<?xml version="1.0" encoding="utf-8"?>







    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom">
        <channel>
            <title>ADVANTLAW -&gt; News</title>
            <link>https://www.advantlaw.com/</link>
            <description></description>
            <language>it-it</language>
            <copyright>RYZE Digital</copyright>
            
            <pubDate>Wed, 09 Sep 2026 19:50:02 +0200</pubDate>
            <lastBuildDate>Wed, 09 Sep 2026 19:50:02 +0200</lastBuildDate>
            
            <atom:link href="https://www.advant-nctm.com/en/news/feed.xml" rel="self" type="application/rss+xml" />
            
                
                    <item>
                        <guid isPermaLink="false">news-10643</guid>
                        <pubDate>Mon, 31 Aug 2026 09:47:57 +0200</pubDate>
                        <title>Cyber Resilience Act: quali prodotti rientrano e quando adeguarsi</title>
                        <link>https://www.advant-nctm.com/en/news/ambito-di-applicazione-del-cyber-resilience-act</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>A smartwatch, a router, an industrial PLC, and even a cloud API: very different products, but with something in common. They could all fall within the scope of the Cyber Resilience Act.</p><p>For an initial assessment, just ask three questions.</p><p>Does the product contain digital elements?</p><p>Is it made available on the European Union market in the course of a commercial activity?</p><p>Can it exchange data with another device or a network?</p><p>If the answer to all three questions is yes, then the CRA applies.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10578</guid>
                        <pubDate>Thu, 23 Jul 2026 14:19:00 +0200</pubDate>
                        <title>Raffaele Giarda joins ADVANT Nctm as new Partner</title>
                        <link>https://www.advant-nctm.com/en/news/raffaele-giarda-nuovo-partner-di-advant-nctm</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">ADVANT Nctm announces that Raffaele Giarda has joined the Firm as Partner.&nbsp;</p><p class="text-justify">Raffaele Giarda’s arrival further strengthens the Firm’s Technology, Media, Entertainment and Telecommunications (TMT) practice, which will benefit from his extensive experience gained over more than three decades in sector-specific regulation, including matters relating to foreign direct investments in Italy (FDI).</p><p class="text-justify">The appointment of Raffaele Giarda is part of ADVANT Nctm’s ongoing strategy to further enhance its professional capabilities in support of clients, reinforcing the Firm’s TMT expertise at a time when innovation and digital transformation represent key drivers for businesses and their growth.</p><p class="text-justify"><i>“Raffaele Giarda’s arrival is a source of great pride for us. He is a highly regarded professional with a strong reputation built over decades of experience, including internationally, in the TMT sector and in advising on complex transactions. His experience further enhances our offering in this area while strengthening the Firm’s ability to support clients in a rapidly evolving and constantly changing market environment”</i>, commented <strong>Paolo Montironi</strong>, <strong>Senior Partner</strong> at <strong>ADVANT Nctm</strong>.</p><p class="text-justify"><i>“Joining ADVANT Nctm represents a new and important stage in my professional journey, within a Firm that combines a European dimension, the quality of its professionals and a clear vision for growth. I bring with me extensive experience in the TMT sector, with the aim of contributing from the outset to the further strengthening of the Firm’s position in its market”</i>, said <strong>Raffaele Giarda</strong>.</p><p class="text-justify">Following Raffaele Giarda’s arrival, ADVANT Nctm’s total number of Partners reaches 88.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/6/9/csm_ADV_HandinHand_ab9ab6cfbc.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10517</guid>
                        <pubDate>Fri, 03 Jul 2026 14:45:29 +0200</pubDate>
                        <title>2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace</title>
                        <link>https://www.advant-nctm.com/en/news/relazione-annuale-2025-del-garante-privacy-lia-accelera-la-compliance-digitale-deve-correre</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On <strong>2 July 2026</strong>, at the Sala della Regina of Palazzo Montecitorio, the Italian Data Protection Authority (“Garante”) presented to Parliament its Annual Report on activities carried out in 2025. This is more than the customary institutional report (and likely the last to be presented by the current Board, whose term expires in 2027). Rather, it provides a snapshot of a digital ecosystem in which artificial intelligence, digital identity, connected healthcare, algorithmic management of work, child protection and cyber security have become part of a single legal and regulatory agenda. The underlying message is clear: privacy is no longer merely a defensive compliance exercise, but a driver of innovation, trust and competitiveness.</p><p><strong>AI and new technologies: from experimentation to accountability</strong></p><p>Unsurprisingly, given current developments, the most prominent chapter of the Report is the one <strong>on artificial intelligence (AI)</strong>. The Garante continued to pursue an approach that is not solely enforcement-driven but aimed at addressing risks to data subjects at an early stage: from oversight of <strong>deepfakes </strong>to enforcement measures concerning <strong>deepnude </strong>applications and the non-consensual generation of intimate images. From this perspective, the processing of personal data has become the principal point of tension between computational power, model opacity and the protection of individual dignity.</p><p>The same approach is reflected in initiatives concerning <strong>web scraping</strong>for the training of generative AI systems and in the favourable opinion on the ministerial guidelines for the introduction of AI in schools. The point is not to halt innovation, but to ensure it is properly governed through a valid legal basis, meaningful transparency, data minimisation, impact assessments where necessary, and documented governance throughout the entire lifecycle of the system. For businesses and public administrations, AI cannot be regarded purely as a technological project: it is, in every respect, also a regulatory issue.</p><p><strong>Digital healthcare, public administration and biometrics: innovating, but by design</strong></p><p>In the healthcare sector, the Authority issued 28 opinions on draft decrees and regulations, reiterating that the digitalisation of care pathways must incorporate <strong>privacy by design</strong>, data minimisation, lawfulness, transparency and accountability from the outset. The Report highlights recurring issues in the management of health records, patient identification procedures, the disclosure of health data and the prevention of unauthorised access to information systems. Digital healthcare therefore remains one of the main testing grounds for compliance: the more useful data is for patient care, the more it must be protected through genuinely effective technical, organisational and procedural measures.</p><p>The use of biometrics likewise confirms the central importance of the principle of proportionality. The <strong>FaceBoarding </strong>case at Milan Linate Airport, concerning the centralised storage of passengers’ biometric data, illustrates that the efficiency of the service cannot override the&nbsp;legal assessment of risk, the necessity of the processing and less intrusive alternatives. In a context of increasing automation of identification processes, biometric data remains a high-risk category and requires heightened caution.</p><p>On the public sector front, the Report also confirms the Garante’s advisory role in the digitalisation of public administration, including work on the <strong>IT-Wallet system</strong>. The message is clear: digital identity, interoperability and administrative simplification can only work if the data-processing architecture is designed in a manner consistent with the European framework and with the principle of effective protection of data subjects.</p><p><strong>Children and work: where technology meets vulnerability</strong></p><p>The protection of children remains a cross-cutting priority. The Garante continued to focus its activities on <strong>age verification </strong>systems, the phenomenon of <strong>sharenting </strong>and awareness-raising campaigns, including <i>“Your privacy is worth more than a like</i>”. Children’s personal data should never be regarded as “insignificant”: it is information that may accompany an individual over time, affecting their digital identity, reputation and freedom of self-determination.</p><p>In the employment context, instead, the Report confirms the focus on disproportionate processing activities and excessive forms of monitoring. The prohibition imposed on <strong>Amazon Italia Logistica </strong>in relation to the data of over 1,800 workers is part of a well-established approach: digital tools, monitoring systems, video surveillance and AI solutions applied to the organisation of work must comply with the principles of necessity, proportionality and transparency. Productivity alone does not justify pervasive surveillance.</p><p><strong>Telemarketing, news reporting and inspections: traditional challenges become more sophisticated</strong></p><p>Alongside the new frontiers of AI, the Report points out that the traditional challenges have by no means disappeared. The fight against <strong>aggressive telemarketing</strong>, particularly in the energy sector, continues to require significant action, not least because data collection and commercial profiling techniques are becoming increasingly sophisticated. Similarly, in balancing privacy and the right to report news, the Authority reaffirmed the principle of the essential nature of information, criticising excessive sensationalism and the publication of unnecessary details that undermine individual dignity.</p><p>Inspection activities confirmed the pervasiveness of data processing and the central importance of controls in high-impact sectors, such as SPID, facial recognition, video surveillance, scientific research,&nbsp;data breaches and public databases. Perhaps the most significant takeaway is that the Garante describes a landscape in which poor practices do not disappear but become layered and amplified by increasingly sophisticated technologies. For this reason, compliance must be continuous, verifiable and underpinned by concrete organisational safeguards.</p><p><strong>Key figures for 2025</strong></p><ul><li data-list-item-id="e56e0609c5b8a973a35ae97cacc35c2e8"><span><strong>807</strong> decisions adopted by the Board.</span></li><li data-list-item-id="ea5b72714ff0d602179e8343b9fe55686"><span><strong>4,288</strong> complaints and <strong>145,846</strong>reports examined.</span></li><li data-list-item-id="ee7c39b67cc1a01b0b43030119b117fb1"><span><strong>65</strong> opinions on legislative and administrative acts and data protection impact assessments.</span></li><li data-list-item-id="e2a1015e8013c0997a1d7897cf2337671"><span><strong>506</strong> corrective and sanctioning measures.</span></li><li data-list-item-id="ecbf0790d1cc3a7a60e1873ad35c550ee"><span>More than <strong>€37 million </strong>in fines collected.</span></li><li data-list-item-id="ef7d3b4e65c2605b8dc6d5d2ad48bc604"><span><strong>2,415</strong> data breach notifications, an increase compared with 2024.</span></li><li data-list-item-id="eebc6417ac49c82332415431de6ececb2"><span><strong>854 </strong>reports concerning the dissemination or threatened dissemination of intimate material, primarily involving cases of <strong>sextortion</strong>.</span></li><li data-list-item-id="e6a060a2015d1a2894485fc222f2f6350"><span><strong>130 </strong>inspections carried out, including with the support of the Guardia di Finanza.</span></li><li data-list-item-id="e5ff83313746b692530cd05046df0c278"><span>More than <strong>13,500 </strong>requests for information from members of the public and organisations handled.</span></li></ul><p><strong>From data to trust: the Report’s real message</strong></p><p>In 2025, the Garante took part in <strong>260 international meetings</strong> and contributed to European and global initiatives on AI, data governance and the protection of fundamental rights. Yet the Report’s central message is directed equally at the national level and at day-to-day implementation: businesses and public administrations are called upon to make data protection a structural pillar of governance, security and trust. Privacy compliance can no longer be confined to the records of processing activities or privacy notices: it must be integrated into decision-making processes, technological development models, supplier management, cybersecurity and corporate culture. In other words, the question&nbsp;is no longer whether to innovate, but how to do so without losing control over data and, consequently, over the relationship of trust with individuals, customers, employees and citizens.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10490</guid>
                        <pubDate>Thu, 25 Jun 2026 13:56:54 +0200</pubDate>
                        <title>AI Enters Trade Secret Protection</title>
                        <link>https://www.advant-nctm.com/en/news/intelligenza-artificiale-segreti-commerciali-proprieta-intellettuale</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">On 10 June 2026, the Italian Council of Ministers approved two draft legislative decrees aimed at adapting national legislation to Regulation (EU) 2024/1689 (the AI Act). Among the proposed measures is an amendment to Article 98 of the Italian Industrial Property Code governing the protection of trade secrets.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>The Content of the New Paragraph 1-bis</strong></p><p class="text-justify">The proposal expressly includes data, algorithms and mathematical methods used for training AI systems among the business information and technical-industrial know-how that may qualify as trade secrets, provided that the traditional requirements of secrecy, economic value and reasonable protection measures are met.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Scope of the Provision: Inclusion and Definition</strong></p><p class="text-justify">The amendment operates on two complementary levels. First, it expressly clarifies that AI-related assets may fall within the scope of trade secret protection. Secondly, it provides a definition of algorithms and mathematical methods, including model architectures, optimisation functions, training procedures and configurations, as well as any other technical-computational element functional to the development of AI systems.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>A Clarification Rather than a New Intellectual Property Right</strong></p><p class="text-justify">The amendment does not create a new intellectual property right over AI models, nor does it alter the existing requirements for trade secret protection. Rather, it provides legal certainty by confirming that AI assets may benefit from the existing trade secret regime.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Objective Limits of Protection</strong></p><p class="text-justify">Protection remains conditional upon the fulfilment of the requirements set out in Article 98. Consequently, publicly available model weights, openly accessible datasets, and generally known architectures or optimisation functions will not automatically qualify for protection.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Why Trade Secrets Rather than Copyright?</strong></p><p class="text-justify">The legislative choice reflects the difficulties of relying on copyright law to protect AI assets. Copyright remains tied to human authorship and individual creative contribution, whereas many AI-related assets derive their value primarily from investment, data collection, engineering effort and technical development rather than creative expression.</p><p class="text-justify">From this perspective, trade secret protection appears better suited to preserving the economic value of large-scale AI investments through an objective and technology-neutral legal framework.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Procedural Aspects: The Specialised Business Courts</strong></p><p class="text-justify">Disputes concerning training datasets, algorithms and model weights benefiting from trade secret protection would fall within the jurisdiction of the Italian Specialised Business Courts, ensuring continuity with existing case law on trade secrets and confidential business information.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Critical Perspectives: The Transparency Challenge</strong></p><p class="text-justify">The proposal is not immune from criticism. Some commentators argue that recognising AI data, architectures and parameters as potential trade secrets may increase opacity at a time when both EU and national legislation are moving towards greater transparency and explainability requirements.</p><p class="text-justify">However, a distinction must be drawn between the explanation of a specific automated decision and disclosure of the underlying model. The former concerns the intelligibility of a decision affecting an individual, whereas the latter concerns access to datasets, model weights, architectures and training configurations. These are distinct legal and technical issues.</p><p class="text-justify">A more delicate tension may arise where verification of an AI system requires access to training data or the model itself in order to investigate bias, discrimination or malfunction. In such circumstances, trade secret protection may operate not as a barrier to explanation, but as a limitation on full inspection of the system.</p><p class="text-justify">&nbsp;</p><p class="text-justify"><strong>Conclusion</strong></p><p class="text-justify">By expressly recognising the potential trade secret protection of AI assets, the proposed amendment provides businesses with valuable guidance for structuring research and development investments and designing protection strategies. It confirms a clear policy choice in favour of an objective form of protection based on secrecy rather than a creativity-based model centred on authorship. The effectiveness of this choice will ultimately depend on how courts and regulators balance innovation, legal certainty, transparency and accountability in the AI ecosystem.</p><p class="text-justify">&nbsp;</p><p class="text-justify">For more information, please visit our <a href="https://www.advant-nctm.com/en/expertise/practice-areas/intellectual-property" target="_blank">Intellectual Property</a> and <a href="https://www.advant-nctm.com/en/expertise/practice-areas/digital-and-data" target="_blank">Digital and Data</a> practice areas.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Intellectual Property</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10463</guid>
                        <pubDate>Wed, 17 Jun 2026 14:38:45 +0200</pubDate>
                        <title>Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)</title>
                        <link>https://www.advant-nctm.com/en/news/space-economy-e-data-economy-il-documento-strategico-di-politica-spaziale-nazionale-dspsn</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The context and purpose of the National Space Policy Strategic Document (DSPSN)</strong></p><p>Space is progressively asserting itself as one of the dimensions of State sovereignty, due to its strategic importance in terms of national security, scientific research and economic competitiveness. Space infrastructure and services, as well as data collected through observation, telecommunications and navigation systems, affect a wide range of public functions: from civil protection to environmental monitoring, from territorial protection to critical infrastructure security, and ultimately industrial and scientific development.</p><p>For these reasons, it is not surprising that the space sector has recently been subject to regulation under Law No. 89 of 13 June 2025, which has bridged the previous regulatory gap, providing Italy with a stable legal framework. This legislative measure recognises the structural transformation of the space sector, which is increasingly characterised by the presence of private operators alongside traditional government agencies, and aims to regulate access to outer space and the performance of space activities through a licensing regime. The law therefore responds to the need to ensure adequate public oversight of operators’ activities, also in order to prevent potential international liability on the part of the State and to avoid a competitive disadvantage compared to other European legal systems already equipped with national regulations governing this sector.</p><p>Law No. 89 of 13 June 2025 represents, however, only one component of the broader process of consolidating Italy’s space governance. Whilst it defines the regulatory framework within which operators are required to carry out space-related activities, the planning and strategic dimension remains central, aimed at identifying the country’s public, industrial, scientific and technological priorities. It is precisely in this context that the National Space Policy Strategic Document (DSPSN) takes on significance. It does not directly regulate access to space, but translates the Government’s guidelines into a medium- to long-term vision for the development of national space policy.</p><p>With regard more specifically to the DSPSN, the relevant legal basis is Law No. 7 of 11 January 2018, which vested in the Prime Minister overall leadership, general political responsibility and coordination of policies relating to space and aerospace programmes. The aforementioned law established the Interministerial Committee for Space and Aerospace Research Policies (“COMINT”), tasked with defining the Government’s policy guidelines on space and aerospace matters. On 14 May, COMINT approved the first National Space Policy Strategic Document (“DSPSN”), which is aimed at translating the Government’s policy guidelines on space and aerospace matters into a medium- to long-term planning framework. The Document sets out strategic objectives and priority measures aimed at strengthening national strategic autonomy, supporting the growth of the industrial and scientific sector and consolidating Italy’s international position in the space sector.</p><p><strong>Key elements of the DSPSN and the strong interconnection between the Space Economy and the Data Economy</strong></p><p>The DSPSN is structured around four key areas of action: i) expanding knowledge and the benefits to society; ii) fostering the growth and competitiveness of the national industrial ecosystem; iii) strengthening the regulatory and governance framework; and iv) identifying priority areas for international cooperation. Across these four areas, “traditional” digital topics play a central role, recognising a close correlation between the development of the Space Economy and the Data Economy.</p><p>In fact, for each of the four areas, the Document attributes strategic relevance to the governance of data collected or related to the space domain, to enabling technologies (artificial intelligence, quantum technologies and robotics) and to cybersecurity. National space policy therefore appears to be built around the idea that the value of space – in terms of efficiency in the performance of public functions and new opportunities for economic operators – lies not only in the development of orbital infrastructure, launch systems or missions, but also – and increasingly – in the ability to transform space-related data, technologies and services into tools for public decision-making, industrial development and national security.&nbsp;</p><p>From this perspective, the Space Economy and the Data Economy are closely interlinked: Earth observation, satellite telecommunications, navigation, Space Domain Awareness and government services all depend on the collection, processing, protection and utilisation of large volumes of data.</p><p><strong>The central role of data governance for the Space economy</strong></p><p>The Document first highlights the importance of space-related analysis and the central role of data in advancing scientific research. With this in mind, Objective 5.1, which is specifically dedicated to supporting scientific and industrial research, provides for the development of open platforms for sharing – both public and private – data relating to scientific and industrial research. The Document also calls for laboratories and centres of advanced expertise specialising in data processing and interpretation, with a view to promoting Open Science and strengthening the national research ecosystem.</p><p>A similar approach is evident in Objective 6.4 regarding satellite data, which focuses on supporting the sustainability of the planet and improving public administration services. In this area, the DSPSN envisages the enhancement and development of the “Iride Marketplace” infrastructure platform, including cloud-based solutions, in order to facilitate access to, processing and sharing of satellite data among public administrations and institutional users. This initiative includes the definition of data interoperability standards and the development of software tools for data visualisation and analysis.