsp;</p><p>- Private economic operators providing digital services to the public, including but not limited to:</p><ul><li><span>banks, insurance companies, transportation companies and telecommunications operators;</span></li><li><span>e-commerce platforms, providers of audiovisual content, marketplaces and online services;</span></li><li><span>operators of ATMs, self-service terminals, electronic ticketing and postal services.</span></li></ul><p>- Entities involved in the design, production and marketing of digital tools intended for the general public, including but not limited to:</p><ul><li><span>web sites and mobile applications;</span></li><li><span>electronic devices with user interfaces;</span></li><li><span>management or application software accessible by end users.&nbsp;</span></li></ul><p><i><strong>Who supervises and what do those who fail to comply risk?</strong></i></p><p>The Agency for Digital Italy (AgID) is responsible for supervising the implementation of the regulations: it can carry out audits, inspections and, in case of non-compliance, take sanctioning and inhibitory measures.</p><p>Specifically, in case of violation, AgID can:</p><p>- issue a warning setting a deadline for compliance;&nbsp;</p><p>- apply fines:</p><ul><li><span>up to 5% of the average annual turnover for serious violations committed by entities offering services to the public through websites or mobile applications, with an average turnover, in the last three years of activity, exceeding €500 million;</span></li><li><span>between €5,000 and €40,000 for the other subjects, taking into account the seriousness of the violation, the number of users involved and the scope of the inaccessible services;</span></li><li><span>additional sanctions of €2,500 to €30,000 in case of non-compliance with AgID warnings or obstruction of inspection activities.&nbsp;</span></li></ul><p>AgID can also take particularly strong administrative inhibitory measures, including:&nbsp;</p><p>- website blackout or removal of applications from digital stores;&nbsp;</p><p>- temporary or permanent ban on access to non-compliant digital services.</p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8965</guid>
                        <pubDate>Thu, 08 May 2025 17:57:35 +0200</pubDate>
                        <title>NIS, ACN’s resolution on notification of sharing agreements</title>
                        <link>https://www.advant-nctm.com/en/news/nis-la-determinazione-dellacn-sulla-notifica-degli-accordi-di-condivisione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>ACN's Resolution No. 136118 of 10 April 2025 – <i>Notification of agreements on the sharing of cybersecurity information pursuant to Article 17 of the NIS</i> Decree (<strong>“Resolution 136118”</strong>) sets out the procedures whereby NIS entities that are a party to (cybersecurity information) sharing agreements must notify the ACN of their participation in such agreements.</p><p>Sharing agreements are governed by Article 17 of Legislative Decree No. 138/2024 and concern the (voluntary and optional) sharing between NIS entities or between NIS entities and other entities (e.g. suppliers of NIS entities) of information relating to cybersecurity, such as cyber threats, near misses, vulnerabilities, techniques and procedures, security alerts, etc. Such agreements are functional to the prevention of incidents as well as to the management, containment and mitigation of their consequences, and contribute to raising collective cybersecurity standards.</p><p>The participation of a NIS entity in one or more sharing agreements must be notified to the ACN via the service portal, providing the text of the agreement and indicating its name and the list of the entities that are a party to it.</p><p>As regards the notification deadlines, for agreements entered into after the entry into force of Legislative Decree 138/2024 (i.e. after 16 October 2024), notification must be made promptly and therefore at the same time or immediately after the conclusion of the agreement. In any event, sharing agreements signed before the entry into force of Legislative Decree 138/2024 (and still in force on 31 May 2026) must be notified by 31 May 2026.</p><p>The list of sharing agreements to which the NIS entity is a party notified to the ACN must always be checked and updated over time: in particular, pursuant to Resolution 136118, any changes (e.g., the signing of a new agreement, the termination of an agreement in place, or changes to the text or parties to the agreement) must be notified to the ACN within 14 days of the date of the change.</p><p>The list of sharing agreements must be updated at least once a year: between 15 April and 31 May of each year, NIS entities shall update, again via the portal, the list of sharing agreements to which they are a party.</p><p>Should you need any assistance and support in complying with the obligations under the NIS regulations, please contact your professional advisors.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/e/9/csm_ADV_II_White-Collar-Crime-Compliance-1_copy_42133935c6.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8866</guid>
                        <pubDate>Wed, 16 Apr 2025 07:38:21 +0200</pubDate>
                        <title>NIS: Determinations Defining the Obligations Adopted — Information Update Deadline Set for May 31</title>
                        <link>https://www.advant-nctm.com/en/news/nis-adottate-le-determinazioni-che-definiscono-gli-obblighi-laggiornamento-delle-informazioni-scade-il-31-maggio</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On April 15, 2025, the Italian National Cybersecurity Agency (“ACN”) published on its website three new determinations issued by the Director General of the ACN:</p><ul><li><strong>Determination ACN No. 136117 of April 10, 2025</strong> — Platform, Point of Contact and Substitute, Information Update and NIS Representative under Article 7 of the NIS Decree (“Determination 136117”);</li><li><strong>Determination ACN No. 136118 of April 10, 2025</strong> — Notification of Cybersecurity Information Sharing Agreements under Article 17 of the NIS Decree (“Determination 136118”); and</li><li><strong>Determination ACN No. 164179 of April 10, 2025</strong> — Basic Specifications for Fulfilling Obligations under Articles 23, 24, 25, 29, and 32 of the NIS Decree (“Determination 164179”).</li></ul><p>Determination 136117, which updates and replaces Determination ACN No. 38565 of November 26, 2024, governs access to the services portal and the procedures for registration and information updates, as well as the designation of the point of contact and other persons authorized to operate on the ACN services portal on behalf of NIS entities.</p><p>The main new features introduced by Determination 136117 concern:</p><ul><li>the substitute point of contact;</li><li>the secretariat;</li><li>the operators; and</li><li>the process for the annual update of information.</li></ul><p>The substitute point of contact is a natural person, different from the main point of contact, designated by the NIS entity pursuant to Article 7(4)(d) of Legislative Decree No. 138/2024, whose role is to support the point of contact in carrying out its functions (except for registration, which remains solely with the point of contact).</p><p class="text-justify">The secretariat, on the other hand, is the natural person who supports the point of contact and the substitute point of contact in interactions with ACN.</p><p>Finally, the operators are those who support the point of contact and the substitute point of contact in operating on the portal.</p><p>As with the point of contact, the functions of the substitute point of contact may only be carried out by the legal representative, a general attorney (registered in the business register), or an employee delegated by the legal representative. However, it is unclear whether this also applies to the secretariat and operators.</p><p>To operate on the portal, the substitute point of contact, the secretariat and the operators must be invited by the point of contact, complete registration and associate their user account with that of the NIS entity. However, the secretariat and operators may not use the portal to send communications to ACN regarding the fulfilment of obligations under Legislative Decree no. 138/2024. The role of secretariat may only be assigned to a single user.</p><p>It should be noted, in any case, that while the designation of the substitute point of contact is mandatory, the involvement of the secretariat and operators is purely optional.</p><p>With regard to the process of updating information, Determination 136117 requires that between April 15 and May 31 of each year, the information required by Article 7(4 and 5) of Legislative Decree no. 138/2024 be submitted via the portal section called "NIS Service/Annual Update".</p><p>In particular, all NIS entities must, as applicable, provide or verify the update of the following information:</p><ul><li>personal and contact details of the point of contact and, where applicable, data contained in the power of attorney conferred by the legal representative;</li><li>personal and contact details of the substitute point of contact and, where applicable, data contained in the power of attorney conferred by the legal representative;</li><li>personal and contact details of the secretariat;</li><li>personal and contact details of the NIS entity (at a minimum, tax code, company name, registered office address, legal representative, list of general attorneys, telephone number, certified email address and ordinary email address must be provided);</li><li>list of the members of the administrative and management bodies, to be identified based on Article 38(5) of Legislative Decree no. 138/2024 (at a minimum, name and surname, tax code and certified email address must be provided);</li><li>list of the services falling within the scope of Legislative Decree no. 138/2024 provided by the NIS entity, indicating the EU Member States in which they are provided;</li><li>public IP address space in use or available to the NIS entity (i.e. public and static IP addresses used or available to a NIS entity through contracts or agreements with Internet service providers, Regional Internet Registries or other organizations responsible for providing IP addresses based on national, European and international regulations and agreements);</li><li>domain names in use or available to the NIS entity (i.e. domain names used or available to a NIS entity through contracts or agreements with domain name registration service providers or other organizations responsible for providing domain names based on national, European and international regulations and agreements); and</li><li>list of information sharing agreements (i.e. voluntary arrangements between NIS entities to exchange relevant cybersecurity information under Article 17 of Legislative Decree no. 138/2024).</li></ul><p>Providers of domain name system services, top-level domain name registry operators, domain name registration service providers, cloud computing service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, online marketplace providers, online search engine providers, and social network platform providers must also, where applicable, provide or verify the update of information relating to their EU establishments. Furthermore, if they are established outside the national territory and have appointed their representative in Italy, they must provide and verify the update of the personal and contact details of the representative in Italy.</p><p>Detailed analyses of Determination 136118 and Determination 164179 will be available shortly.</p><p>If you need assistance and support in fulfilling the obligations set out in the NIS legislation, please contact your professional advisers.</p>]]></content:encoded>
                        