</p><p>Furthermore, Objective 9.2 expressly links the use of satellite data to growth in the industrial sector. In this regard, the Document aims to promote the widespread use of satellite data and information, with a particular focus on SMEs and start-ups, in order to enhance their competitive positioning in the commercial market.</p><p>Objective 8.1 is also particularly relevant, as it is dedicated to strengthening Italy’s leadership in Earth Observation. The Document highlights the development of the national Earth Intelligence ecosystem and stipulates that services should be designed to be interoperable and scalable, integrating Earth Observation data with other information sources such as socio-economic data, IoT-derived data, and predictive models. The aim is to provide solutions capable of meeting the needs of public administrations and key sectors, including precision agriculture, natural resource management, environmental monitoring, cultural heritage and security.</p><p class="text-justify"><strong>Technology as a driving force behind the space economy</strong></p><p class="text-justify">A second macro-theme emerging from the DSPSN is the central role of technology in national space policy. The Document does not view technology merely as an area of research and development, but as a cross-cutting lever to enhance competitiveness, strategic autonomy and the capacity to transform space into public and industrial value.&nbsp;</p><p class="text-justify">Already in the “Reference Scenario” section, the DSPSN highlights how the Space Economy is driven by satellite services and data, but also by innovation in launch systems, satellite constellations and artificial intelligence.</p><p>This approach is reflected in the objectives relating to research and skills. Objective 5.1 identifies artificial intelligence for space applications, quantum technologies, new materials, robotics, MEMS sensors and applications for environmental, climate and agricultural monitoring as priority technologies. Objective 5.2 links these areas to the development of advanced STEM skills, providing for specialised training pathways and centres of excellence dedicated, among other things, to AI, cybersecurity and quantum technologies applied to space.</p><p>Technology is also of key importance in relation to national technological sovereignty. Objective 7.3 provides for a plan to develop critical space technologies and calls for proposals relating to emerging and enabling technologies, including AI, advanced propulsion, cybersecurity and quantum technologies, also for complex and dual-use space applications. In this regard, safeguarding critical technologies is intended to reduce dependencies and strengthen the country’s industrial capacity.</p><p>Finally, the DSPSN emphasises technology in the management of space data and in the modernisation of the production and administrative system. Objective 8.1 links the development of the Iride Marketplace to data storage, analysis and distribution, including through the use of AI and machine learning. Objectives 9.1 and 11.1 refer, respectively, to digitalisation, robotics, digital twins and AI for production infrastructure, as well as advanced digital skills in public administration. This gives rise to an integrated vision, in which technology cuts across research, industry, data, training and administration, emerging as an essential prerequisite for an innovative and independent space policy.</p><p><strong>Space and cybersecurity</strong></p><p>The third macro-theme is that of cybersecurity. In the DSPSN, cybersecurity is closely linked to the recognition of space as a strategic domain, characterised by critical infrastructure, dual-use applications and geopolitical risks. The protection of space systems is, therefore, not regarded merely as a technical requirement, but as a component of national security.</p><p>The Document, again in the “Reference Scenario” section, highlights that the protection of satellite infrastructure has become indispensable for safeguarding national activities and capabilities on Earth. This is particularly relevant for dual-use systems, where security requirements must be taken into account from the earliest stages of development.</p><p>Objective 5.2 explicitly includes cybersecurity skills among those necessary for the development of the Space Economy. The Document provides for dedicated training programmes and the creation of laboratories and centres of excellence for research and training in cybersecurity applied to space.</p><p>The key point on this issue, however, is Objective 7.2, which provides for the development of a cybersecurity plan or roadmap, in accordance with Law No. 89 of 13 June 2025. This plan is intended to implement end-to-end cybersecurity, monitoring systems for critical infrastructure and natural hazards, rapid response, data protection and standard protocols. The Document also emphasises the maintenance, upgrading and resilience of space, satellite, ground and IT infrastructure, as well as the establishment of advanced cyber defence capabilities, including a Space Security Awareness Centre.</p><p>Finally, Objective 7.3 places cybersecurity within the broader framework of the National Space Security Strategy. The Document links the protection of critical assets, know-how and classified and sensitive information to the need to strengthen national technological sovereignty. Objective 8.2 also has significant implications, insofar as it refers to the development of satellite infrastructure for secure and resilient connectivity, high-speed optical communications, quantum encryption, RF systems, onboard processing, protocols, ground segments and user terminals.</p><p><strong>Preliminary reflections on the DSPSN: new opportunities for Italian businesses?</strong></p><p>The analysis of the DSPSN reveals that digital technology constitutes an essential component of national space policy. The Space Economy outlined in the Document is no longer limited to the infrastructural dimension of space, but increasingly relies on the ability to collect, process, protect and leverage digital data and services.&nbsp;</p><p>From this perspective, the Space Economy and the Data Economy are closely interconnected: the strategic value of space depends on the ability to transform satellite data, enabling technologies and space capabilities into useful tools for public administration, businesses and society.</p><p>The central role attributed by the DSPSN to data governance, artificial intelligence, quantum technologies, robotics, machine learning, digital twins and cybersecurity confirms that digital technology is the key enabler of the new space economy. Through these technologies, space infrastructure and data can be converted into advanced services for environmental and climate monitoring, precision farming, civil protection, the security of critical infrastructure, secure communications and the modernisation of production and administrative processes.</p><p>Within this framework, significant opportunities arise for Italian companies, including SMEs and start-ups, which are called upon to develop solutions based on satellite data, Earth Intelligence, artificial intelligence, cybersecurity, resilient communications and downstream services. Data access and sharing platforms, the further development of the Iride Marketplace, support for emerging technologies and targeted calls for proposals relating to critical space technologies may contribute to strengthening Italy’s industrial supply chain.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/0/5/csm_Spazio_31fecfe572.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10462</guid>
                        <pubDate>Wed, 17 Jun 2026 14:33:43 +0200</pubDate>
                        <title>Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation</title>
                        <link>https://www.advant-nctm.com/en/news/governance-dei-dati-personali-nei-club-calcistici-luso-dei-dati-come-leva-strategica-tra-gdpr-sicurezza-e-valore-generato</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The football club as a data ecosystem (and as a media company)</strong></p><p>From a personal data protection perspective, a medium-to-large football club is no longer just about “sport and ticketing”; it is a physical and digital ecosystem that generates value through <strong>data and proprietary content</strong>.</p><p>Here, privacy is not a “side issue” to be ticked off a list: it is part of the business model, as it&nbsp;builds trust, enables monetisation, enhances brand value and ensures operational continuity. The GDPR requires the club to know precisely <strong>what data is collected</strong>, where it is stored, who has access to it, on what legal basis it is processed and for how long, while clearly distinguishing among the various categories of data subjects (supporters, minors, players, technical and medical staff, employees, suppliers).</p><p>At the same time, many clubs now operate as fully-fledged <strong>media companies</strong>: they produce and distribute proprietary content, manage official thematic channels and, in some cases, “club-branded” digital or streaming platforms with a D2C (Direct-To-Consumer) approach.</p><p><strong>Types of data and “high-impact” risks</strong></p><p>The data that is most valuable from a business perspective is often also the most risky in terms of its potential impact on the fundamental rights of data subjects:</p><ul style="margin-left:7px;"><li data-list-item-id="e3065cb180fc12b73152340dd43bc1eab"><span><strong>Personal and contact data </strong>(memberships, ID badges, accreditation data, CRM data);</span></li><li data-list-item-id="e3c39997d4c1617458651135397ed6d73"><span><strong>Financial data </strong>(payments, refunds, invoicing);</span></li><li data-list-item-id="e026fb8b715866e5f6e6044297ff3d94b"><span><strong>Audio-visual recording data </strong>(matches, training sessions, events, editorial content);</span></li><li data-list-item-id="e47655b3cdbc7295d632f610d35c85ead"><span><strong>Access and physical/digital security data </strong>(turnstiles, access control, logs);</span></li><li data-list-item-id="eb4e66ea0f0b6a77447fb5d362f9844c3"><span><strong>Data relating to users’ digital behaviour </strong>(apps/websites, interactions, marketing campaigns);</span></li><li data-list-item-id="ede57e86901d7ad553471371e7bdffbdc"><span><strong>Health and performance data </strong>(fitness, injuries, wearables/GPS, performance analysis).</span></li></ul><p>An often underestimated “strategic” aspect is that many top-tier clubs now have <strong>entire teams of data analysts </strong>(or analytics departments) working on <strong>performance, injury prevention, match analysis and, above all, player scouting and recruitment</strong>.</p><p>When inferences about health or physical condition are drawn from performance data, or when health or biometric data are processed, the processing tends to become “high risk”. This requires stronger legal bases and conditions of lawfulness, compliance with the principles of data minimisation and proportionality, segregation of access rights and, often, a <strong>DPIA </strong>(and, if legitimate interest is used, a well-reasoned <strong>LIA</strong>).</p><p><strong>Privacy by design and by default (separation by domain, not by “function”)&nbsp;</strong></p><p>In a well-structured club, the golden rule is to design separate<strong> data domains </strong>and controls that are consistent with the relevant purposes and legal bases, whilst avoiding informal archives and “catch-all repositories”.</p><p>From a best-practice perspective, one might envisage at least:</p><ul style="margin-left:7px;"><li data-list-item-id="e53d7a1f88f4c3e677032764e6c227470"><span><strong>A medical/sports performance area</strong>: health and performance data;</span></li><li data-list-item-id="e213fd50316797c82c55b25388aaffbd3"><span><strong>A sporting operations area</strong>: contracts, team selection records, non-health-related technical statistics;</span></li><li data-list-item-id="e97c8133dfc165eda78bacbc943a86bf5"><span><strong>A media/marketing area</strong>: images and videos for communication, contact details and preferences, digital interaction data.</span></li></ul><p><strong>Privacy roles and the supplier chain (including broadcasters and media partners)</strong></p><p>As a rule, the club is <strong>the </strong>data<strong> controller </strong>for the processing of personal data relating to its sporting and commercial activities. However, the actual governance depends on the supply chain of the relevant service providers, such as, for example, ticketing, CRM, cloud services, contact centres, digital agencies, wearable tech, media content production and distribution.</p><p>Here, compliance hinges on contracts and responsibilities:</p><ul style="margin-left:7px;"><li data-list-item-id="e3cf0b73155e978e2b00f92ebedf08604"><span><strong>Data processor</strong>, where the supplier processes data on behalf of the club;</span></li><li data-list-item-id="e540d8b505c4f8343808b5434c38dcfa9"><span><strong>Joint controllers</strong>, where the purposes and means are determined jointly (e.g. initiatives with sponsors or co-marketing);</span></li><li data-list-item-id="ec5ebe6c083af5c16460d06daca46afb5"><span><strong>Independent controller</strong>, where the partner uses the data for its own purposes (a scenario that is not uncommon in the media, streaming and advertising sectors).</span></li></ul><p>From the “media company” perspective, it is also useful to consider <strong>the scope and distribution rights </strong>between the club’s own channels and third-party digital services (concepts such as “official club platform” versus “third-party digital service” help to avoid confusion between content governance and personal data governance).</p><p><strong>Legal bases and transparency: why consent is not a “wild card”</strong></p><p>A club should avoid the temptation of “universal consent”:</p><ul style="margin-left:7px;"><li data-list-item-id="ee08227dfd96c69fa899bf33444f5b326"><span>for many core processing activities (performance of a contract, legal obligations, security, sports management), consent is not the most appropriate basis;</span></li><li data-list-item-id="e8646a71507b402d791e0ae4149b01388"><span><strong>consent becomes crucial for direct marketing, commercial profiling, and non-essential cookies and tracking technologies</strong>.</span></li></ul><p>In practical terms, two things make all the difference:</p><ol><li data-list-item-id="e2a5caa602a1808cf92faf94c9d3643ae"><span><strong>Omnichannel privacy notices </strong>(stadium, ticketing, app, e-commerce, academy), which are consistent but not “one-size-fits-all”;</span></li><li data-list-item-id="e4b00c87c18ff9f19eaaceccb3938b5e1"><span><strong>Preference and consent management </strong>in CRM systems: granular consents, simple withdrawal mechanisms, cross-channel alignment.</span></li></ol><p><strong>The digital dimension of data processing activities</strong></p><p>This is where the most typical risks are concentrated: lack of transparency in profiling, excessive sharing with third parties, “indefinite” retention, and unregulated transfers outside the EU.</p><p>Italian Data Protection Authority’s Guidelines on cookies and tracking tools (10 June 2021) reiterate that, where required, consent must be freely given, specific, informed and documented, and discourage misleading practices.</p><p>For a club that offers users a seamless experience within an interconnected ecosystem – across apps, e-commerce, OTT services (streaming platforms and on-demand content) and other</p><p>digital initiatives – it is essential to avoid automated cross-device and cross-platform tracking across the various touchpoints. A data value-creation strategy is truly effective only when supported by robust data governance and when its logic remains transparent and explainable to users at all times.</p><p><strong>Minors and the youth sector</strong></p><p>The youth sector significantly increases the level of risk exposure, both because of the age of those involved and the nature of the data processed, which often relates to sport, education and, in some cases, health.</p><p>In Italy, the age at which a person may validly provide <strong>digital consent </strong>in relation to information society services <strong>is set at 14</strong>; below this age, parental authorisation is required.</p><p>This does not mean, however, that content and images may be used freely or indiscriminately. The correct approach remains to <strong>minimise the amount of data </strong>and clearly distinguish between what is necessary for sporting activities and what serves promotional purposes, by establishing specific policies on the use of images, official channels, retention periods and procedures for revocation.</p><p><strong>The stadium as a “data system”</strong></p><p>Video surveillance systems, access control, stewarding and crowd management also generate continuous streams of personal data.</p><p>Compliance is achieved through: visible privacy notices (including simplified versions), clearly defined purposes (security/public order), non-excessive data retention, restricted access to recordings, rules governing cooperation with the authorities, and clarity regarding the data protection responsibilities assumed by the company on a case-by-case basis.</p><p><strong>Cybersecurity and data breach management</strong></p><p>For clubs, the security of personal data is not merely an IT issue: a data breach affecting CRM, ticketing, payment or sports medicine systems can have legal, financial, reputational and sporting consequences.</p><p>A clearly defined process is required: detection, containment, risk assessment, recording, post-incident procedures and – where required – notification to the supervisory authority within 72 hours, and communication to data subjects.</p><p><strong>Privacy function, DPO and internal governance</strong></p><p>As complexity increases, a mature privacy function is required, integrated with other corporate functions:</p><ul style="margin-left:7px;"><li data-list-item-id="efed154cd504b2abec0bc27dc9fcf3203"><span><strong>DPO </strong>where applicable (regular and systematic monitoring on a large scale, special categories of data on a large scale, etc.);</span></li><li data-list-item-id="e1cf89923ed83a21d6438746240ed3194"><span><strong>A constantly updated record of processing activities</strong>;</span></li><li data-list-item-id="e9359046304990e88da84ae34912c0aa6"><span><strong>Data ownership </strong>by domain (Fans/Ticketing, Media/Content, Academy, Player Medical/Performance, Stadium Security): clarity on who decides, who authorises and who is accountable;</span></li><li data-list-item-id="e0d969736f77137d14f817741b56ccf15"><span><strong>Vendor governance</strong>: due diligence and audits on critical processing operations (e.g. ticketing, CRM, OTT, wearables, security).</span></li></ul><p class="text-justify"><strong>Conclusion: trust as an asset, data as a strategic lever</strong></p><p class="text-justify">In modern football, the trust among fans, families, players, sponsors and investors also depends on how the club manages its data. A club that treats personal data as an asset (rather than a risk to be addressed) achieves greater operational continuity, better fan engagement and more sustainable partnerships – precisely because it effectively operates as both a sports organisation and <strong>a media company</strong>.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/2/c/csm_Calcio_63783d8349.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10461</guid>
                        <pubDate>Wed, 17 Jun 2026 14:32:32 +0200</pubDate>
                        <title>Tracking pixels in e-mails: the Data Protection Authority&#039;s new rules</title>
                        <link>https://www.advant-nctm.com/en/news/tracking-pixel-nelle-e-mail-le-nuove-regole-del-garante</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>1. Introduction</strong></p><p>By Order No. 284 of 17 April 2026, published in the Official Gazette on 29 April 2026, the Data Protection Authority (<i>“<strong>Authority</strong>”</i>) adopted the first Guidelines specifically dedicated to the use of tracking pixels in electronic mail communications (“<i><strong>Guidelines</strong></i>”).</p><p class="text-justify">This measure comes at a time of growing attention to tools for monitoring users’ online behaviour and aims to provide a uniform interpretative framework regarding the application of Article 122 of Legislative Decree No. 196/2003 (“<i><strong>Privacy Code</strong>”</i>) and the provisions of Regulation (EU) 2016/679 (“<strong>GDPR</strong>”) to tracking systems embedded in emails.</p><p>According to the Authority, tracking pixels are particularly intrusive tools as they operate without the data subject’s knowledge. The Guidelines are based on the observation that such technologies enable the sender to determine whether a message has been opened, the number of views, the device used and, in some cases, further technical data relating to the recipient.</p><p><strong>2. Key points of the measure</strong></p><p><i>2.1 The classification of tracking pixels as tools subject to Article 122 of the Privacy Code</i></p><p>One of the main clarifications provided by the Authority concerns the legal nature of tracking pixels.</p><p>The Authority states that the insertion of the pixel and the subsequent collection of information generated by its activation constitute operations falling within the scope of Article 122 of the Privacy Code, as they involve both a form of <i>“storage of information on the terminal equipment of a data subject or user</i>” and subsequent <i>“access to information already stored</i>”.</p><p>Of particular significance is the passage in which the Authority states that tracking pixels must be regarded as covert tracking tools, as their presence is not normally detectable by the user and they operate automatically and invisibly.</p><p>The Guidelines also identify a number of parties that may be involved in the use of tracking pixels, including the sender of the message, the email service provider, the provider of mailing list rental services, the provider of tracking technology and the content creator. The Authority specifies that each of these parties is required, on a case-by-case basis and in accordance with the principle of accountability, to define their respective roles for the purposes of&nbsp;the legislation on the protection of personal data.</p><p>The measure also distinguishes between different types of email messages relevant for the purposes of</p><p>the application of the regulations: (i) newsletters, i.e. periodic communications of an informative nature; (ii) DEM (Direct Email Marketing), communications of a predominantly&nbsp;promotional or commercial nature; (iii) transactional emails and automated messages, sent in connection with specific user actions or ongoing transactions; and (iv) service emails, characterised by content designed to meet the specific needs of individuals or the community. This classification&nbsp;is relevant for the purposes of identifying the legal basis applicable to the processing associated with the use of tracking pixels.</p><p><i>2.2 The obligation to provide prior information</i></p><p>The Guidelines attach particular importance to transparency.</p><p class="text-justify">Indeed, according to the Authority, the use of tracking pixels in emails must be disclosed in advance to the email recipient, regardless of the purpose of the communication or the type of sender.</p><p>The Authority also emphasises that the use of tracking pixels requires all data controllers who already use them or intend to use them to adequately inform the data subjects, in accordance with the principles of fairness and transparency set out in the GDPR.</p><p>At an operational level, the measure allows for simplified, layered information procedures, allowing, for example, the use of summary notices accompanied by links to detailed documentation, as well as the use of digital tools such as chatbots, pop-ups, virtual assistants or other communication channels.</p><p><i>2.3 When consent is required</i></p><p>A central aspect of the Guidelines concerns identifying the cases in which the use of tracking pixels requires the user’s consent.</p><p>The Data Protection Authority reiterates that Article 122, paragraph 2-<i>bis</i>, of the Privacy Code introduces a general prohibition on accessing information stored on a user’s terminal equipment, storing information, or monitoring user activity through electronic communications networks; such prohibition may only be subject to derogation where the conditions set out in paragraph 1 of the same Article are met.</p><p class="text-justify">The main scenarios in which consent may not be required include:</p><ul style="margin-left:8px;"><li data-list-item-id="e4a6e74596e6766f2cb2d9ea303771998"><span>processing carried out solely for the purpose of aggregated statistical analysis of email opens, provided that appropriate anonymisation techniques are used;</span></li><li data-list-item-id="e19d89873ec344a78e600dc33d6908611"><span>activities necessary to ensure the security of authentication or account management processes;</span></li><li data-list-item-id="e2f2e435a9effa4ad0061e3f63f7558ce"><span>service or institutional communications where the sender has a legal obligation to send them or where there are specific requirements to protect users. By way of example, the Data Protection Authority refers to messages containing useful guidance on how to prevent phishing or fraud, communications regarding contractual or logistical/organisational changes, notifications relating to security incidents, official information campaigns, as well as reminders regarding deadlines and contractual or social security obligations.</span></li></ul><p>Conversely, consent is required when tracking is used for marketing purposes, profiling, or the individual optimisation of promotional campaigns.