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/7/5/csm_ADV_Start-up_2_ab64e3285d.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8807</guid>
                        <pubDate>Thu, 03 Apr 2025 12:02:29 +0200</pubDate>
                        <title>NIS, so what now? Dates to watch out for</title>
                        <link>https://www.advant-nctm.com/en/news/nis-e-ora-il-calendario-delle-date-da-tenere-a-mente</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">On 16 October, Legislative Decree No. 138/2024 came into force, whereby Italy implemented Directive (EU) 2022/2555 (the so-called NIS2 Directive).</p><p class="text-justify">Legislative Decree No. 138/2024 generally applies to medium and large enterprises in 17 critical and highly critical sectors (besides public administrations and certain other types of entities identified directly by the National Cybersecurity Agency (ACN)) and imposes on NIS entities obligations that can be grouped into the following categories:&nbsp; &nbsp;</p><ul><li><p class="text-justify"><span><strong>obligations to register and update information</strong>: every year NIS entities must register or update their registration on the ACN web portal, specifying their point of contact and providing a series of information relating, among other things, to the activities carried out and services provided;</span></p></li><li><p class="text-justify"><span><strong>obligations relating to security measures</strong>: NIS entities are required to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the information and network systems used in their activities or in the provision of their services;</span></p></li><li><p class="text-justify"><span><strong>obligations relating to incident notifications</strong>: NIS entities must notify the CSIRT, according to a multiple-stage approach and without delay, of security incidents that have a significant impact on the provision of their services;</span></p></li><li><p class="text-justify"><span><strong>obligations for administrative and management bodies</strong>: administrative and management bodies, which are responsible for breaches of NIS regulations, are required to undergo training in IT security and to promote the periodic offer of IT security training for their employees.</span></p></li></ul><p class="text-justify">If your organisation is an NIS entity or you assume it will become one during the course of this year, here is a calendar with the dates to remember to ensure compliance with Legislative Decree No. 138/2024.</p><p class="text-justify">&nbsp;</p><figure class="table" style="width:100.0%;"><table style="border-style:none;" class="contenttable"><tbody><tr><td style="background-color:#F2F2F2;border-color:#D9D9D9;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>&nbsp;15 April 2025</strong></span></td><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:none;border-right-style:solid;border-top-style:solid;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you registered on the ACN portal by 10 March 2025, you will receive confirmation from the ACN that your organisation has been included in the list of essential or important entities at the email addresses (of the organisation and the point of contact) that you provided during registration.</span></p><p class="text-justify"><span>Still on 15 April 2025, the ACN will adopt the resolutions that will define the basic obligations regarding incident notification and security measures that NIS entities must comply with starting from January 2026.</span></p></td></tr><tr><td style="border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From 15 April to 31 May 2025</strong></span></td><td style="border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you have been included in the list of essential and important entities, you will have to provide, through the portal, further information relating, in particular, to the domain names in use, the Member States in which you offer services regulated by the NIS and the managers in your organisation.</span></p></td></tr><tr><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From 1 January al 28 February 2026</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you registered on the ACN portal by 10 March 2025, you will need to confirm the information provided or update it, if necessary.</span></p><p class="text-justify"><span>If, instead, you did not register on the ACN portal by 10 March 2025 (because you believed that you did not fall within the scope of Legislative Decree No. 138/2024 on that date) but during the course of the year you have exceeded the thresholds for medium-sized enterprises or started activities that determine the application of the NIS regulations, you will have to make your first registration.</span></p></td></tr><tr><td style="border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From January 2026</strong></span></td><td style="border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>The basic obligations relating to incident notifications, laid down by the ACN in the resolution to be adopted by 15 April 2025 will become applicable.&nbsp;</span></p></td></tr><tr><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From October 2026</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>The basic obligations relating to safety measures, laid down by the ACN in the resolution to be adopted by 15 April 2025, will become applicable.</span></p></td></tr></tbody></table></figure><p class="text-justify">&nbsp;</p><p class="text-justify">If you need assistance and support to fulfil the obligations of the NIS regulations, please contact your reference professionals.&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8472</guid>
                        <pubDate>Tue, 11 Feb 2025 15:44:47 +0100</pubDate>