</p><p>The provision expressly refers to cases where individual measurement and analysis of email open rates are used to assess and improve the performance of promotional campaigns on the basis of observed behaviour, or when the open rate data is used to derive inferred information about the user’s potential tastes, interests and preferences for the purpose of creating commercial profiles.</p><p><i>2.4 Single consent and the right to granular withdrawal</i></p><p>One of the most innovative aspects of the Guidelines is the attempt to reconcile the need for protection with that for simplification.</p><p class="text-justify">The Data Protection Authority indeed recognises that consent to receive promotional communications and consent to the use of tracking pixels can be obtained through a single expression of consent.</p><p>This simplification is, however, accompanied by an important safeguard for the data subject: the possibility of subsequently withdrawing consent, even on a selective basis.</p><p>The Guidelines stipulate that the user may revoke consent only partially, specifically with regard to tracking associated with the receipt of tracking pixels, while continuing to receive email communications that do not contain tracking tools, if they so wish.</p><p>The Data Protection Authority also draws attention to the data controller’s obligation to duly record all choices made by the data subject, including any partial withdrawals, not least for the purposes of demonstrating consent, which the data controller may be required to do pursuant to Article 7(1) of the GDPR.</p><p><i>2.5 Privacy by design and data minimisation</i></p><p>The measure also focuses on the technical measures that data controllers should adopt to reduce the risks arising from tracking.</p><p>Among the suggested solutions is the use of pseudonymised and non-sequential identifiers, while keeping the correspondence between these identifiers and the recipients’ email addresses separate.</p><p>According to the Data Protection Authority, these measures help to reduce the exposure of email addresses by minimising the risk of data passing through the network being traceable.</p><p><strong>3. Practical implications</strong></p><p>The new Guidelines will have a significant impact on all operators using email campaigns, marketing automation platforms, newsletters and direct email marketing systems.</p><p>In particular, organisations will need to:</p><ul style="margin-left:7px;"><li data-list-item-id="e256f16286ac34f1fc50ebddb5ead708f"><span>check whether the tracking pixels used fall within the exemptions identified by the Data Protection Authority or whether they require consent to be obtained;</span></li><li data-list-item-id="e8c16fa52ce2af3376e7fe234171b4933"><span>update their personal data processing notices/privacy policies, cookie policies and consent collection procedures;</span></li><li data-list-item-id="e6e96713da647ad2ce2396b5b63443611"><span>implement mechanisms that allow users to withdraw their consent to tracking in a simple and granular manner;</span></li><li data-list-item-id="e422a0f828b8ad451557cdee99bf95d2b"><span>review their contractual relationships with email service providers, marketing automation</span><i><span>&nbsp;</span></i><span>platforms and tracking technology providers;</span></li><li data-list-item-id="e6e0dd45a78da680861da332d14a1be11"><span>assess the adoption of technical measures in line with the principles of “privacy by design” and “privacy by default”.</span></li></ul><p>The transitional arrangements set out in the measure are also particularly significant. The Data Protection Authority has recognised the complexity of the required adjustments, granting operators a <strong>period of six months </strong>from the date of publication in the Official Gazette. The Guidelines distinguish, in this regard, between new processing operations, for which consent must be obtained in advance at the time the email address is collected, and processing operations already underway, for which the data controller must promptly fulfil their information obligations with the first available communication and implement a mechanism allowing for the withdrawal of consent, even on a granular basis, identifying solutions characterised by maximum recognisability, visibility and ease of use for the benefit of the data subject. The Data Protection Authority specifies that this transitional regime is intended to be gradually phased out as new processing operations are undertaken and become subject to the rule requiring prior consent.</p><p><strong>4. Conclusions</strong></p><p>The new Guidelines mark an important step in the evolution of Italian legislation on tracking technologies.</p><p>The Authority confirms a broadly rigorous approach, classifying tracking pixels as tools subject to the special rules set out in Article 122 of the Privacy Code and reaffirming the central importance of the principles of transparency and control by the data subject.</p><p>At the same time, the Authority introduces certain operational simplifications – such as a single consent for promotional communications and tracking – and identifies specific cases of exemption that allow the efficiency of certain services to be maintained.</p><p>For businesses, public bodies, technology providers and digital marketing practitioners, the six-month compliance period provided for by the regulation therefore represents an opportunity to review the processes, tools and legal bases for data processing relating to the sending of electronic communications, in light of a regulatory framework that increasingly prioritises transparency and user awareness.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10460</guid>
                        <pubDate>Wed, 17 Jun 2026 14:30:01 +0200</pubDate>
                        <title>THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS </title>
                        <link>https://www.advant-nctm.com/en/news/le-nuove-linee-guida-della-commissione-sulla-classificazione-dei-sistemi-di-ia-ad-alto-rischio</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The context and structure of the Guidelines</strong></p><p>Regulation (EU) 2024/1689 (“<strong>AI Act</strong>”) imposes significant obligations regarding governance, documentation, transparency, human oversight and monitoring on AI systems classified as “high-risk” under Article 6. In this context, the European Commission has recently published and launched a public consultation on draft<a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems" target="_blank" rel="noreferrer"><strong>Guidelines</strong></a>, adopted pursuant to Article 6(5) of the AI Act, with the aim of supporting providers, deployers and competent authorities in classifying the level of risk associated with AI systems.</p><p>Although not legally binding, the Guidelines represent the main interpretative reference currently available for carrying out this classification and provide numerous practical examples intended to guide the application of the provisions of the AI Act.</p><p>Article 6 distinguishes between two categories of high-risk systems. The first comprises AI systems intended for use as safety components of a product, or which themselves constitute a product covered by the EU harmonisation legislation listed in <strong>Annex I </strong>to the AI Act, provided that they are subject to third-party conformity assessment. The second, on the other hand, concerns systems that fall within one of the use cases listed in <strong>Annex III</strong>, which includes, amongst others, the areas of biometrics, employment, access to essential services (including credit scoring and insurance risk assessment), critical infrastructure, migration and the administration of justice.</p><p><strong>Annex I: the concept of “safety component”</strong></p><p>With regard to the systems covered by Annex I, one of the most significant clarifications provided by the Guidelines concerns the concept of “safety component” referred to in Article 3(14) of the AI Act,</p><p>which applies in two alternative scenarios.</p><p>The first scenario is fairly intuitive and concerns AI systems intended by the provider to perform a <strong>safety function,</strong> namely to prevent or mitigate risks to health, the safety of persons or property.</p><p>The second scenario is less obvious: an AI system may qualify as a safety component, <strong>irrespective of the provider’s intended purpose</strong>, if its failure or malfunction – including incorrect outputs, false negatives or misclassification – may endanger the health and safety of persons or property in the product context.</p><p>The Commission cites, by way of example, systems used in the operation of lift doors, lane assistance functions, or the optimisation of the functioning of household appliances, where a malfunction could result in physical harm to persons.</p><p>By contrast, functionalities aimed solely at operational efficiency, performance optimisation or service-quality improvement remain excluded where any error would not give rise to safety risks.</p><p><strong>The “intended purpose” and liability along the AI supply chain</strong></p><p>A key issue addressed by the Guidelines concerns the concept of “intended purpose”, defined in Article 3(12) of the AI Act as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the relevant technical documentation, instructions for use and promotional or sales materials.</p><p>According to the Commission, the classification of a system does not depend solely on its technical characteristics, but also on the way in which the provider presents it on the market.</p><p>The Guidelines clarify that, where contractual documentation, instructions for use, promotional materials or technical documentation present the system as applicable across a generality of contexts, without clearly defining the permitted uses or specifically excluding high-risk uses, the intended purpose may also encompass such uses.</p><p>Of particular significance is the statement that <strong>a generic contractual clause asserting that high-risk uses of the system are excluded is in itself insufficient </strong>to prevent the system from being classified as “high-risk”, if the product positioning or the provider’s examples of use effectively provide for or promote such uses.</p><p><strong>Annex III: use cases of greatest interest to businesses</strong></p><p><i>Systems used in the employment sector</i></p><p>Among the cases covered by Annex III, those relating to the employment sector are of particular practical importance to businesses.</p><p>The Guidelines clarify that all systems which significantly influence the <strong>selection process </strong>are classified as high-risk, even if they do not directly determine the outcome.</p><p>Therefore, the high-risk category includes, for example, job-matching and candidate-ranking systems, tools that assign scores or classifications during the selection process, automated systems for searching for candidates on social networks or public databases, as well as targeted job advertising solutions that determine which users will see specific job vacancies.</p><p>A similar approach is adopted with regard to the<strong> management of work-related relationships</strong>. The Guidelines confirm that systems used to assign tasks, determine operational priorities, monitor performance, influence professional assessments or decisions relating to promotions, remuneration or termination of employment, particularly where such activities are based on the processing of behavioural indicators.</p><p>Furthermore, the Commission specifies that the scope of application of the cases in question is not limited to employees, but may also extend to self-employed individuals, professionals, contractors and platform workers.</p><p><i>Credit assessment systems</i></p><p>The Guidelines confirm an equally broad interpretation with regard to systems used for credit assessment.</p><p>According to the Commission, any AI system intended to be used to evaluate the creditworthiness of natural persons or to establish their credit score must be considered high-risk, even where the system serves only one of these purposes.</p><p>This category includes systems that process financial, asset-related or behavioural data to generate scores or assessments used in the decision-making process relating to the granting of credit. Excluded, however, are systems used exclusively for marketing, customer service or the monitoring of exposures following the granting of credit, as well as those intended solely for the purpose of detecting financial fraud, for which the AI Act provides a specific exemption.</p><p><strong>The “filter” mechanism provided for in Article 6(3) of the AI Act</strong></p><p>The Guidelines also devote considerable attention to the exclusion mechanism provided for in Article 6(3) of the AI Act, which allows excluding, subject to certain conditions, from the category of high-risk systems certain AI systems which, despite formally falling within one of the use cases listed in Annex III,<strong> do not materially influence the outcome of the decision-making process</strong>.</p><p>The Commission cites, by way of example, systems that perform purely preparatory, organisational or support tasks, such as document classification, the reorganisation of information or the provision of regulatory references, without making assessments of the specific case or affecting the content of the final decision.</p><p>The Guidelines specify, however, that the filter does not apply when the system carries out</p><p>profiling activities within the meaning of the GDPR, or when it operates within more complex architectures whose outputs contribute substantially to a significant decision. Furthermore, it is reiterated that the mere presence of human oversight (an essential requirement laid down by the AI Act itself) is not sufficient to preclude classification as a high-risk system.</p><p><strong>Timeline and next steps</strong></p><p>The Guidelines are currently open for public consultation, but already provide guidance of</p><p>considerable interest to organisations undertaking AI Act compliance programs. With regard to deadlines, the Guidelines note that the deadlines originally set out in Article 113 of the AI Act have been postponed by the proposed Digital Omnibus Regulation, on which the European institutions have reached a political agreement. In particular, the obligations for high-risk systems classified under Article 6(2) (Annex III) will apply from <strong>2 December 2027</strong>, whilst those for systems classified under Article 6(1) (Annex I) will apply from<strong>2 August 2028</strong>. For systems already placed on the market or put into service before 2 August 2026, the AI Act will apply only in the event of significant design changes made after that date.</p><p>In this context, organisations should carefully review their inventory of AI systems in use, verify the intended purpose identified by providers – including through technical and commercial documentation – and adequately document the assessments carried out in cases of more complex classification.</p><p>Indeed, for many organisations, the main challenge will not be to identify systems that are clearly high-risk, but rather to demonstrate, through a structured and documented analysis, the reasons why a particular system should not be classified as such.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/5/8/csm_ADV_Start-up_2_3dd5708e68.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10459</guid>
                        <pubDate>Wed, 17 Jun 2026 14:26:24 +0200</pubDate>
                        <title>WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?</title>
                        <link>https://www.advant-nctm.com/en/news/perche-il-tribunale-di-roma-ha-annullato-il-provvedimento-del-garante-su-openai</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Summary of the judgement</strong></p><p>On 18 March 2026, the Court of Rome annulled in its entirety order No. 755 issued by the Italian Data Protection Authority on 2 November 2024. However, the Court did not examine the substance of the alleged infringements, resolving the matter entirely on a preliminary and overriding <strong>issue</strong>: <strong>jurisdiction</strong>. A procedural defeat, one might say; yet, in terms of practical consequences, it amounts to a defeat on the merits.</p><p><strong>The contested order: what the Data Protection Authority objected to</strong></p><p>The Data Protection Authority alleged that OpenAI had breached Article 33 of the GDPR for failing to notify the data breach of 20 March 2023: of Articles 5(2) and 6 of the GDPR for the lack of a legal basis for the training of its models; of Articles 5(1)(a), 12 and 13 of the GDPR for shortcomings in the privacy policy; of Articles 24 and 25(1) of the GDPR for failing to put in place age verification systems; and of Article 83(5)(e) of the GDPR for failing to launch the communication campaign that had previously been ordered. The fine amounted to EUR 15 million, accompanied by a six-month institutional communication campaign across all the main Italian media outlets (radio, television, newspapers and the internet).</p><p>OpenAI challenged the order, setting out ten grounds of appeal. The Court considered only the first of these, ruling that it was well-founded and that it encompassed all the others.</p><p><strong>The crux of the matter: who was authorised to impose the penalty?</strong></p><p>OpenAI complained that the Data Protection Authority lacked the competence to investigate cross-border infringements and impose the resulting sanctions, as Articles 55 and 56 of the GDPR provide for the so-called “one-stop-shop” mechanism, under which the only supervisory authority “competent to act” in relation to “cross-border processing” is that “of the main establishment or of the single establishment of the controller”, in its capacity as “lead supervisory authority”.</p><p>The change in circumstances had occurred in the course of the proceedings: OpenAI set up its Irish subsidiary on 24 March 2023 and received, on 15 February 2024, formal notification from the Irish Data Protection Commission recognising OpenAI Ireland as an EU establishment for GDPR purposes. However, the penalty decision was not issued until November 2024, nine months later.</p><p><strong>The Data Protection Authority’s argument — and its legal limitations</strong></p><p>It must be acknowledged that the Data Protection Authority’s position was not without its own internal logic. The defendant administration replied that the penalty decision concerned infringements committed prior to 15 February 2024, taking the view that the applicable legislation <i>ratione temporis </i>was that in force at the time the infringement was committed, with the consequence that the one-stop-shop mechanism did not apply to infringements committed and finalised before that date. In line with such approach, the Data Protection Authority in fact partially complied with the cooperative mechanism: it forwarded to the lead authority in Ireland the documents relating to ongoing and continuing infringements, in accordance — according to its interpretation — with the principle <i>of “tempus regit actum” r</i>eferred to in Article 11 of the Preliminary Provisions.</p><p>However, the Court did not agree with this interpretation, considering that the argument was based on an erroneous reading of <strong>Opinion No. 8 of 9 July 2019 of the EDPB </strong>— a soft-law instrument adopted pursuant to Article 64 of the GDPR at the request of the French and Swedish authorities, which does not constitute a primary source of EU law but contributes to defining the rules applicable to the allocation of competences among national supervisory authorities, serving as an authoritative interpretative guide for courts and administrative authorities to ensure the uniform application of the Regulation throughout the Union.</p><p><strong>How the Court interpreted the EDPB Opinion</strong></p><p>The crux of the decision lies in the interpretation of Article 4.3.2 of the EDPB Opinion, which specifically governs the creation of a main establishment whilst proceedings are ongoing.</p><p>The EDPB has clarified that “the creation of a main or single establishment or its relocation from a third country to the EEA” whilst proceedings are ongoing ”will allow the controller to benefit from the one-stop-shop, with the consequence that every pending proceeding will be transferred to the supervisory authority of the State in which the main establishment is located” and that “such supervisory authority will become the lead supervisory authority”.</p><p>The Data Protection Authority’s defence regarding the continued applicability of the one-stop-shop mechanism solely in relation to ongoing or continued infringements was found to lack a legal basis, stemming from an erroneous interpretation of paragraph 16 of the Opinion, which refers the issues addressed “mainly” to infringements of an ongoing or continued nature. The Court observed that the very use of the adverb “mainly” serves to rule out the possibility that the EDPB intended to limit the issues covered by the Opinion solely to ongoing infringements; rather, it sought to indicate the types of infringements in which such issues arise <i>most frequently</i>.</p><p>The underlying principle is even more significant: making the determination of the competent authority dependent on the nature of the alleged infringement would not only cause the uncertainty that the EU legislation aims to avoid, but also a reversal of the logical legal order in which issues are examined, making the resolution of a preliminary question such as jurisdiction dependent on the outcome of the examination of a question of substance.</p><p><strong>The </strong><i><strong>“tempus regit actum” </strong></i><strong>argument — rejected</strong></p><p>The Data Protection Authority also invoked the legal principle of <i>“tempus regit actum” </i>to argue that the applicable legislation was that in force at the time the infringements were committed. The Court considered this argument to be irrelevant: in the present case, what is at issue is not a change in the applicable legislation during the course of the proceedings, but rather the change in certain factual circumstances — the creation of a single establishment by the data controller within the territory of the Union — the consequences of which are taken into account and governed by the EDPB Opinion. It is not, therefore, a matter of the retroactive application of the law, but of adapting jurisdiction to supervening facts, as already provided for and regulated by European law.</p><h2>&nbsp;</h2><p><strong>The exceptions that did not apply</strong></p><p>The Court also examined whether any of the exceptional circumstances applied in which jurisdiction reverts to the national authority concerned. In this regard, Article 56(2) of the GDPR — according to which each supervisory authority is competent to handle complaints that relate solely to an establishment in its Member State or that have a substantial impact on data subjects solely within its Member State — and Article 66, which, by way of derogation from Article 60, grants each supervisory authority the power to adopt provisional measures where it considers that urgent action is required to protect the rights and freedoms of data subjects. In addition to these cases, there is the case where the lead supervisory authority, although seised of the matter, decides not to handle the case (see, to that effect, CJEU, C-645/19, <i>Facebook Ireland and Others</i>). However, none of these exceptional circumstances was found to exist in the present case.</p><p><strong>The case law of the Court of Cassation</strong></p><p>The Supreme Court had already clarified that <i>“the national data protection authority is entitled to impose sanctions where it appears that the processing was carried out by an Italian company with full and direct decision-making autonomy with regard to personal data</i>” (order, First Division, No. 27189 of 22 September 2023) and that <i>“the Italian Data Protection Authority has the power to issue the measures falling within its remit against a foreign entity, even if it is established outside the Union, which operates outside the national territory, provided that it carries out, through a permanent establishment on Italian territory, an actual and genuine activity in the context of which the processing takes place”</i> (judgement of First Division, No. 3952 of 2022). In both rulings, the prerequisite for recognising the Italian Data Protection Authority’s power to impose sanctions is identified as the presence on Italian territory of a company or a permanent establishment: circumstances which do not exist in the present case.</p><p>The Court’s decision therefore forms part of a consistent line of case law.</p><p><strong>The data point worth more than a thousand arguments</strong></p><p>Other supervisory authorities, although “concerned” at the time proceedings were initiated in relation to the same infringements committed by the applicant company, subsequently declined to exercise their jurisdiction in favour of the Irish supervisory authority, which was deemed to be the lead authority from 15 February 2024, and forwarded all the investigative files to it. The Italian Data Protection Authority was left on its own. The Court held that it was in the wrong — whilst acknowledging, in the allocation of legal costs, the genuine novelty and complexity of the issues addressed.</p><p><strong>The operative part</strong></p><p>The creation of the data controller’s single establishment pending the administrative proceedings — even though these had been lawfully initiated in January 2024 — should have</p><p class="text-justify">immediately resulted in its transfer to the supervisory authority of the State in which the main establishment is located — in this case, the Irish authority — and the initiation of the cooperation mechanism set out in Articles 60 and 61 of the Regulation. In upholding the appeal, the Court annulled order No. 755 of the Data Protection Authority dated 2 November 2024. The costs of the proceedings have been shared between the parties, given the novelty of the issues involved.</p><p><strong>The merits of the case remain open — and this is what matters</strong></p><p>The judgement does not amount to a ruling on the merits. The infringements originally alleged by the Italian Data Protection Authority — legal basis for training the models, transparency, age verification, data breach and failure to implement previously-imposed corrective measures — remain intact and will presumably be addressed by the Irish DPC under the cooperative mechanism set out in Articles 60 and 61 of the GDPR. The case file is not extinguished; it merely changes hands.</p><p><strong>Implications: a lesson that extends far beyond OpenAI</strong></p><p>The ruling by the Court of Rome has implications that extend far beyond the parties to the case. The legal issues identified — legal basis for training AI models, transparency obligations towards users, age verification, and the handling of data breaches — are structural issues affecting any provider of artificial intelligence systems offering their services to European users, regardless of what emerges from the new Digital Omnibus legislative and regulatory framework.</p><p>For non-EU AI providers currently operating on the European market without a formally recognised establishment, the picture that emerges from the judgement is clear:</p><ul><li data-list-item-id="e5655929772a668a47226033c34bbaaa0"><span><strong>Until there is a recognised EU establishment</strong>, any national supervisory authority is potentially competent, and there is a real risk of parallel and fragmented proceedings.</span></li><li data-list-item-id="e1e91c7ce1ae125ae0cb55a6a9853a4c6"><span><strong>Once the establishment has been formally recognised</strong>, the one-stop-shop mechanism is triggered — even if proceedings are already underway — and the case file must be transferred to the lead authority, unless a final decision has already been taken.</span></li><li data-list-item-id="ef8e5bd96b0cd02edd9cc29a5d4762b29"><span><strong>The objective criterion is temporal</strong>, not substantive: what matters is not the nature of the infringement (whether a one-off or ongoing breach), but whether or not a final decision had already been issued at the time the establishment was recognised. EDPB Opinion No 8/2019 identifies this moment as the point at which jurisdiction is “crystallised”.</span></li><li data-list-item-id="e431f3d3c24f5a857a7d055cfdeb70f52"><span><strong>Exceptions do exist, but they are exceptional</strong>: local jurisdiction remains only for infringements affecting data subjects in that Member State </span><i><span>exclusively</span></i><span>, or for urgent measures under Article 66 of the GDPR. It is not a standard recourse.</span></li></ul><p>For AI system providers with an established presence in Europe, however, the ruling serves as a reminder that the choice of country of establishment — and the speed with which formal recognition is obtained from the local regulatory authority — is a decision with regulatory implications of the utmost importance: not a corporate detail, but a strategic lever for risk management.</p><p>In conclusion: whilst the Court of Rome has (for now) brought the Italian chapter of the OpenAI case to a close, the issues that fuelled the preliminary investigation remain unresolved and highly topical. Anyone who develops or distributes artificial intelligence systems aimed at the European market — from any country in the world — will sooner or later have to grapple with them.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/8/4/csm_AdobeStock_1185159049_779f018b39.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10458</guid>
                        <pubDate>Wed, 17 Jun 2026 14:20:55 +0200</pubDate>
                        <title>Cyber Resilience Act: the countdown has started</title>
                        <link>https://www.advant-nctm.com/en/news/cyber-resilience-act-il-conto-alla-rovescia-e-iniziato</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>With Regulation (EU) 2024/2847 (“<i><strong>Cyber Resilience Act</strong></i>” or “<i><strong>CRA</strong></i>”), the European Union is introducing a set of common rules aimed at strengthening the cybersecurity of digital products placed on the European market.</p><p>Software, hardware, connected devices and, more generally, products containing digital elements must be designed, developed and maintained with cybersecurity in mind throughout their entire lifecycle.</p><p>The Cyber Resilience Act came into force on 10 December 2024, but its effects will begin to be felt in the coming months.</p><p class="text-justify">Indeed, the CRA will be implemented gradually, with some provisions coming into force as early as 2026, while the regulatory framework will be fully applicable from 11 December 2027.</p><p>The first deadlines have already been set: from 11 June 2026, the rules relating to conformity assessment bodies will apply; from 11 September 2026, manufacturers will be required to report any actively exploited vulnerabilities or serious incidents affecting product security.</p><p class="text-justify"><strong>Who is affected and which products containing digital components are covered?</strong></p><p>The provisions of the Cyber Resilience Act are primarily addressed to manufacturers of products containing digital components, but they also apply to other economic operators in the supply chain, including importers, distributors, authorised representatives and, where applicable, open-source software maintainers. In some cases, the manufacturer’s obligations may also fall on importers or distributors, for example when they market a product under their own name or brand or substantially modify the product.</p><p>With regard to its material scope, the Cyber Resilience Act applies to products with digital elements made available on the European Union market. Broadly speaking, these are software or hardware products, including related remote data processing solutions, where their intended purpose or reasonably foreseeable use involves a direct or indirect, logical or physical data connection to a device or network.</p><p>The Cyber Resilience Act therefore covers, by way of example, IoT devices, routers, operating systems, applications, management software, hardware and software components, smart home products, wearable devices and, more generally, digital or connected products intended for distribution or use in the European market.</p><p>However, certain exclusions apply, for example, to products already regulated by specific sectoral legislation, to products developed exclusively for national security or defence purposes, and to certain cases relating to free and open-source software not supplied as part of a commercial activity.</p><p>The practical application of the Cyber Resilience Act therefore requires a case-by-case assessment, taking into account both the product and its distribution model, as well as the role played by the economic operator.</p><p><strong>Key obligations</strong></p><p>The Cyber Resilience Act requires manufacturers to integrate cybersecurity throughout the entire lifecycle of products containing digital elements. Such products must therefore be designed, developed, manufactured and maintained in such a way as to ensure a level of security appropriate to the risks.</p><p>Before placing the product on the market, the manufacturer must carry out an assessment of the cybersecurity risks of the product and take them into account at all relevant stages, from design to development, from production to delivery, right through to maintenance. The product must also comply with specific security requirements, including the reduction of exploitable vulnerabilities, secure-by-default configuration, protection against unauthorised access, safeguarding the confidentiality, integrity and availability of data, as well as the ability to receive security updates.</p><p>The manufacturer will also be required to prepare the technical documentation, carry out the applicable conformity assessment procedure, draw up the EU declaration of conformity and affix the CE marking. For many products, self-assessment may be sufficient, while for those considered important or critical from a cybersecurity perspective, more rigorous procedures may be required, including the involvement of notified bodies.</p><p>The manufacturer’s obligations do not end with the placing of the product on the market. The CRA requires the adoption of appropriate processes to identify, correct and document vulnerabilities even in the post-market phase.</p><p>From 11 September 2026, manufacturers will also be required to notify actively exploited vulnerabilities affecting the product and serious incidents affecting its security. For actively exploited vulnerabilities, an initial report must be made within 24 hours of the manufacturer becoming aware of them, followed by a formal notification within 72 hours and a final report. Similar obligations apply to serious incidents, in accordance with specific timeframes for reporting and the final report.</p><p>Importers and distributors are also subject to specific obligations. Before placing a product on the market or making it available, they must verify that the manufacturer has complied with the required obligations and that the product is accompanied by the required documentation and bears the CE marking. If they have reason to believe that a product does not comply or poses a cybersecurity risk, they must not place it, or make it available, on the market.</p><h2>&nbsp;</h2><p><strong>What to do now</strong></p><p>In light of the deadlines set out in the Cyber Resilience Act, it is essential to begin an assessment of products, internal processes and relationships with suppliers and business partners in good time.</p><p>Preparing in advance will therefore be essential to identify any compliance gaps and approach the upcoming deadlines with greater awareness.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/b/8/csm_ADV_II_Manufacturing-Industry-1_copy_45519edffe.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10457</guid>
                        <pubDate>Wed, 17 Jun 2026 14:18:27 +0200</pubDate>
                        <title>AI: Council of Ministers gives preliminary approval to two draft legislative decrees implementing law no. 132/2025</title>
                        <link>https://www.advant-nctm.com/en/news/ai-il-cdm-approva-in-via-preliminare-i-decreti-attuativi-della-legge-n-132-2025</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>Overview</strong></p><p>On 10 June 2026, exercising the powers delegated under Law No. 132/2025 (the&nbsp;Italian Law&nbsp;on Artificial Intelligence), the Council of Ministers granted preliminary approval to two draft legislative decrees concerning artificial intelligence, which are still subject to amendment. The first decree addresses the powers of national authorities, market surveillance, sanctions, regulatory sandboxes, training and employment-related provisions (the “<strong>Decree</strong>”). The second&nbsp;decree regulates the use of AI systems in policing activities and introduces provisions on civil and criminal liability. This briefing focuses on the first draft decree.</p><p><strong>Governance takes shape: authorities, coordination and regulatory sandbox</strong></p><p>The Agency for Digital Italy (AgID) is the national notifying authority, with responsibility for notification procedures and conformity assessment bodies. The National Cybersecurity Agency (ACN) is responsible for market surveillance and acts as the single point of contact. ACN is also responsible for the national registration of high-risk AI systems listed in Annex III, point 2,&nbsp;of the AI Act.</p><p class="text-justify">The role of sectoral authorities remains unchanged: the Decree identifies the Bank of Italy, CONSOB and IVASS as the competent authorities within their respective fields, in addition to the Italian Data Protection Authority insofar as matters fall within its remit.</p><p class="text-justify">The Decree also establishes a Coordination Committee within the Presidency of the Council of Ministers, to ensure coordination and cooperation among national authorities, other&nbsp;public administrations and independent authorities. The Committee may issue common guidelines for the conclusion of agreements and memoranda of understanding, as well as for the adoption of policy documents.</p><p class="text-justify">The Decree also establishes the Italian AI Regulatory Sandbox — the regulatory sandbox provided for in Article 57 of the AI Act — which will be jointly managed by AgID and ACN.</p><p><strong>Sanctions: a graduated enforcement framework</strong></p><p>In accordance with the AI Act, the most serious infringements, relating to the prohibited practices set out in Article 5 of the AI Act, may result in fines of up to 35 million euros or, if higher, up to 7% of the undertaking’s&nbsp;total annual global turnover for the previous financial year. Lower maximum fines apply for other categories of infringements, including those imposed on providers and deployers in relation to high-risk AI systems, those applicable to notified bodies, and those concerning transparency and reporting to the authorities.</p><p>The Decree also provides for non-monetary penalties for less serious infringements. As an alternative to financial penalties, the authorities may order that the infringement be remedied or require the publication of a statement setting out the infringement and identifying the responsible party. Sanctioning proceedings in the financial sector remain subject to the sector-specific procedures applied by the Bank of Italy, CONSOB and IVASS under the Italian Banking Act (TUB), the Consolidated Financial Act (TUF) and the Insurance Code, in accordance with the special regime applicable to financial institutions.&nbsp;</p><p><strong>Employment: the final decision must remain human</strong></p><p>The Decree stipulates that, in employment-related decision-making processes, employers using AI systems must ensure that decisions concerning the establishment, modification or termination of the employment relationship, including disciplinary measures, are not taken solely on the basis of automated processing. The final decision must remain with a natural person exercising genuine and independent judgment.</p><p>Upon request, the worker is entitled to receive, through human intervention, a clear and understandable explanation of the decision, including how the AI system influenced the decision-making process and the main parameters taken into account. Any dismissal carried out in breach of these provisions is null and void. This provides stronger protection than&nbsp;that currently available under Italian employment law: it will not be sufficient to state that “the final decision is made by a human” if, in practice, the AI system’s output substantially determines it.</p><p>The Decree also establishes an explicit link between AI and occupational health and safety: the use of AI systems affecting work organisation, production rates, the way in which work is carried out, or safety-related decision-making processes must be taken into account in the workplace risk assessment (Documento di Valutazione dei Rischi – DVR) pursuant to Legislative Decree No. 81/2008.</p><p><strong>Training: a cross-cutting obligation</strong></p><p>The Decree devotes a substantial section to training, introducing measures for schools, teachers, adults, the public administration, universities, research institutions, regulated professions, the judiciary and the health sector. A total of €100 million has been allocated for teacher training under the national programme “PN Scuola e Competenze 2021–202”.</p><p>For regulated professions, the Decree introduces obligations to ensure technical, legal and ethical competence in AI: professional bodies will have six months to update their&nbsp;regulations and twelve months to revise their fair remuneration criteria to reflect the&nbsp;risk classification of the AI system used. In the healthcare sector, AI will become part of the Continuing Medical Education (Educazione Continua in Medicina - ECM) programme, with the involvement of healthcare managers and the national “MIA” platform.</p><p><strong>What to do now</strong></p><p>The texts are not yet final, but there are two operational priorities.</p><p>First, an initial review of the AI systems currently in use — distinguishing between prohibited practices, high-risk systems, systems subject to transparency obligations and low-risk systems — to prioritise compliance activities and to prepare of the required technical documentation: logs, risk assessments, human supervision, change logs and governance decisions.</p><p>The second priority concerns HR processes that make use of AI systems. The Decree prohibits decisions relating to the establishment, modification or termination of an employment relationship (including disciplinary measures) from being taken solely on the basis of automated processing, and provides that any dismissal carried out in breach of these requirements is null and void. In practice, this requires a review of decision-making processes relating to staff selection, performance management, job assignments and disciplinary measures, ensuring that meaningful human oversight is in place and properly documented, rather than merely formal. Particular attention should be paid to candidate ranking and scoring systems, productivity monitoring tools, and software used for automated shift scheduling or workload allocation, where their outputs have a decisive influence on management decisions. From a contractual perspective, it will also be advisable to review the clauses in contracts with the AI system providers, in terms of algorithm transparency, access to logs and the allocation of liability in the event of a dispute.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/4/b/csm_AdobeStock_66590766_ac6999c962.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10456</guid>
                        <pubDate>Wed, 17 Jun 2026 14:12:27 +0200</pubDate>
                        <title>Minors online: what businesses need to know</title>
                        <link>https://www.advant-nctm.com/en/news/minori-online-cosa-le-imprese-devono-sapere</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>For minors, the internet is home. It is where they find information, study, communicate and build a significant part of their social lives.</p><p>But it is not always a safe place. It amplifies hate speech and disinformation, facilitates practices such as cyberbullying and the non-consensual sharing of sexual or explicit content, and can foster patterns of isolation or addiction. Artificial intelligence further exacerbates these risks: it enables the creation of deepfakes and AI-generated images without the consent of the person depicted; it allows the deployment of chatbots capable of influencing minors’ choices and behaviour; and it makes it possible to tailor content to the specific cognitive vulnerabilities of individual users.</p><p>There is now widespread consensus on the need to protect minors online. How effective protection can be achieved, however, is far less clear.</p><p>In Italy, as in the rest of Europe, the regulatory framework is fragmented and rapidly evolving, and many of the key issues remain unresolved.</p><p><strong>The regulatory framework</strong></p><p>Italy has no comprehensive regulatory framework specifically addressing minors in the digital environment.</p><p>The legal framework is made up of various legislative instruments operating at different but complementary levels and often requiring a holistic interpretation.</p><p>The main legislative instruments currently relevant are:</p><ul><li style="margin-left:7px;" data-list-item-id="eb9de2c84b39ef33b973298fc4d9e51c8"><span>Regulation (EU) 2016/679 (“</span><i><span><strong>GDPR</strong>”</span></i><span>) and Legislative Decree No. 196/2003 (</span><i><span>“<strong>Italian Privacy Code</strong>”</span></i><span>), applicable to data controllers processing the personal data of minors;</span></li><li style="margin-left:7px;" data-list-item-id="ec85d3c2d115fef857f2614d0a64a131c"><span>Regulation (EU) 2022/2065 (“</span><i><span><strong>Digital Services Act</strong></span></i><span>” or “</span><i><span><strong>DSA</strong></span></i><span>”), the European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA, and Commission Recommendation (EU) 2026/1035 on establishing a common framework for EU-wide age verification technologies, applicable to providers of intermediary services;</span></li><li style="margin-left:7px;" data-list-item-id="ed2cf510ed57f297b6313245cf1b93fc5"><span>Directive 2010/13/EU, as amended by Directive (EU) 2018/1808 (“</span><i><span><strong>Audiovisual Media Services Directive</strong></span></i><span>” or “</span><i><span><strong>AVMS Directive</strong></span></i><span>”), transposed in Italy by Legislative Decree No. 208/2021 (</span><i><span>“<strong>Consolidated Act on Audiovisual Media Services</strong>”&nbsp;</span></i><span>or </span><i><span>“<strong>TUSMA</strong>”</span></i><span>), applicable to video-sharing platform providers;</span></li><li data-list-item-id="eb575d147ef22b32e989b4c5a7fa4c582"><p class="text-justify"><span>Decree-Law No. 123/2023, converted into Law No. 159/2023 (</span><i><span>“<strong>Caivano&nbsp;Decree</strong></span></i><span>”) and AGCOM (Italian Communications Authority) Resolution No. 96/25/CONS, applicable to providers distributing pornographic content but increasingly serving as a technical benchmark for age verification; and</span></p></li><li data-list-item-id="ef2c5a3fa8fbec31e5156e272a04c5bcd"><span>Law No. 132/2025 (</span><i><span>“<strong>Italian Artificial Intelligence&nbsp;Act</strong></span></i><span>”), which includes a provision specifically addressing minors’ use of artificial intelligence systems.</span></li></ul><p>In addition to the legislative instruments outlined above, two further initiatives deserve mention: the G7 Common Principles for a Safer and More Secure Digital Space for Minors, adopted by the G7 Digital and Technology Ministers in 2026, which establish a shared framework covering age verification, safety by design, protection from illegal content, parental control tools, digital literacy and risk management, and Bill No. 1136 (<i>“<strong>Bill 1136</strong></i>”), currently under consideration by the Italian Parliament, which introduces specific provisions governing minors’ access to social media and video-sharing platforms, as well as age verification and digital consent.</p><p><strong>Three key issues</strong></p><p>Beyond the existing legal framework, three issues currently lie at the heart of the political and regulatory debate at both national and European level.</p><p><strong>The ban on access to social media</strong></p><p>One of the issues currently dominating the debate on the protection of minors online concerns the introduction of a minimum age for accessing social media.</p><p>In 2024, Australia introduced a ban on under-16s; France, Denmark and Spain are considering similar measures; in Italy, Bill 1136 proposes to prohibit minors under the age of 15 from opening accounts on social media (as well as on video-sharing platforms).</p><p>These measures address genuine concerns. The risk, however, is that attention is focused exclusively on the age threshold for access, while neglecting the characteristics of the services once minors are granted access. A comparison with more mature regulatory models is instructive. The UK’s Age-Appropriate Design Code and the California Age-Appropriate Design Code Act do not merely set age limits, but impose requirements relating to responsible design, risk assessment and provider accountability. From this perspective, the protection of minors depends not only on who can access the service, but also on how the service is designed.</p><p><strong>The digital age of consent&nbsp;</strong></p><p>Closely linked to the issue of minors’ access to social media is that of minors’ consent to the processing of their personal data.</p><p>Article 8 of the GDPR sets the age at which a minor may validly consent at 16, while allowing Member States the option to set lower thresholds, which in any case must not be below 13. Italy has exercised this option, setting the age for a minor’s consent at 14.</p><p>If approved in its current form, however, Bill 1136 would raise the age of consent for minors to 16.</p><p>The issue is further complicated by the fact that age thresholds are not uniform even within the same legal system. The Italian Artificial Intelligence Act, for example, allows minors to access and use AI systems independently from the age of 14 onwards. Accordingly, an operator managing a service with social components and AI-based features may find itself applying different rules to the same user base.</p><p><strong>Service design and the functioning of algorithms</strong></p><p>The third aspect of the debate — and probably the most sensitive — concerns the design of digital services and the functioning of algorithmic systems.