                        <title>Guidelines on pseudonymisation</title>
                        <link>https://www.advant-nctm.com/en/news/linee-guida-sulla-pseudonimizzazione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">The new guidelines on #pseudonymisation (“<a href="https://www.edpb.europa.eu/system/files/2025-01/edpb_guidelines_202501_pseudonymisation_en.pdf" target="_blank" rel="noreferrer"><i>Guidelines 01/2025 on Pseudonymisation</i></a>”, “<i><strong>Guidelines</strong></i>”) of the European Data Protection Board #EDPB out for consultation up to 28 February 2025 are a must-read.&nbsp; What are we talking about? Pseudonymisation is a technique that makes personal data more difficult to identify without additional information.&nbsp;</p><p class="text-justify">Within the scope of Regulation (EU) 2016/679 (“<strong>GDPR</strong>”), which introduces the concept for the first time, pseudonymisation is considered one of the technical measures that the data controller or processor can use to fulfil their obligations regarding personal data protection. Specifically, the pseudonymisation procedure consists of making personal data relating to a specific individual no longer attributable to that individual, except – and this is the substantial difference with anonymisation – through the use of additional information, including any additional information that is beyond the control of the party carrying out the pseudonymisation. Such additional information (so-called pseudonymisation secrets) must be stored separately and protected by adequate security measures. The aim is to ensure that those who process the pseudonymised data are not able to attribute it to the individual to whom the data belongs.&nbsp;</p><p>As stated in the Guidelines, since pseudonymised data constitutes information relating to an identifiable natural person, it remains personal data to all intents and purposes and, as such, is subject to the provisions of the GDPR.&nbsp;</p><p class="text-justify">In this regard, the EDPB seems to adopt a very broad notion of personal data, in contrast to the recent conclusions of Advocate General Dean Spielmann in case C-413/23 P of 6 February 2025. In fact, adopting a more restrictive approach, the Advocate General emphasises that, in order to determine whether pseudonymised data should be considered personal data and therefore fall within the objective scope of the GDPR, one must take into account the reasonable likelihood that the additional information can be used by the recipient of the data to identify the data subject, as the mere theoretical identifiability of the data subject is not sufficient.</p><p class="text-justify">Going back to the Guidelines, a fundamental concept introduced by the EDPB is that of “pseudonymised domain”, which can be defined as the set of authorised individuals and systems that can access the pseudonymised data. Within said domain, which is to be determined by the data controller/processor, the pseudonymised data can be processed minimising the risk of re-identifying the data subjects. This logically implies that pseudonymisation secrets&nbsp;must be kept separate from the pseudonymisation domain.&nbsp;</p><p class="text-justify">Keeping in mind the&nbsp;accountability principle, the controller is required to evaluate, also through periodic&nbsp;risk assessments, the likelihood of re-identification within the pseudonymisation domain, so as to ensure that the risk remains negligible throughout the entire processing period.</p><p class="text-justify">On the other hand, the Guidelines also provide useful operational guidance for companies and operators, giving some examples of appropriate technical measures for pseudonymisation, including:</p><ul><li><p class="text-justify"><span>advanced encryption techniques, such as SHA-3 hash functions, which can be used to create pseudonymised data. To increase the security of the process, it is possible to combine such functions with a salt, i.e. a randomly and securely generated data string;</span></p></li><li><p class="text-justify"><span>security measures relating to the IT infrastructure, such as limiting access to&nbsp;pseudonomysation secrets&nbsp;(in concrete terms, access could be limited to system administrators only, applying also to them the principle of least privilege);</span></p></li><li><p class="text-justify"><span>the use of&nbsp;data protection engineering&nbsp;tools on so-called quasi-identifiers (i.e. information that, if combined, can indirectly identify an individual), including techniques such as&nbsp;generalisation and suppression, which modify the level of detail of the data or eliminate highly risky data to reduce the risk of re-identification.</span></p></li></ul><p class="text-justify">In conclusion, the analysis of the Guidelines highlights the fundamental role that pseudonymisation can play in the application of the principle of privacy by design, as well as in some areas of business activity that are extremely sensitive from a&nbsp;data protection&nbsp;point of view, such as the management of whistleblowing channels and the transfer of personal data outside the EU. As clarified by the Guidelines, pseudonymisation can also facilitate the use of legal bases such as the legitimate interest referred to in Article 6(1)(f) of the GDPR for the processing of personal data - an approach that is certainly useful when looking for an alternative to consent and balancing the interests of companies and the rights of individuals - and favour the compatibility of the data processed by any recipients with the evaluation of the original purpose of the processing, pursuant to Article 6(4) GDPR.&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/f/4/csm_ADV_II_Intellectual-Property-4_copy_a5f140c600.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
            
        </channel>
    </rss>