</p><p>From this perspective, the regulatory debate is gradually shifting from content control to accountability for design choices that encourage compulsive use of services. These include infinite scroll, notifications deliberately designed to capture users’ attention, recommender systems optimised to maximise time spent on the platform, autoplay features, and intermittent reward mechanisms. The European Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA expressly classify these techniques as incompatible with a high level of protection for minors. This is the principle of “safety by design”, which requires minors’ protection to be integrated from the service development stage, rather than addressed <i>ex post</i> on individual pieces of content.</p><p>The scope of these obligations varies, however, depending on the type of service provided. Transparency obligations relating to recommender systems and the ban on profiling-based advertising apply to all online platform providers. The obligations to assess and mitigate systemic risks, on the other hand, are more stringent for very large online platforms (“<strong>VLOPs</strong>”) and very large online search engines (“<strong>VLOSEs</strong>”), which are required to carry out periodic risk assessments and adopt mitigation measures&nbsp;that are reasonable, proportionate and effective.</p><p><strong>Age verification</strong></p><p>Setting a minimum age for access to social media and for digital consent&nbsp;risks remaining a dead letter unless supported by truly reliable age verification mechanisms.</p><p>From this perspective, Commission Recommendation (EU) 2026/1035 establishes a common framework for age verification technologies, based on an interoperable, privacy-respecting model utilising digital identities and advanced cryptographic protocols. The system — developed by the European Commission as an open-source solution and already being trialled in some Member States, including Italy — is based on zero-knowledge proofs: the user downloads an app, verifies their age using an electronic ID or a pre-installed banking app, and receives a digital credential that can be submitted to online platforms. The aim is to enable verification that a specific age threshold has been met without disclosing additional information about the user’s identity: the platform receives only a true/false response (e.g., “over 18: yes”), without access to the user’s name, date of birth or other personal data. Once certification is complete, the link between the user and the certificate provider is severed, preventing any tracking of online activities. In Italy, Bill 1136 provides for a verification system based on a national digital mini-wallet, which constitutes a national implementation of the European solution: not an alternative or parallel system, but a tailored application of the same technical blueprint made available by the Commission as open source, consistent with the requirements of the Recommendation and the implementation timetable set out therein.</p><p><strong>Obligations for businesses</strong></p><p>Against this background, while these issues remain unresolved and the regulatory framework continues to evolve, what should businesses providing information society services intended for, or otherwise accessible to, minors do?</p><p>The answer depends on the nature of the service provided, as well as on the size of the business.</p><p>Providers of online platforms (including social media providers and video-sharing platform providers) must not only comply with the ban on advertising based on the online profiling of minors, but also design their platforms so as to ensure an effective level of protection for minors. This entails, among other things, the adoption of protective default settings, configuring recommender systems that do not maximise user attention and engagement, eliminating features that encourage compulsive behaviour, and providing parental control tools. Furthermore, VLOPs and VLOSEs must identify, analyse and assess the systemic risks their services may pose to minors and adopt reasonable, proportionate and effective mitigation measures, which may include adjusting algorithmic systems, the introduction of age verification tools and specific content moderation measures.</p><p>It is important to note that merely stating in the terms and conditions that a platform is intended for adults does not exempt providers from these obligations. Where effective measures are not implemented to prevent access by minors, the service is deemed to be accessible to minors.</p><p class="text-justify">In addition to the obligations applicable to all online platform providers, providers of video-sharing platforms subject to Italian jurisdiction are also required, under TUSMA, to implement age verification systems for content that may impair the physical, mental or moral development of minors, as well as parental control tools. Providers of video-sharing platforms (and website operators) distributing pornographic content in Italy are also subject to a ban on access by under-18s to the pornographic content distributed, and are required to verify users’ age, in accordance with the procedures laid down by AGCOM.</p><p>Furthermore, should Bill 1136 be enacted, social media providers and video-sharing platform providers would be subject to two additional obligations.</p><p>The first concerns the prohibition on the creation of accounts for minors under the age of 15, rendering void any contracts already concluded with minors who have not yet reached that age at the time&nbsp;</p><p>the law enters into force. The second is the obligation to verify users’ ages via a national digital mini-wallet implementing the European age verification solution, again in accordance with procedures laid down by AGCOM.</p><p>And what about those providers of information society services other than online platforms (such as e-commerce services) or entities that process personal data of minors? For these entities, there is currently no explicit obligation to verify age. Data protection law requires appropriate measures to ensure that a minor’s consent is valid, but it does not prescribe a specific age verification system nor define the technical means by which such verification must be carried out. In the absence of an express statutory obligation, however, it is advisable to carry out a risk assessment — similar in principle to that required under the Commission’s Guidelines for online platform providers — to determine whether, having regard to the nature of the service, the categories of personal data processed and the reasonably foreseeable presence of minors among users, age verification mechanisms compliant with the European technical solution or equivalent standards should be implemented.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/4/1/csm_ADV_Education_1_08a812c0b7.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10422</guid>
                        <pubDate>Thu, 11 Jun 2026 09:24:30 +0200</pubDate>
                        <title>AI-generated content: the European Commission publishes the Code of Conduct on labelling</title>
                        <link>https://www.advant-nctm.com/en/news/contenuti-generati-dallia-la-commissione-europea-pubblica-il-codice-di-condotta-per-letichettatura</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The context: transparency as a pillar of the AI Act</strong></p><p>Yesterday, the European Commission published the final version of the Code of Conduct on the marking and labelling of AI-generated content, a strategic tool within the European regulatory framework for AI. The Code represents the operational response to the transparency obligations set out in Article 50 of the AI Act, which will come into force on 2 August 2026.</p><p>The AI Act, moreover, has identified transparency as one of the most urgent systemic risks to be addressed. When machine-generated content is indistinguishable from human-generated content — journalistic texts, deepfake videos, synthetic voices — it creates fertile ground for disinformation, the manipulation of public opinion and a loss of trust in the information ecosystem. Consider, for example, an apparently authentic video of a political leader circulated during an election campaign, a voice recording used to impersonate a company executive and authorise a bank transfer, or images of events that never took place circulating on social media during crisis situations. In all these cases, the ability to identify the artificial origin of the content plays an essential role in preserving user trust.</p><p>The Code of Conduct is the practical tool through which the Commission seeks to translate these regulatory principles into concrete actions.</p><p><strong>What the Code provides for: obligations and target audience</strong></p><p>The Code is voluntary in nature, but carries significant legal weight: companies that sign up to it will be able to rely on shared standards to more easily demonstrate compliance with the obligations set out in the AI Act in the areas covered by the Code itself. This mechanism makes it particularly attractive to industry.</p><p>There are two target groups.</p><p><strong>Providers</strong>, i.e. those who develop (generative) AI systems. They are under an obligation to ensure that the content produced (audio, images, video, text) is marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions adopted must be effective, interoperable, robust and reliable, in line with the state of the art and implementation costs.</p><p><strong>Deployers</strong>, i.e. those who make generative AI systems available to end users. They are subject to disclosure obligations in two specific cases:</p><ul><li data-list-item-id="ed62ea707045d48fae0a1f6f150109240"><span><strong>Deepfakes</strong>: audio, image or video content depicting real people, objects, places or events in such a way as to appear authentic, but which is not. In practical terms, this category would include a video showing a person making statements they have never actually made.</span></li><li data-list-item-id="ee57571b45397ec1174c0a9955be7281b"><span><strong>Texts of public interest</strong>: articles, press releases or publications generated by AI on matters of public relevance, unless they have undergone a process of human review with editorial responsibility. The most obvious example is an article generated by an AI system commenting on election results, health measures or government decisions. Conversely, a text that has undergone substantial human review and been published under the editorial responsibility of a journalist or editorial team could benefit from the exception provided for in the AI Act.</span></li></ul><p>There is also a requirement to inform users when they interact with an interactive AI system, such as a chatbot or a virtual assistant.</p><p><strong>The process: how the Code was developed</strong></p><p>The Code is the result of a participatory process launched in September 2025 by the AI Office, involving a public consultation and a call for expressions of interest. The process involved two thematic working groups (one for providers and one for deployers), led by independent chairs and vice-chairs, and included a wide range of stakeholders: developers of detection technologies, trade associations, civil society organisations, academics and major online platforms.</p><p>Over seven months — from November 2025 to June 2026 — three interim drafts were produced and put out for consultation before the final version was finalised. In parallel, the Commission published interpretative guidelines to clarify the scope of regulatory obligations and cover aspects not addressed by the Code.</p><p><strong>Practical implications: what changes for businesses and users</strong></p><p>For technology companies, signing up to the Code means adopting technical standards for content labelling and traceability, such as digital watermarking, signed metadata and provenance standards such as C2PA, as well as implementing appropriate disclosure systems for end users.</p><p>For example, an image generated by an AI model could contain metadata that allows platforms and verification tools to automatically identify its artificial origin, even if the label visible to the user has been removed.</p><p>Companies that do not sign up will still have to comply with the obligations of the AI Act from 2 August 2026, but without the benefit of being able to refer to the shared standards identified by the Code.</p><p>For the public, the expected impact is significant: deepfakes and AI-generated texts on matters of public interest will have to be clearly identified, making it easier to recognise when one is dealing with synthetic content.</p><p>The question of technical feasibility remains open. Watermarks and metadata can be removed or altered, and the detection of synthetic content in distributed environments still poses a significant technological challenge. The Code itself acknowledges this limitation, requiring the adoption of ‘technically feasible’ solutions in light of the state of the art.</p><p><strong>Outlook: a model for the rest of the world?</strong></p><p>The European initiative comes at a time of intense global regulatory competition over artificial intelligence. Whilst the United States is proceeding with a more fragmented approach and China has adopted specific rules on synthetic content, the European Union aims to build a model based on transparency and the accountability of operators.</p><p>A scenario that is far from unlikely is one in which a global platform chooses to apply European labelling standards to all users, rather than developing different systems for each national market. This is a phenomenon already observed in the past with European data protection legislation.</p><p>The challenge will be to maintain a balance between transparency and innovation, ensuring that excessive compliance burdens do not put European businesses at a disadvantage compared to their global competitors. The Code of Conduct on represents a significant attempt to strike this balance, with August 2026 serving as the first real-world test.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Intellectual Property</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10349</guid>
                        <pubDate>Thu, 28 May 2026 14:02:26 +0200</pubDate>
                        <title>Trade Secrets and the Digital Omnibus: Protecting Know-How While Data Circulates by Operation of Law</title>
                        <link>https://www.advant-nctm.com/en/news/trade-secrets-e-digital-omnibus-proteggere-il-know-how-mentre-i-dati-circolano-per-obbligo-di-legge</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><strong>The issue, in brief</strong></p><p>The Digital Omnibus — the legislative package through which Brussels is streamlining the EU’s digital rules — has been moving in the same direction for years: more sharing, more portability, fewer silos. A legitimate objective, but one with a side effect that many companies have not yet fully grasped: every data-sharing obligation creates an additional window through which know-how that has not been — or cannot be — patented may escape.</p><p>The package includes two main texts: one amending existing rules on data, cybersecurity, and privacy (the “digital acquis”), still under negotiation; and another concerning artificial intelligence, for which a provisional political agreement was reached on 7 May 2026. The dates of official publication remain subject to completion of the formal process.</p><p><strong>What changes in practice</strong></p><p>The most relevant amendments to the digital acquis for those handling sensitive information include:</p><p>– <strong>Public data and large operators.</strong> Public administrations may impose special conditions on Very Large Enterprises and DMA gatekeepers reusing public-sector data, in order to prevent privileged access to data from reinforcing already dominant positions.</p><p>– <strong>Data intermediaries.</strong> The mandatory regime under the Data Governance Act would become voluntary, with lighter separation requirements. More actors in the chain means more points of contact.</p><p>– <strong>Cloud switching.</strong> Simplified regimes for certain categories, but with explicit safeguards regarding trade secrets and risks of exposure to third-country jurisdictions.</p><p>– <strong>Smart contracts for data sharing.</strong> The essential requirements under Article 36 of the Data Act would be removed: fewer technical constraints, greater reliance on contractual governance.</p><p><strong>The starting point: the Data Act</strong></p><p>Already applicable since 12 September 2025, the Data Act grants users of connected devices the right to have their data shared with third parties. For manufacturers, this exposes a delicate perimeter: the data may contain operational logic, configuration parameters, performance information — everything that makes up know-how without ever having been labelled as such. Moreover, the Data Act disapplies the sui generis protection of databases in this context, shifting the burden of protection onto trade secrets.</p><p>Consider a practical example. A manufacturer of connected industrial equipment receives a request from a customer to share 18 months of operational logs with an independent maintenance provider that directly competes with its after-sales service. Those logs contain calibration parameters and control sequences developed over years of R&amp;D and never patented. The Data Act does not allow for a blanket refusal, but it does permit the manufacturer to require proportionate technical measures before sharing the data (Article 4(6)): NDAs with anti-reverse-engineering clauses, sensitive data disclosed only in aggregated form, and contractual prohibitions on using the data to develop competing services (Article 6(2)(e)). If the third party refuses those measures, the manufacturer may block the sharing, but must provide written reasons and notify the competent authority. These two steps are not optional: they are the formal conditions for a lawful refusal.</p><p>The Regulation also provides for the possibility of refusing disclosure where sharing would make serious economic harm highly likely. The threshold is high, and the practical problem is that the harm must be demonstrated before the disclosure occurs, based on data that has not yet left the company. Those who have not documented the value of their trade secrets will find themselves without arguments when they are most needed.</p><p><strong>The Digital Omnibus novelty: the jurisdictional factor</strong></p><p>If approved in its proposed form, the amendment to the Data Act would introduce a new basis for refusing disclosure: the risk of unlawful acquisition by entities operating in third countries with insufficient safeguards — or with formally equivalent safeguards lacking effective enforcement.</p><p>This represents a concrete shift in perspective. Today, many leaks do not originate from cyberattacks or disloyal employees: they arise because data lawfully shared reaches a legitimate recipient operating in a jurisdiction where a local authority may require disclosure — and where obtaining an injunction is slow or impossible. The secret is lost because of a structural systemic issue, not because of malicious intent. The proposal seeks to turn this asymmetry into a legal lever: refusal is legitimate, but it must be justified in writing and notified to the competent authority.</p><p><strong>Five things to do now</strong></p><p>– <strong>Map data from a competitive standpoint.</strong> Not for GDPR purposes: which datasets, if analysed, reveal proprietary processes or logic? Which fall within the scope of the Data Act?</p><p>– <strong>Build a trade secret registry.</strong> A trade secret exists if it is not generally known, has economic value because it is secret, and is protected through reasonable measures. NDAs, access controls, audit logs, internal policies: everything documented and updated.</p><p>– <strong>Structure responses to data-sharing requests.</strong> What is needed is a process, not a case-by-case assessment. Clear criteria are required regarding when to refuse disclosure, how to justify the refusal, and how to notify it.</p><p>– <strong>Conduct a jurisdictional assessment of data flows.</strong> Who receives the data? Where do they operate? Where are their subcontractors located? What is the actual level of enforcement in those jurisdictions?</p><p>– <strong>Monitor the legislative process.</strong> The Digital Omnibus for the digital acquis will evolve. Those working with sensitive data need to know how, and when.</p><p>The direction of the Digital Omnibus will not change: more circulation, more portability. But companies that have built their competitive advantage on data and unpatented processes cannot wait for the legislation to stabilise. The trade secret that survives is the one already structured as such before someone asks for it to be shared.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Intellectual Property</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10252</guid>
                        <pubDate>Fri, 24 Apr 2026 15:30:23 +0200</pubDate>
                        <title>What changes under the new ACN determination on categorisation?</title>
                        <link>https://www.advant-nctm.com/en/news/cosa-cambia-con-la-nuova-determinazione-acn-sulla-categorizzazione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><i>Practical guidance on the new NIS compliance requirements to be fulfilled by 30 June 2026.</i></p><p>Italy’s National Cybersecurity Agency (“ACN”) has today published Determination No. 155238/2026 (“the Determination”), which sets out the relevance categories, as well as the process, procedures and criteria for the listing, characterisation and categorisation of activities and services.&nbsp;</p><p>The Determination introduces two categorisation models, set out in its Annexes 1 and 2 respectively. Both are structured around ten macro-areas, each with a name, description and pre-assigned relevance category. The four relevance categories established by the Determination are: high impact, medium impact, low impact and minimal impact.&nbsp;</p><p>Essentially, the two annexes identify the same macro-areas, which differ only in the relevance category assigned to them.</p><p>As regards the scope of application, Annex 1 applies to (i) NIS entities operating in the following sectors: energy; transport; healthcare; drinking water; wastewater; space; postal and courier services; waste management; manufacturing, production and distribution of chemicals; production, processing and distribution of food; manufacturing; and (ii) entities providing local public transport services. Annex 2 applies to all other NIS entities not falling within those sectors.</p><p>In practice, the Determination requires NIS entities, through the ACN Portal, to list and categorise all internal and external activities and services and assign them to the relevant macro-areas of the model set out in the applicable annex. For each activity or service, entities must specify three elements: the corresponding macro-area, the name and description, and the relevance category.</p><p>The Determination also allows entities a degree of discretion. NIS entities may assign a specific activity or service to a different category from that pre-assigned to the macro-area, based on their assessment of the impact that a potential compromise could have on their ability to properly carry out NIS-related activities and services. In such case, the entity must retain the documentation supporting that assessment. By contrast, where the entity does not carry out activities or provide services attributable to one or more macro-areas, it is not required to report them.</p><p>The Determination also lays down two coordination provisions. The first concerns entities that have already classified data and services for the Public Administration in accordance with ACN Directorial Decree No. 21007/24: for such entities, that model continues to apply, rather than the model introduced by the Determination. The second concerns activities and services subject to the national cyber security framework, for which the relevance category is predetermined as “high impact”, without applying the standard procedure.</p><p>For matters not expressly governed by the Determination, the provisions of the NIS Decree shall apply. The Determination shall apply from 1 May 2026.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10245</guid>
                        <pubDate>Tue, 21 Apr 2026 17:02:27 +0200</pubDate>
                        <title>Consent or Pay and the Digital Omnibus: rethinking the relationship between fundamental rights and the DATA economy</title>
                        <link>https://www.advant-nctm.com/en/news/consent-or-pay-e-digital-omnibus-un-nuovo-rapporto-tra-diritti-fondamentali-ed-economia-dei-dati</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><i>The following is the text of a speech delivered by Giulio Uras at the panel discussion “Pay or Okay and data monetisation: where do we stand? Developments and prospects for data exploitation”, as part of the Privacy Symposium 2026.</i></p><p>As you know, a number of business models are based on Consent or Pay mechanisms – indeed, they depend on such mechanisms. This is particularly true of the online publishing sector: newspapers fund their journalism through advertising revenues.</p><p>You will also be familiar with the legal issue these models have raised for years: the requirement that consent be freely given.</p><p>According to supervisory authorities, consent is not freely given – and is therefore invalid – if the alternative offered to users, namely paying, effectively pushes them to consent. This approach is consistent with Article 7 of the GDPR and with how it is strictly interpreted by the European Data Protection Board.</p><p>I have to admit that, after years of debate, I am still not sure what this so-called “equivalent alternative” – which would ensure free consent – is supposed to look like. But I don’t think I’m the only one. After all, it is easy to argue that charging €1.99 a month may influence a user’s choice. It is far harder to identify a genuinely viable alternative that would not.</p><p>And while we were debating this – that is to say, the price of consent – the European Commission reframed the debate.</p><p>With the Digital Omnibus, the legislator acknowledges something we all know: users do not read cookie banners, do not fully understand what they are agreeing to, and tend to give consent simply in order to fully access content that would otherwise be blocked by the presence of such banners.</p><p>In other words, consent is not the result of a genuinely free and informed choice.</p><p>To address this problem, the proposal introduces automated signals: technical tools that allow users to express their preferences once and for all without having to interact with cookie banners every time. Data controllers are required to implement tools capable of reading and complying with these signals.</p><p>In a sense, this represents an attempt to move beyond consent as we have known it until now.</p><p>But – and this is where the debate becomes particularly interesting – the legislator introduces an exception: media service providers, when offering media services, are not required to comply with those signals.</p><p>And there is no technical justification for such an exemption. The reason is economic: the aim is to preserve publishers’ ability to interact directly with users to obtain their consent and, in doing so, to safeguard the revenue streams that support independent journalism, which is considered a pillar of democratic society.</p><p>Now, on the one hand, the European legislator tells us that the cookie banner system is ineffective, creates fatigue - the fatigue associated with consent - and does not lead to genuinely informed decisions.</p><p>On the other hand, it has decided to maintain – and indeed to protect – it precisely in the media sector.</p><p>This raises an obvious question: how can we, at the same time, acknowledge that the mechanism is structurally inadequate for obtaining free consent, yet continue to base the validity of such consent on that very mechanism?</p><p>Perhaps the answer is simpler – and more uncomfortable – than we have been willing to admit so far.</p><p>Perhaps it is time to openly acknowledge that Consent or Pay, in its current form, has limitations. That the user’s choice is inevitably influenced. That consent, in these contexts, can never be entirely free from influence.</p><p>But that does not automatically make it unlawful.</p><p>Because another consideration comes into play: the need to strike a fair balance.</p><p>The right to the protection of personal data, after all, does not exist in a vacuum. It coexists with other rights and freedoms: freedom of expression, freedom of information, and freedom of enterprise.</p><p>The point is not to question the fundamental nature of the right to personal data protection. Rather, it is to recognise that, in a constitutional system, even fundamental rights can come into conflict and must be balanced.</p><p>And here, in my view, the Digital Omnibus marks a significant shift.</p><p>It does not say that personal data is a commodity.</p><p>It does not say that the right to data protection can be waived.</p><p>But it goes a step further by recognising that when sufficiently significant interests are at stake, which are structural and democratically justified, balancing is not only possible, but legitimate.</p><p>And it does so through an express legislative provision, not through a doctrinal construct.</p><p>This, inevitably, has significant implications.</p><p>Because it makes it harder to sustain an absolutist approach, such as that expressed by the European Data Protection Board itself, according to which personal data can never become the object of commercial exchange or be made subject to conditionality.</p><p>The emerging regulatory landscape is more nuanced.</p><p>So perhaps the real question is no longer: “Can data have a price?”. But rather: “What interests justify it having a price under certain conditions?”.</p><p>And above all: who decides where to strike this balance?</p><p>The European legislator, certainly.</p><p>The supervisory authorities, through their interpretation.</p><p>The courts, in concrete cases.</p><p>And, to some extent, the market itself – although market forces alone cannot determine the outcome.</p><p>Otherwise, there is a clear risk that the balance will gradually slip into commodification.</p><p>So, in my opinion, this is the real issue on which the debate must now focus: the framework of values that the European system is building.</p><p>If the exemption for the media is justified by the democratic importance of journalism, what other economic interests can lay claim to the same status?</p><p>I am thinking of the sustainability of digital platforms, technological innovation, access to digital services, and scientific research.</p><p>The open question remains where to draw the line between a legitimate balance and a gradual erosion of a fundamental right.</p><p>Much, in my view, depends on the interplay between the Digital Omnibus and Consent or Pay.</p><p>And perhaps that is why Consent or Pay is no longer simply about consent.</p><p>It has become the place where a much broader question is being decided: what kind of relationship European law should establish between fundamental rights and the data economy.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/5/8/csm_ADV_Start-up_2_3dd5708e68.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-10220</guid>
                        <pubDate>Tue, 14 Apr 2026 10:20:07 +0200</pubDate>
                        <title>NIS2: ACN adopts new determinations on relevant suppliers, categorization of activities and services, and deadlines for new NIS entities registered in 2026</title>
                        <link>https://www.advant-nctm.com/en/news/nis2-acn-ha-adottato-le-nuove-determinazioni-su-fornitori-rilevanti-categorizzazione-di-attivita-e-servizi-e-scadenze-per-i-nuovi-soggetti-nis</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 13 April 2026, the Italian National Cybersecurity Agency (“ACN”) published on its website two new determinations issued by the Director General of ACN:</p><ul><li data-list-item-id="e5ae2f3ed975048c397b78f6d3077e8e5"><span><strong>ACN Determination No. 127437 of 13 April 2026</strong></span>, which updates and replaces the previous ACN Determination No. 379887 of 19 December 2025 and introduces the obligation to carry out the new process for listing and categorizing activities and services, as well as listing relevant NIS suppliers during the annual information update;</li><li data-list-item-id="e8d3b93953cbb57918bcbb1068866b7b2"><span><strong>ACN Determination No. 127434 of 13 April 2026</strong></span>, which sets the deadlines by which entities newly included in the NIS list during 2026 must comply with obligations concerning the notification of significant incidents and the adoption of security measures.</li></ul><p><strong>List of relevant NIS suppliers</strong></p><p>ACN Determination No. 127437/2026 introduces the obligation to indicate relevant NIS suppliers as part of the broader annual information update process.</p><p>A relevant NIS supplier is an entity that provides services or products to a NIS entity and meets at least one of the following criteria:</p><ol><li data-list-item-id="ec7b4a484f7217c25090df6dd60b61f0e">the supply relates to the activities or services referred to in Annex I, points 8 and 9, of the NIS Decree, including DNS service providers, top-level domain name registry operators, cloud service providers, data center service providers, content delivery network (CDN) providers, as well as managed service providers and managed security service providers;</li><li data-list-item-id="e9894b24125ef418aa94fb001f7923409">disruption or compromise of the supply would have a significant impact on the NIS entity’s ability to deliver the activities or services falling within the scope of NIS, also because adequate alternative suppliers are not available (non-substitutable suppliers).</li></ol><p>To comply with this obligation, NIS entities must use the “NIS Service / Annual Information Update” on the ACN Portal and indicate, for each relevant supplier:</p><ul><li data-list-item-id="e208c4cbd9ba691e27508812ae890b3c4">company name;</li><li data-list-item-id="e19da10ae9e42d7b8a64a1a1d7ed2013b">tax identification number;</li><li data-list-item-id="e52e7fe3dd759ddf520a93fdf9b5696e8">country of registered office;</li><li data-list-item-id="e2d7dafd3faa662c6b02735cbb8738b0b">CPV (Common Procurement Vocabulary) codes relating to the supplies received by the NIS entity;</li><li data-list-item-id="edd8fcb1eb6d6f6f75dbbda2a868aa531">the relevance criterion applied.</li></ul><p><strong>Listing and categorization of activities and services</strong></p><p>One of the main operational innovations concerns the obligation for NIS entities to communicate the list of their activities and services, assigning each of them a corresponding relevance category. Legislative Decree No. 138/2024 (“NIS Decree”) provides that this requirement must be fulfilled from 1 May to 30 June each year, via the ACN digital platform, starting from the receipt of the first notification of inclusion in the list of NIS entities.</p><p>ACN Determination No. 127437/2026 specifies that this activity must be carried out through the “NIS Service / Categorization” on the ACN Portal. In practice, the Point of Contact must complete the list of the organization’s activities and services and assign to each a relevance category according to the model that will be established by ACN in the coming days, with the publication of a determination containing the categorization model, together with supporting materials to assist in carrying out a simplified Business Impact Analysis (BIA).</p><p>It is important to note that, after the 30 June deadline, the categorized list of activities and services will be considered final and no longer amendable, except in cases of delay due to documented technical-operational issues not attributable to the entity.</p><p>Furthermore, financial entities subject to the DORA Regulation and also falling within the scope of NIS are exempt from this specific requirement, without prejudice to the possibility of voluntary compliance.</p><p>The categorized list of activities and services submitted by NIS entities may be subject to compliance checks by ACN, carried out on a sample basis and also by comparison with data submitted by comparable entities. ACN must provide feedback within 90 days of submission, a deadline that may be extended once by up to an additional 60 days in case of further review. Where additional information, clarifications, or amendments are requested, the NIS entity must respond within 30 days; in case of failure to respond or late response, the list may be rejected. In the absence of a negative outcome communicated within the prescribed timeframe, the list shall be deemed validated.</p><p><strong>Deadlines for entities included in the NIS list for the first time in 2026</strong></p><p>ACN Determination No. 127434/2026 concerns entities that were included for the first time in the list of NIS entities during 2026. For these entities, ACN has set the deadlines for compliance with obligations relating to security measures and incident notification. In particular:</p><ul><li data-list-item-id="e6aa6cd3c15279f7e343d395a700a3846">the deadline for the adoption of the security measures set out in Annexes 1 and 2 of ACN Determination No. 379907/2025 is 31 July 2027;</li><li data-list-item-id="e889c4266c16d93cbeca8ed40e3f79368">the obligation to notify significant incidents described in Annexes 3 and 4 of ACN Determination No. 379907/2025 applies from 1 January 2027.</li></ul><p>An additional provision concerns top-level domain name registry operators and domain name registration service providers included in the NIS list during 2026. For these entities, ACN Determination No. 127434/2026 provides that the obligations referred to in Article 4(1) of ACN Determination No. 379907/2025 must be fulfilled by 31 July 2027.</p><p>If you need assistance and support in complying with the obligations under the NIS framework, please contact your trusted advisors.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9682</guid>
                        <pubDate>Wed, 29 Oct 2025 17:01:06 +0100</pubDate>
                        <title>Italy’s AI Regulations Take Effect: Should Other Countries Follow?</title>
                        <link>https://www.advant-nctm.com/en/news/italys-ai-regulations-take-effect-should-other-countries-follow</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Italy has become the first country in the European Union to pass a national law on AI before the EU’s own AI Act takes effect. The law, approved by the Senate in the middle of last month, builds on discussions that began in April las year. Impact Newswire reports that the Italian government wants to create more elaborate rules for both public and private AI use, focusing on accountability, ethics and transparency.&nbsp;</p><p>The law includes 28 articles that define how AI can be used in different sectors. It also introduces rules for protecting minors under 14, requiring parental consent before any data linked to them can be processed. Italian lawmakers say the goal is to make AI systems fair and safe for citizens while allowing companies to keep innovating responsibly.</p><p>According to <strong>Giulio Uras</strong>:</p><p>“The Italian government’s effort has been both remarkable and, for once, genuinely timely. It sets a clear benchmark for EU countries aiming to complement the AI Act at the national level. Its approach is founded on three key pillars: innovation, transparency, and criminal protection.&nbsp;</p><p>On innovation, the Italian law conveys a clear and forward-looking policy direction. By authorising the secondary use of pseudonymised personal data for research purposes, it adopts a functional and proportionate regulatory model designed to foster scientific and technological development. This approach implicitly acknowledges that Europe’s ability to compete in the global AI landscape depends on avoiding an overly dogmatic interpretation of fundamental rights (particularly in the field of data protection) that could unduly restrict legitimate research and innovation.&nbsp;</p><p>As for transparency, the Italian law is more debatable. The law extends disclosure obligations across several sectors (including employment and intellectual professions) without following the AI Act’s risk-based approach. Such a broad rule may overburden low-risk systems and, paradoxically, stifle innovation.</p><p>The criminal protection provisions yield mixed results. The new offense addressing deepfakes(Art. 612-quater of the Italian Criminal Code) effectively targets a growing threat. More broadly, introducing criminal law safeguards was undoubtedly necessary, as it reinforces protection against the unlawful use of AI to obtain unfair profits or inflict harm. However, criminal provisions are effective only when they can be concretely enforced. In this regard, the drafting technique adopted for the new aggravating circumstance (Art. 61, no. 11-decies of the Italian Criminal Code) raises issues of legal clarity and operational effectiveness, which may ultimately limit its enforceability in practice.</p><p>The real challenge for EU Member States that wish to follow Italy’s example will be to do so without adding unnecessary layers of bureaucracy or new burdens on businesses. Otherwise, the drive for innovation risks being lost in translation.”&nbsp;</p><p><i>Full article published in TechRound</i>.&nbsp;<br>&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/6/csm_Prova_2_dd566079a8.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9608</guid>
                        <pubDate>Mon, 06 Oct 2025 12:07:14 +0200</pubDate>
                        <title>NIS: The CSIRT Contact Person must be appointed by 31 December</title>
                        <link>https://www.advant-nctm.com/en/news/nis-entro-il-31-dicembre-deve-essere-designato-il-referente-csirt</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 19 September, the ACN (National Cybersecurity Agency) adopted Determination ACN No. 250916, which updates and replaces the previous Determination ACN No. 333017 of 22 July 2025.</p><p>The most significant change is the introduction of the <i>CSIRT Contact Person</i>.</p><p><strong>Who is the CSIRT Contact Person?</strong></p><p>The CSIRT Contact Person is the individual responsible for managing communications with <i>CSIRT Italia</i> (the national Computer Security Incident Response Team) and for transmitting notifications of significant incidents (as defined in Determination ACN No. 164179) as well as voluntary reports of relevant cybersecurity information.</p><p>To ensure prompt and continuous communication with the CSIRT, the regulation allows the appointment of one or more deputies to the CSIRT Contact Person. These deputies support the Contact Person in their duties and can act on their behalf in cases of absence or impediment.</p><p>Unlike the Point of Contact and the Deputy Point of Contact, the CSIRT Contact Person (and their deputy) may also be an external individual (for example, a consultant).</p><p>In any case, designated persons must possess basic skills in cybersecurity and incident management, along with an in-depth knowledge of the information systems and networks of the NIS entity for which they operate.</p><p>The designation must be carried out by the Point of Contact through a dedicated procedure. This procedure will be active from 20 November 2025 and must be completed by 31 December 2025 via the service portal accessible through the ACN website.</p><p>At first glance, the introduction of the CSIRT Contact Person represents an important support tool for NIS entities, as it allows them to delegate the management of incident notifications to external individuals. This relieves NIS entities from particularly burdensome and time-consuming activities for which it may be preferable to rely on external consultants with specific expertise.</p><p>This is particularly useful for:</p><ul><li><span>NIS entities that lack adequate internal structures or resources to manage the requirements related to incident notification;</span></li><li><span>foreign organizations under national jurisdiction (for example, providers of public electronic communications networks and publicly available electronic communications services) that may face challenges due to language barriers or time zone differences.</span></li></ul><p>If you need assistance and support in fulfilling the obligations under the NIS framework, <a href="https://www.advant-nctm.com/esperienza/aree-di-attivita/it-e-data/compliance-digitale" target="_blank"><strong><u>click here</u></strong></a></p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/5/8/csm_ADV_Start-up_2_3dd5708e68.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9559</guid>
                        <pubDate>Fri, 19 Sep 2025 10:20:35 +0200</pubDate>
                        <title>Italy has its law on artificial intelligence</title>
                        <link>https://www.advant-nctm.com/en/news/litalia-ha-la-sua-legge-sullintelligenza-artificiale</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The contents of the law on artificial intelligence and future challenges.</p><p><strong>The final approval</strong><br>On September 17, 2025, the Senate, with 77 votes in favor, 55 against and 2 abstentions, definitively approved the law on artificial intelligence (hereinafter, the “Law”).<br>Italy thus becomes the first EU country to integrate the rules set out in the AI Act with national legislation on artificial intelligence. The aim of the national legislator is to further strengthen the level of protection from risks connected with the use of artificial intelligence in certain areas and sectors.</p><p><strong>The structure of the Law</strong><br>The Law is composed of 28 articles divided into six titles.<br>Title I, programmatic in nature, establishes the principles to be respected and the purposes that artificial intelligence should pursue.<br>Title II lays down specific provisions regarding the use of artificial intelligence systems in certain sectors such as the healthcare sector, scientific research, the world of employment, intellectual professions, public administration and the administration of justice.<br>Title III sets out the procedures for drafting and updating the national strategy for artificial intelligence, which must foster public-private collaborations and promote research and training.<br>Title IV is dedicated to copyright protection and Title V to criminal protection.<br>Finally, Title VI contains the financial and final provisions.</p><p><strong>The competent authorities</strong><br>With the approval of the Law, the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) have been officially designated as the national competent authorities in the field of artificial intelligence.<br>AgID, as the notifying authority, will define the procedures and exercise the functions and tasks relating to notification, assessment, accreditation and monitoring of the entities appointed to verify the compliance of high-risk artificial intelligence systems.<br>Meanwhile, ACN, as the supervisory authority, will be responsible for monitoring artificial intelligence systems, with inspection and sanctioning powers.<br>Both authorities will also contribute to the definition and updating of the national strategy for artificial intelligence in agreement with the Department for Digital Transformation.<br>In addition, within the Presidency of the Council, the following are established:</p><ul><li>the Steering Coordination Committee, with functions of coordinating steering action and promoting research, experimentation, development, adoption and application activities of artificial intelligence systems and models;</li><li>the Coordination Committee among the authorities, with the task of ensuring coordination and cooperation between national competent authorities, other public administrations and independent authorities.</li></ul><p><strong>The main innovations sector by sector</strong><br>Healthcare and research. Art. 8 of the Law authorizes the secondary use of personal data (including special categories) for research purposes, provided they are free of identifying elements and without prejudice to the obligation to inform the data subject. The use of artificial intelligence in healthcare will be allowed as support for prevention, diagnosis, care and treatment processes, on condition that the final decision remains with the doctor.</p><p>Employment. A ministerial observatory on artificial intelligence is established to monitor risks and opportunities of artificial intelligence in the employment context. Any automated assessment of workers’ performance without the possibility of contestation is prohibited, while employers are required to inform and train staff on the use of technological tools.</p><p>Intellectual professions. Art. 13 of the Law limits the use of artificial intelligence systems in intellectual professions to instrumental and support activities for professional work, with prevalence of the intellectual work being performed. In addition, professionals are required to inform the client about the artificial intelligence systems used, with clear, simple and exhaustive language.</p><p>Justice. Art. 15 of the Law prohibits the use of artificial intelligence systems for the adoption of judicial decisions in an automated way; however, they may be used for analysis and support in the drafting of documents, without prejudice to the responsibility of magistrates.</p><p><strong>How the criminal code changes</strong><br>Title V introduces certain amendments to the criminal code. In particular, the Law introduces a new type of offence and a new common aggravating circumstance.<br>The new offence, which is included in Art. 612-quater c.p., punishes the dissemination of falsified content, capable of misleading (so-called deep fakes), through artificial intelligence systems.<br>On the other hand, the Law establishes an articulated system of aggravating circumstances, the core of which is the introduction of a common aggravating circumstance in Art. 61, no. 11-decies c.p., which provides for an increased penalty where the use of an artificial intelligence system constitutes a treacherous means to facilitate the offence, hinder the defence or aggravate its consequences.</p><p><strong>Implementation of the Law</strong><br>For the entry into force of the Law, it remains only to await promulgation by the President of the Republic and its publication in the Official Gazette, from which the 15 days of vacatio legis will begin.<br>In any case, once the Law has entered into force, it will be up to the Government to complete the framework through the adoption, within twelve months, of one or more legislative decrees. These will regulate aspects of particular importance, including:</p><ul><li>the definition of an organic framework concerning the use of data, algorithms and mathematical methods for the training of artificial intelligence systems;</li><li>the attribution to the competent authorities of supervisory, inspection, sanctioning and other administrative powers provided for by the AI Act;</li><li>the regulation of measures for updating the existing legislation on banking, financial, insurance and payment services;</li><li>the definition of rules on civil liability for damages resulting from the use of artificial intelligence;</li><li>the definition of criteria for imputing criminal liability of natural persons and administrative liability of entities, taking into account the actual level of control over systems.</li></ul><p><strong>The unresolved issues</strong><br>Some critical issues highlighted during the parliamentary process remain in the text of the Law definitively approved by the Senate.<br>In particular, in its detailed opinion C(2024)7814, the Commission had “rejected” the first draft of the Law for three main reasons:</p><ol><li>definitions cannot deviate from those used in the AI Act;</li><li>the healthcare, intellectual professions and judicial administration sectors risk being subject to excessive obligations;</li><li>AgID and ACN are government authorities and therefore do not ensure full independence.<br>While the first issue had already been resolved by referring to the AI Act definitions, the other two areas of potential incompatibility with EU legislation do not appear to have been addressed.</li></ol><p><strong>The challenge is now</strong><br>The final approval of the Law represents an important milestone for Italy, which takes the lead among other European countries with regard to artificial intelligence. But the real challenge begins now with the implementation of the legislation.<br>The success of the Law will in fact largely depend on the quality of the legislative decrees that the Government will have to adopt within the next year; a crucial test to translate the programmatic objectives into operational rules that can adequately balance the needs of operators, technological progress and the protection of fundamental rights and freedoms.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/5/8/csm_ADV_Start-up_2_3dd5708e68.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9314</guid>
                        <pubDate>Wed, 16 Jul 2025 09:32:21 +0200</pubDate>
                        <title>2024 Annual Report of the Italian Data Protection Authority to Parliament</title>
                        <link>https://www.advant-nctm.com/en/news/relazione-annuale-2024-del-garante-privacy-al-parlamento</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The presentation of the 2024 Annual Report by the Italian Data Protection Authority to the Chamber of Deputies represents a key event not only for institutions, legal professionals, and stakeholders, but also for all citizens. In a fast-evolving technological context—marked by the advent of artificial intelligence and the relentless digitalization of processes and services—privacy protection continues to be a fundamental pillar of democracy and digital trust.</p><p><strong>Key Figures of 2024: A Year of Challenges and Actions</strong></p><p>The report clearly highlights how complex and interconnected the landscape of data protection has become:</p><ul><li><span><strong>2,204 data breaches</strong> were reported across both public and private sectors—evidence of increasing exposure to risk and the need for a rigorous, proactive approach from all actors, especially in light of the Authority's increasingly strict sanctions in serious cases.</span></li><li><span><strong>130 inspections</strong> were carried out, focusing on highly innovative areas: digital identity systems (SPID), facial recognition, video surveillance, and artificial intelligence applications. These audits underscore how the privacy challenge is increasingly intertwined with technological innovation and cybersecurity.</span></li><li><span><strong>835 collegial decisions</strong> were adopted, including <strong>468 corrective and punitive measures</strong>—a strong signal of the Authority’s growing attention to both repressive and preventive efforts concerning the most relevant violations. Sanction-related payments amounted to <strong>€24,430,856.45</strong>.</span></li><li><span>Over <strong>16,000 inquiries</strong> were handled by the Authority, reflecting a growing and tangible interest in data protection and the need for clear and authoritative communication to support citizens and businesses.</span></li></ul><p><strong>Privacy and Artificial Intelligence: Assessments and Perspectives</strong></p><p>In 2024, the Authority focused on the profound implications of adopting artificial intelligence in key sectors: from digital healthcare to age verification, digital identity management, and the risks linked to web scraping for algorithm training. The dialogue between technological evolution and legal regulation is becoming increasingly intense, leading the Authority to reaffirm the need for strict, up-to-date governance in response to emerging digital scenarios.</p><p>Audit activities and decisions also addressed the sensitive issues of <strong>automated decision-making and profiling</strong>, as well as the <strong>cybersecurity of public and private infrastructures</strong>. The report calls on all data controllers to maintain a high level of awareness and responsibility in terms of both technical and organizational security.</p><p><strong>Culture of Compliance: Rights and Trust at the Core</strong></p><p>The Authority’s assessment is clear: building a culture of compliance and data security is no longer a mere regulatory requirement. It is a safeguard for the fundamental rights of individuals and an essential foundation for digital trust in society and the marketplace.</p><p>A renewed call is made to all stakeholders—public and private—to invest in <strong>training</strong>, <strong>continuous process updates</strong>, and <strong>transparency</strong>, in order to strengthen a digital ecosystem that protects the <strong>dignity</strong>, <strong>freedom</strong>, and <strong>security</strong> of every individual.</p><p>The 2024 Annual Report of the Italian Data Protection Authority portrays a country where personal data protection is no longer just a technical issue, but a <strong>social, legal, and ethical matter</strong>. From managing data breaches to AI innovation, the challenge is ongoing and demands that all players rise to the occasion—working together to build a <strong>safer, more inclusive, and more transparent digital future</strong>.</p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9295</guid>
                        <pubDate>Fri, 11 Jul 2025 12:42:57 +0200</pubDate>
                        <title>ADVANT Lawyers offer perspectives on new EU rules for AI regulation</title>
                        <link>https://www.advant-nctm.com/en/news/advant-lawyers-offer-perspectives-on-new-eu-rules-for-ai-regulation</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>On 10 July 2025, The European Union unveiled a new code of practice on AI regulation, some of the first detail on how EU regulators plan to implement the AI Act passed last year. Lawyers from member firms of the European law firm association&nbsp;<a href="http://www.advantlaw.com" target="_blank">ADVANT</a> offer their perspectives on this development, and its implications below.</p><p><strong>Comments from</strong><a href="https://www.advant-nctm.com/en/professional/cv-professional/paolo-lazzarino" target="_blank"><strong> Paolo Lazzarino</strong></a><strong>, Partner at ADVANT Nctm (Italy):</strong></p><p><i>“The new Code of Practice released by the European Commission on July 10, 2025,</i> <i>marks a significant step toward transparency in artificial intelligence. One of its core elements is the requirement for developers of generative AI models to disclose what data was used to train them. This isn’t just a formality—it allows users, journalists, and other developers to understand the foundations behind AI-generated content. Think of it as a nutrition label for AI: knowing what a model was ‘fed’ helps to assess the reliability of what it produces.</i></p><p><i>“This focus on transparency is aimed to build public trust and increase corporate accountability. If we know whether the data comes from a certain media or archives, we can better evaluate the model’s potential biases and limitations. While the Code is voluntary, companies that adopt it show a commitment to responsible AI, anticipating the binding requirements that will come into force under the EU AI Act in the coming years.”</i></p><p><strong>Comments from</strong><a href="https://www.advant-nctm.com/en/professional/cv-professional/paolo-gallarati" target="_blank"><strong> Paolo Gallarati</strong></a><strong>, Partner at ADVANT Nctm (Italy):</strong></p><p><i>“This will also contribute to raise awareness on the fair processing of personal data in AI training models, with a view to preserving the right balance between the legitimate interest of AI developers and data subjects’ consent: in fact, big data and machine learning can pierce the veil of anonymous data enabling the identification of individuals with technical means whose affordability was unimaginable just a few years ago.”</i></p><p><strong>Comments from</strong><a href="https://www.advant-nctm.com/en/professional/cv-professional/giulio-uras" target="_blank"><strong>Giulio Uras</strong></a><strong>, Counsel at ADVANT Nctm (Italy):</strong></p><p><i>“From a compliance standpoint, the EU’s newly released code of practice for general-purpose AI systems reveals not only the technical direction of AI Act enforcement, but also the political and economic balancing act the Union is currently engaged in.</i></p><p><i>“While framed as a voluntary tool, the code is clearly intended to become the de facto compliance path for major AI providers. For legal and compliance professionals working within the AI Act’s risk-based framework, the immediate challenge is operational: how to ensure conformity and due diligence in an environment where upstream transparency — particularly in relation to model documentation and training data — remains discretionary and, in many cases, asymmetrical.</i></p><p><i>“Beyond the legal mechanics, however, the broader picture is harder to ignore. The EU’s attempt to ‘simplify’ compliance via soft law mechanisms is, in reality, a defensive maneuver. With geopolitical uncertainty increasing — and transatlantic tensions, industrial policy shifts, and global AI races accelerating — Europe’s regulatory approach risks becoming both overly cautious and structurally rigid. The code’s voluntary nature may ease the short-term burden on industry, but it also delays legal certainty and fosters fragmented compliance strategies across jurisdictions and actors.</i></p><p><i>“Moreover, the EU’s efforts to accommodate industry concerns, while politically expedient, arguably dilute the AI Act’s foundational promise of trustworthy and safe AI. In practice, this risks creating a compliance framework that is neither robustly enforceable nor truly innovation-friendly — particularly for EU-based firms that do not have the scale or leverage of the major GPAI developers.”</i></p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-9085</guid>
                        <pubDate>Thu, 05 Jun 2025 12:06:28 +0200</pubDate>
                        <title>Metadata, the Italian Data Protection Authority intervenes on the Extension of the Retention Period Beyond 21 Days</title>
                        <link>https://www.advant-nctm.com/en/news/metadati-il-garante-interviene-sullestensione-del-periodo-di-conservazione-oltre-i-21-giorni</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">With Decision No. 243 of April 29, 2025, the Italian Data Protection Authority (“<i><strong>IDPA”</strong></i>) imposed an administrative fine of €50,000 on the Lombardy Region (“<i><strong>Region</strong></i>”) for having retained, without the necessary procedural safeguards, metadata generated by email management systems for 90 days and Internet browsing logs for 365 days. In particular, the Region failed to comply with the obligations set out in Article 4(1) of Law No. 300/1970 (“<i><strong>Workers’ Statute</strong></i>”) and did not conduct a data protection impact assessment (DPIA) pursuant to Article 35 of the GDPR.</p><p class="text-justify">In this Decision, the IDPA reiterated that metadata generated by email management systems and Internet browsing logs are personal data and that their generalized collection, as it enables remote monitoring of work activity, requires the employer, under certain circumstances, to follow the procedures set out in Article 4(1) of the Workers’ Statute.</p><p class="text-justify">The IDPA’s Position Paper dated June 6, 2024, had already established this position, specifying that metadata generated by employee email systems may be retained only for limited periods, generally not exceeding 21 days. If retention exceeds 21 days, it is necessary—according to the IDPA—to follow the procedures under Article 4(1) of the Workers’ Statute. This is unless the data controller can concretely demonstrate specific technical or organizational reasons (e.g., related to the cybersecurity of the email service) that justify the extension of the retention period beyond 21 days.</p><p class="text-justify">Such reasons were not found in this case.</p><p class="text-justify">The Region, moreover, through three external providers, was able to combine IP addresses, MAC addresses, and employee identities, thus having full access to information that enabled potential profiling and individual monitoring of employees. The IDPA considered such processing disproportionate and excessive relative to the principles of data minimization and storage limitation. It therefore mandated, among other things, the anonymization of attempts to access blacklisted websites, the reduction of Internet browsing log retention from 365 to 90 days (with retention beyond this limit allowed only after anonymization), restricted access to data to expressly authorized personnel, and encryption of data enabling the association between device and employee.</p><p class="text-justify">The IDPA also clarified that, considering the fact that processing metadata from employee email systems potentially involves “high risks” to the rights and freedoms of the individuals concerned (since it entails systematic monitoring of employees—deemed vulnerable due to their subordinate employment status), conducting a DPIA is mandatory, and failure to do so constitutes a violation of Article 35 of the GDPR.</p><p class="text-justify">The IDPA’s stance is thus clear: metadata should not be retained for more than 21 days, and doing so without following the procedures under Article 4(1) of the Workers’ Statute is only legitimate in the presence of proven technical reasons related to the functioning and cybersecurity of the service (which cannot be based on generic IT security concerns of the employer’s networks and systems). Where such reasons are lacking, it is necessary, depending on the case, to reach an agreement with union representatives or obtain authorization from the competent Labor Inspectorate. In all cases, a DPIA and a Legitimate Interest Assessment (LIA) must be conducted and documented, relevant information notices on the processing of personal data and internal policies and procedures updated, and appropriate technical and organizational measures adopted to ensure an adequate level of personal data protection.</p><p class="text-justify">If you need assistance and support in complying with the obligations related to the collection and retention of metadata generated by corporate email systems, contact your trusted professionals.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8979</guid>
                        <pubDate>Tue, 13 May 2025 15:09:54 +0200</pubDate>
                        <title>New digital accessibility obligations</title>
                        <link>https://www.advant-nctm.com/en/news/nuovi-obblighi-di-accessibilita-digitale</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>The requirement for compliance with accessibility obligations for digital services made available to consumers will be binding from 28 June 2025. Relevant regulatory sources include: Legislative Decree 82/2022, which transposed Directive (EU) 2019/882, known as the “European Accessibility Act” (EAA); Law 4/2004, as amended and supplemented, known as the “Stanca Act” (which first introduced accessibility obligations for public authorities); Law 120/2020, which extended the subjective scope of the Stanca Act to the private sector as well, with a focus on businesses that provide essential services of general interest through digital channels.</p><p><i><strong>Who is obliged to comply with the regulations?</strong></i></p><p>Digital accessibility obligations apply specifically to:&nbsp;</p><p>- Private economic operators providing digital services to the public, including but not limited to:</p><ul><li><span>banks, insurance companies, transportation companies and telecommunications operators;</span></li><li><span>e-commerce platforms, providers of audiovisual content, marketplaces and online services;</span></li><li><span>operators of ATMs, self-service terminals, electronic ticketing and postal services.</span></li></ul><p>- Entities involved in the design, production and marketing of digital tools intended for the general public, including but not limited to:</p><ul><li><span>web sites and mobile applications;</span></li><li><span>electronic devices with user interfaces;</span></li><li><span>management or application software accessible by end users.&nbsp;</span></li></ul><p><i><strong>Who supervises and what do those who fail to comply risk?</strong></i></p><p>The Agency for Digital Italy (AgID) is responsible for supervising the implementation of the regulations: it can carry out audits, inspections and, in case of non-compliance, take sanctioning and inhibitory measures.</p><p>Specifically, in case of violation, AgID can:</p><p>- issue a warning setting a deadline for compliance;&nbsp;</p><p>- apply fines:</p><ul><li><span>up to 5% of the average annual turnover for serious violations committed by entities offering services to the public through websites or mobile applications, with an average turnover, in the last three years of activity, exceeding €500 million;</span></li><li><span>between €5,000 and €40,000 for the other subjects, taking into account the seriousness of the violation, the number of users involved and the scope of the inaccessible services;</span></li><li><span>additional sanctions of €2,500 to €30,000 in case of non-compliance with AgID warnings or obstruction of inspection activities.&nbsp;</span></li></ul><p>AgID can also take particularly strong administrative inhibitory measures, including:&nbsp;</p><p>- website blackout or removal of applications from digital stores;&nbsp;</p><p>- temporary or permanent ban on access to non-compliant digital services.</p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8965</guid>
                        <pubDate>Thu, 08 May 2025 17:57:35 +0200</pubDate>
                        <title>NIS, ACN’s resolution on notification of sharing agreements</title>
                        <link>https://www.advant-nctm.com/en/news/nis-la-determinazione-dellacn-sulla-notifica-degli-accordi-di-condivisione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>ACN's Resolution No. 136118 of 10 April 2025 – <i>Notification of agreements on the sharing of cybersecurity information pursuant to Article 17 of the NIS</i> Decree (<strong>“Resolution 136118”</strong>) sets out the procedures whereby NIS entities that are a party to (cybersecurity information) sharing agreements must notify the ACN of their participation in such agreements.</p><p>Sharing agreements are governed by Article 17 of Legislative Decree No. 138/2024 and concern the (voluntary and optional) sharing between NIS entities or between NIS entities and other entities (e.g. suppliers of NIS entities) of information relating to cybersecurity, such as cyber threats, near misses, vulnerabilities, techniques and procedures, security alerts, etc. Such agreements are functional to the prevention of incidents as well as to the management, containment and mitigation of their consequences, and contribute to raising collective cybersecurity standards.</p><p>The participation of a NIS entity in one or more sharing agreements must be notified to the ACN via the service portal, providing the text of the agreement and indicating its name and the list of the entities that are a party to it.</p><p>As regards the notification deadlines, for agreements entered into after the entry into force of Legislative Decree 138/2024 (i.e. after 16 October 2024), notification must be made promptly and therefore at the same time or immediately after the conclusion of the agreement. In any event, sharing agreements signed before the entry into force of Legislative Decree 138/2024 (and still in force on 31 May 2026) must be notified by 31 May 2026.</p><p>The list of sharing agreements to which the NIS entity is a party notified to the ACN must always be checked and updated over time: in particular, pursuant to Resolution 136118, any changes (e.g., the signing of a new agreement, the termination of an agreement in place, or changes to the text or parties to the agreement) must be notified to the ACN within 14 days of the date of the change.</p><p>The list of sharing agreements must be updated at least once a year: between 15 April and 31 May of each year, NIS entities shall update, again via the portal, the list of sharing agreements to which they are a party.</p><p>Should you need any assistance and support in complying with the obligations under the NIS regulations, please contact your professional advisors.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/e/9/csm_ADV_II_White-Collar-Crime-Compliance-1_copy_42133935c6.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8807</guid>
                        <pubDate>Thu, 03 Apr 2025 12:02:29 +0200</pubDate>
                        <title>NIS, so what now? Dates to watch out for</title>
                        <link>https://www.advant-nctm.com/en/news/nis-e-ora-il-calendario-delle-date-da-tenere-a-mente</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">On 16 October, Legislative Decree No. 138/2024 came into force, whereby Italy implemented Directive (EU) 2022/2555 (the so-called NIS2 Directive).</p><p class="text-justify">Legislative Decree No. 138/2024 generally applies to medium and large enterprises in 17 critical and highly critical sectors (besides public administrations and certain other types of entities identified directly by the National Cybersecurity Agency (ACN)) and imposes on NIS entities obligations that can be grouped into the following categories:&nbsp; &nbsp;</p><ul><li><p class="text-justify"><span><strong>obligations to register and update information</strong>: every year NIS entities must register or update their registration on the ACN web portal, specifying their point of contact and providing a series of information relating, among other things, to the activities carried out and services provided;</span></p></li><li><p class="text-justify"><span><strong>obligations relating to security measures</strong>: NIS entities are required to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the information and network systems used in their activities or in the provision of their services;</span></p></li><li><p class="text-justify"><span><strong>obligations relating to incident notifications</strong>: NIS entities must notify the CSIRT, according to a multiple-stage approach and without delay, of security incidents that have a significant impact on the provision of their services;</span></p></li><li><p class="text-justify"><span><strong>obligations for administrative and management bodies</strong>: administrative and management bodies, which are responsible for breaches of NIS regulations, are required to undergo training in IT security and to promote the periodic offer of IT security training for their employees.</span></p></li></ul><p class="text-justify">If your organisation is an NIS entity or you assume it will become one during the course of this year, here is a calendar with the dates to remember to ensure compliance with Legislative Decree No. 138/2024.</p><p class="text-justify">&nbsp;</p><figure class="table" style="width:100.0%;"><table style="border-style:none;" class="contenttable"><tbody><tr><td style="background-color:#F2F2F2;border-color:#D9D9D9;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>&nbsp;15 April 2025</strong></span></td><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:none;border-right-style:solid;border-top-style:solid;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you registered on the ACN portal by 10 March 2025, you will receive confirmation from the ACN that your organisation has been included in the list of essential or important entities at the email addresses (of the organisation and the point of contact) that you provided during registration.</span></p><p class="text-justify"><span>Still on 15 April 2025, the ACN will adopt the resolutions that will define the basic obligations regarding incident notification and security measures that NIS entities must comply with starting from January 2026.</span></p></td></tr><tr><td style="border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From 15 April to 31 May 2025</strong></span></td><td style="border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you have been included in the list of essential and important entities, you will have to provide, through the portal, further information relating, in particular, to the domain names in use, the Member States in which you offer services regulated by the NIS and the managers in your organisation.</span></p></td></tr><tr><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From 1 January al 28 February 2026</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>If you registered on the ACN portal by 10 March 2025, you will need to confirm the information provided or update it, if necessary.</span></p><p class="text-justify"><span>If, instead, you did not register on the ACN portal by 10 March 2025 (because you believed that you did not fall within the scope of Legislative Decree No. 138/2024 on that date) but during the course of the year you have exceeded the thresholds for medium-sized enterprises or started activities that determine the application of the NIS regulations, you will have to make your first registration.</span></p></td></tr><tr><td style="border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From January 2026</strong></span></td><td style="border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>The basic obligations relating to incident notifications, laid down by the ACN in the resolution to be adopted by 15 April 2025 will become applicable.&nbsp;</span></p></td></tr><tr><td style="background-color:#F2F2F2;border-bottom-style:solid;border-color:#D9D9D9;border-left-style:solid;border-right-style:solid;border-top-style:none;border-width:1.0pt;height:2.0cm;padding:5.4pt;width:29.58%;"><span><strong>From October 2026</strong></span></td><td style="background-color:#F2F2F2;border-bottom:1.0pt solid #D9D9D9;border-left-style:none;border-right:1.0pt solid #D9D9D9;border-top-style:none;height:2.0cm;padding:5.4pt;width:70.42%;"><p class="text-justify"><span>The basic obligations relating to safety measures, laid down by the ACN in the resolution to be adopted by 15 April 2025, will become applicable.</span></p></td></tr></tbody></table></figure><p class="text-justify">&nbsp;</p><p class="text-justify">If you need assistance and support to fulfil the obligations of the NIS regulations, please contact your reference professionals.&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8702</guid>
                        <pubDate>Fri, 21 Mar 2025 15:46:37 +0100</pubDate>
                        <title>Artificial Intelligence Bill: first approval by the Senate</title>
                        <link>https://www.advant-nctm.com/en/news/ddl-intelligenza-artificiale-dal-senato-la-prima-approvazione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>A first analysis of the bill on artificial intelligence currently under review by the Italian Parliament.</p><p><strong>Legislative procedure</strong></p><p>On the night of Thursday 20 March 2025, the Senate of the Italian Republic approved the bill on artificial intelligence (the “<i><strong>AI Bill</strong></i>”) that will supplement, at domestic level, the rules laid down in Regulation (EU) 2024/1689 (better known as&nbsp;“<strong>AI Act</strong>”).&nbsp;</p><p>Almost a year after it was submitted to Parliament, the AI Bill has been given the green light by the Senate with minor amendments. The ball is now in the Chamber of Deputies’ court. However, in order for the provisions to be actually implemented, it will be necessary to wait (even after final approval by Parliament) for the Government to adopt legislative decrees on the matters delegated to it.&nbsp;</p><p>The (long) time taken by the Senate to approve the AI Bill can also be explained in light of the opinion issued by the European Commission, which identified a number of inconsistencies with the AI Act. As outlined below, such inconsistencies have been only partially resolved.</p><p><strong>The bill</strong></p><p>The objective of the AI Bill is to further strengthen the level of protection in relation to the use of artificial intelligence with specific reference to certain areas and sectors.</p><p>The structure of the AI Bill is as follows.</p><p>The first part establishes the&nbsp;<strong>guiding principles</strong>&nbsp;and defines the<strong> national strategy&nbsp;</strong>in relation to the use of artificial intelligence.</p><p>The second part instead contains<strong> specific-sector provisions</strong>, aimed at increasing the level of&nbsp;<strong>transparency</strong>&nbsp;in the following areas and sectors:</p><ul><li><span>healthcare &nbsp;and scientific research;</span></li><li><span>world of work and intellectual professions;</span></li><li><span>judicial activities;</span></li><li><span>public administration;</span></li><li><span>national security;</span></li><li><span>user protection and copyright.</span></li></ul><p>The third section is dedicated to governance&nbsp;and identifies the competent national authorities in this regard, namely:</p><ul><li><span>the<strong>&nbsp;</strong>Italian<strong> Agency for Digital Italy&nbsp;</strong>(AgID), as&nbsp;<u>notifying authority</u>; and</span></li><li><span>the<strong>&nbsp;</strong>Italian<strong> Agency for National Cybersecurity</strong> (ACN), as&nbsp;<u>supervisory authority</u>.</span></li></ul><p>Finally, the fourth part is dedicated to criminal protection and establishes a series of aggravating circumstances in relation to the use of artificial intelligence systems in the commission of certain crimes, while introducing a <strong>new type of crime</strong>&nbsp;that punishes the unlawful dissemination of so-called deep fakes.</p><p><strong>Changes to the original text</strong></p><p>Compared to the original version of 23 April 2024, the new text of the AI Bill has undergone few changes, all of minor importance, including, in particular, the following:</p><ul><li><span>the removal of autonomous definitions of the terms “artificial intelligence systems” and “artificial intelligence models”, while referring to the definitions in the AI Act;</span></li><li><span>the processing of personal data for research and clinical trial purposes will be specifically regulated by a decree issued by the Ministry of Health;</span></li><li><span>the granting of specific powers to the government to set out comprehensive regulations on the use of data, algorithms and mathematical methods in the training of artificial intelligence systems.</span></li></ul><p><strong>The Commission’s remarks</strong></p><p>As mentioned above, the EU Commission made a number of remarks to the Government about the original text of the AI Bill, deemed to be excessively restrictive.&nbsp;</p><p>More specifically, in its&nbsp;<strong>detailed opinion C(2024)7814</strong>, the Commission &nbsp;voted down the bill for three reasons:</p><ul><li><span>definitions cannot deviate from those used in the AI Act;</span></li><li><span>intellectual professions, judicial activities and healthcare are at risk of being overburdened by excessive obligations;</span></li><li><span>the appointed governance authorities, AgID and ACN, are governmental authorities that cannot ensure full independence.</span></li></ul><p><strong>Final considerations</strong></p><p>While the first issue has been addressed and resolved, the remaining issues do not appear to have been taken into consideration. Areas of potential incompatibility with European regulations on artificial intelligence therefore persist.</p><p>The question at this point is: will the AI Bill be approved as it stands, or will lawmakers take the Commission’s opinion into account and revise its content? All we can do is wait for the decision of the Chamber of Deputies.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Artificial Intelligence</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/a/8/csm_ADV_II_Intellectual-Property-4_copy_339629b104.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8658</guid>
                        <pubDate>Mon, 10 Mar 2025 12:20:03 +0100</pubDate>
                        <title>The algorithm must remain under human supervision</title>
                        <link>https://www.advant-nctm.com/en/news/lalgoritmo-deve-restare-sotto-la-supervisione-umana</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Interview with <strong>Fabio Coco</strong> for Plus24 Il Sole 24 Ore</p><p>Artificial intelligence is beginning to make a relevant contribution within the scope of its operations to players in the financial market. We try to take stock of the consequences with Fabio Coco, Partner at ADVANT Nctm.</p><p>Artificial intelligence use cases can bring great benefits to businesses in the financial world. Can we give some examples? In particular, artificial intelligence has been used to detect potential fraud against the payment service provider and customers. The ability to analyze large amounts of data makes it possible to identify anomalies in transactions to detect fraud attempts, but also to profile customer habits and identify transactions that deviate from these so-called patterns even through forms of “adaptive learning” i.e., tools that update their parameters, learning from the data in real time.</p><p><i>Full Article on Plus 24 - Il Sole 24 Ore</i></p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Regulatory</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/d/c/csm_ADV_MEP_5_d3ef2e6bdd.png" length="0" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8472</guid>
                        <pubDate>Tue, 11 Feb 2025 15:44:47 +0100</pubDate>
                        <title>Guidelines on pseudonymisation</title>
                        <link>https://www.advant-nctm.com/en/news/linee-guida-sulla-pseudonimizzazione</link>
                        <description></description>
                        <content:encoded><![CDATA[<p class="text-justify">The new guidelines on #pseudonymisation (“<a href="https://www.edpb.europa.eu/system/files/2025-01/edpb_guidelines_202501_pseudonymisation_en.pdf" target="_blank" rel="noreferrer"><i>Guidelines 01/2025 on Pseudonymisation</i></a>”, “<i><strong>Guidelines</strong></i>”) of the European Data Protection Board #EDPB out for consultation up to 28 February 2025 are a must-read.&nbsp; What are we talking about? Pseudonymisation is a technique that makes personal data more difficult to identify without additional information.&nbsp;</p><p class="text-justify">Within the scope of Regulation (EU) 2016/679 (“<strong>GDPR</strong>”), which introduces the concept for the first time, pseudonymisation is considered one of the technical measures that the data controller or processor can use to fulfil their obligations regarding personal data protection. Specifically, the pseudonymisation procedure consists of making personal data relating to a specific individual no longer attributable to that individual, except – and this is the substantial difference with anonymisation – through the use of additional information, including any additional information that is beyond the control of the party carrying out the pseudonymisation. Such additional information (so-called pseudonymisation secrets) must be stored separately and protected by adequate security measures. The aim is to ensure that those who process the pseudonymised data are not able to attribute it to the individual to whom the data belongs.&nbsp;</p><p>As stated in the Guidelines, since pseudonymised data constitutes information relating to an identifiable natural person, it remains personal data to all intents and purposes and, as such, is subject to the provisions of the GDPR.&nbsp;</p><p class="text-justify">In this regard, the EDPB seems to adopt a very broad notion of personal data, in contrast to the recent conclusions of Advocate General Dean Spielmann in case C-413/23 P of 6 February 2025. In fact, adopting a more restrictive approach, the Advocate General emphasises that, in order to determine whether pseudonymised data should be considered personal data and therefore fall within the objective scope of the GDPR, one must take into account the reasonable likelihood that the additional information can be used by the recipient of the data to identify the data subject, as the mere theoretical identifiability of the data subject is not sufficient.</p><p class="text-justify">Going back to the Guidelines, a fundamental concept introduced by the EDPB is that of “pseudonymised domain”, which can be defined as the set of authorised individuals and systems that can access the pseudonymised data. Within said domain, which is to be determined by the data controller/processor, the pseudonymised data can be processed minimising the risk of re-identifying the data subjects. This logically implies that pseudonymisation secrets&nbsp;must be kept separate from the pseudonymisation domain.&nbsp;</p><p class="text-justify">Keeping in mind the&nbsp;accountability principle, the controller is required to evaluate, also through periodic&nbsp;risk assessments, the likelihood of re-identification within the pseudonymisation domain, so as to ensure that the risk remains negligible throughout the entire processing period.</p><p class="text-justify">On the other hand, the Guidelines also provide useful operational guidance for companies and operators, giving some examples of appropriate technical measures for pseudonymisation, including:</p><ul><li><p class="text-justify"><span>advanced encryption techniques, such as SHA-3 hash functions, which can be used to create pseudonymised data. To increase the security of the process, it is possible to combine such functions with a salt, i.e. a randomly and securely generated data string;</span></p></li><li><p class="text-justify"><span>security measures relating to the IT infrastructure, such as limiting access to&nbsp;pseudonomysation secrets&nbsp;(in concrete terms, access could be limited to system administrators only, applying also to them the principle of least privilege);</span></p></li><li><p class="text-justify"><span>the use of&nbsp;data protection engineering&nbsp;tools on so-called quasi-identifiers (i.e. information that, if combined, can indirectly identify an individual), including techniques such as&nbsp;generalisation and suppression, which modify the level of detail of the data or eliminate highly risky data to reduce the risk of re-identification.</span></p></li></ul><p class="text-justify">In conclusion, the analysis of the Guidelines highlights the fundamental role that pseudonymisation can play in the application of the principle of privacy by design, as well as in some areas of business activity that are extremely sensitive from a&nbsp;data protection&nbsp;point of view, such as the management of whistleblowing channels and the transfer of personal data outside the EU. As clarified by the Guidelines, pseudonymisation can also facilitate the use of legal bases such as the legitimate interest referred to in Article 6(1)(f) of the GDPR for the processing of personal data - an approach that is certainly useful when looking for an alternative to consent and balancing the interests of companies and the rights of individuals - and favour the compatibility of the data processed by any recipients with the evaluation of the original purpose of the processing, pursuant to Article 6(4) GDPR.&nbsp;</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                                <category>Cybersecurity</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/f/4/csm_ADV_II_Intellectual-Property-4_copy_a5f140c600.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-8044</guid>
                        <pubDate>Wed, 02 Oct 2024 11:32:43 +0200</pubDate>
                        <title>NIS2 is ready to go!</title>
                        <link>https://www.advant-nctm.com/en/news/nis2-al-via</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Article by <a href="https://www.advant-nctm.com/professionisti/cv-professional/giulio-uras" target="_blank"><strong><u>Giulio Uras</u></strong></a>, <a href="https://www.advant-nctm.com/professionisti/cv-professional/francesco-fidel-camera" target="_blank"><strong><u>Francesco Fidel Camera</u></strong></a> e <a href="https://www.advant-nctm.com/professionisti/cv-professional/matteo-pagliarulo" target="_blank"><strong><u>Matteo Pagliarulo</u></strong></a>.</p><p>Legislative Decree No. 138/2024 (“<i><strong>NIS2</strong></i>&nbsp;<i><strong>Decree</strong></i>”), transposing Directive (EU) 2022/2555, known as the “NIS2 Directive” was published in the Official Gazette.</p><p>The NIS2 Decree, in addition to repealing Legislative Decree No. 65/2018 – which transposed Directive 2016/1148, the so-called NIS Directive –also provided for the repeal of Articles 40 (“<i>Security of networks and services”</i>) and 41 (“<i>Implementation and control</i>”) of Legislative Decree No. 259/2003 (“<i>Electronic Communications Code</i>”), with the consequence that now providers of public electronic communications networks or publicly available electronic communications services are subject only to the provisions set out in the NIS2 Decree.</p><p><i><strong>To whom does it apply?</strong></i></p><p>The NIS2 Decree applies to both public and private entities operating in “critical” sectors (e.g. energy, transport, banking, healthcare, digital infrastructure, space, waste management, manufacturing of medical devices, machinery, motor vehicles, etc.).&nbsp;</p><p>Moreover, the obliged entities are distinguished into “essential” and “important”, according to their importance for the sector or type of services they provide, as well as their size. Belonging to one or the other category is relevant for the application of sanctions in the event of breach of the obligations under the NIS2 Decree, which are higher for essential entities (equal to a maximum of at least EUR 10 million or a maximum of at least 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher).</p><p><i><strong>What are the obligations?</strong></i></p><p>The main obligations incumbent on the obliged parties are the adoption of IT security risk management measures and the notification of significant incidents.</p><p>With regard to the obligations in the area of IT security risk management, essential and important entities are required to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the information and network systems used in their activities or in the provision of their services.&nbsp;</p><p>With regard to reporting obligations, the NIS2 Decree requires essential and important entities to notify the CSIRT (Computer Security Incident Response Team) of incidents that have a significant impact on the provision of their services.&nbsp;</p><p>Notification is phased and involves: a pre-notification within 24 hours of the incident, the actual notification within 72 hours of the incident, and a final report within 1 month of the notification.</p><p>Both IT security risk management and reporting obligations will be set in detail (also with regard to terms, modalities, specifications and gradual implementation timeframes) by the NCA (National Cybersecurity Authority), through its own decisions based on gradualness and proportionality criteria.</p><p>The responsibility for ensuring compliance with the obligations laid down in the NIS2 Decree lies with administrative and management bodies of essential and important entities, which are responsible for breach of the NIS2 Decree.</p><p>For more information, see our Guide on&nbsp;<a href="https://www.advant-nctm.com/fileadmin/nctm/PDF/Guida_Cybersecurity.pdf" target="_blank"><strong>Cybersecurity</strong></a> (updated in accordance with NIS2 Decree, CER Decree and the Cybersecurity Law) or contact our dedicated professionals.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                            
                            
                            <enclosure url="https://www.advantlaw.com/fileadmin/_processed_/2/e/csm_ADV_Start-up_2_5b953c6711.jpg" length="0" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-4746</guid>
                        <pubDate>Mon, 12 Feb 2024 05:01:38 +0100</pubDate>
                        <title>Company emails and metadata - The Data Protection Authority&#039;s guidance document</title>
                        <link>https://www.advant-nctm.com/en/news/e-mail-aziendali-e-metadati-il-documento-di-indirizzo-del-garante-2</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Last Dec. 21, the Garante per la protezione dei dati personali (Garante for the protection of personal data) adopted the guidance document “E-mail management computer programs and services in the work context and metadata processing.”</p><p>The document imposes timely obligations on employers in relation to the collection, use and storage of metadata by e-mail management computer programs and services in use by employees.</p><p>But what is metadata and what is the content of the obligations imposed by the Guarantor?</p><p><a href="https://www.advantlaw.com/fileadmin/nctm/PDF/Email_aziendali_e_metadati.pdf" target="_blank"><u>Click here for the full document</u></a></p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-5051</guid>
                        <pubDate>Thu, 03 Jun 2021 03:54:45 +0200</pubDate>
                        <title>Vaccination certificates, relevant privacy implications not to be underestimated</title>
                        <link>https://www.advant-nctm.com/en/news/certificazione-vaccinale-le-importanti-implicazioni-privacy-da-non-sottovalutare</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em>The following document was published on June 3, 2021 in "<a href="https://media.mimesi.com/cacheServer/servlet/CropServer?date=20210601&amp;idArticle=545314792&amp;idFolder=12517&amp;idChapter=34221&amp;authCookie=-214691668&amp;trc=pDelivery-t20210601-a545314792-h34221-c1115-d10814-f12517-n784" target="_blank" rel="noreferrer">About Pharma and Medical Devices</a>".&nbsp;</em>The current health emergency arising from the spread of the coronavirus ("Covid-19") has led both national and supranational governmental authorities to adopt measures restricting certain fundamental rights and freedoms of individuals. In particular, some of the restrictions adopted by European Union ("EU") Member States to contain the Covid-19 pandemic have affected citizens' right to free movement.However, the progressive knowledge of Covid-19, its mode of transmission, the effectiveness of therapeutic measures to counteract the disease and, especially, the introduction of the many possibilities of vaccine prophylaxis have made possible a reflection on the exit strategies to be implemented to gradually bring citizens to a condition of normality.In such context, the European Commission took action with a proposal for a Regulation “<em>on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery to facilitate free movement during the COVID-19 pandemic (Digital Green Certificate)</em>”, to date already adopted by the European Parliament (the “<strong>Proposal</strong>”)&nbsp;<a href="/en/news#_ftn1" name="_ftnref1">[1]</a>.&nbsp;</p><ol> <li><strong>The “Digital Green Certificate” </strong></li></ol><p>Pursuant to Article 21 of the Treaty on the Functioning of the European Union, every EU citizen has the right to move and reside freely within the territory of the Member States, subject to the limitations and conditions laid down in the Treaties and by the measures adopted to give them effect.However, some of the measures adopted by the Member States in order to limit the spread of the ‘COVID‑19’ pandemic often consisted of restrictions on entry or other specific requirements applicable to cross-border travellers, such as to undergo quarantine or self-isolation or to be tested for SARS-CoV-2 infection prior to and/or after arrival.The Proposal is set in such context, which aims to facilitate the exercise of the right to free movement within the EU Member States and establish a common framework for the issuance, verification and acceptance of interoperable certificates on COVID-19 vaccination, testing and recovery, called "digital green certificate".&nbsp;</p><ol start="2"> <li><strong>Vaccination certificate</strong></li></ol><p>As mentioned, the digital green certificate allows cross-border issuance, verification and acceptance of any of the following certificates:</p><p style="padding-left: 30px;">(a) a certificate confirming that the holder has received a COVID-19 vaccine in the Member State issuing the certificate ("vaccination certificate");</p><p style="padding-left: 30px;">(b) a certificate indicating the holder’s result and date of a NAAT test or a rapid antigen test listed in the common and updated list of COVID-19 rapid antigen tests established on the basis of Council Recommendation 2021/C 24/01<a href="/en/news#_ftn2" name="_ftnref2">[2]&gt;</a> ("test certificate");</p><p style="padding-left: 30px;">(c) a certificate confirming that the holder has recovered from a SARS-CoV-2 infection following a positive NAAT test or a positive rapid antigen test listed in the common and updated list of COVID-19 rapid antigen tests established on the basis of Recommendation 2021/C 24/01 (“certificate of recovery”).</p>More specifically, the Proposal specifies that the vaccination certificate shall contain the following personal data:<p style="padding-left: 30px;">(a) name: surname(s) and forename(s), in that order;(b) date of birth;(c) disease or agent targeted;(d) vaccine/prophylaxis;(e) vaccine medicinal product;(f) vaccine marketing authorization holder or manufacturer;(g) number in a series of vaccinations/doses;(h) date of vaccination, indicating the date of the latest dose received;(i) Member State of vaccination;(j) certificate issuer;(k) a unique certificate identifier.</p>The attempt undertaken by the EU with the Proposal is to make the vaccination certificate, and more generally the digital green certificate, an instrument for the promotion of freedoms, with respect to which it is necessary to assess the impact on the protection of personal data, ensuring from the outset respect for the principles of proportionality and non-discrimination, which are all the more compulsory since we are dealing with data - health data - which require, due to their sensitivity, a higher degree of protection.&nbsp;<ol start="3"> <li><strong> What are the data protection implications?</strong></li></ol><p>It seems appropriate to recall that Regulation (EU) 2016/679 of the European Parliament and of the Council (the "<strong>GDPR</strong>") applies to the processing of personal data carried out in the context of the Proposal.Well, with reference to the processing of personal data carried out for the purpose of issuing the certificates in question, the Proposal provides for the legal ground to process personal data necessary to issue such certificates and to process&nbsp; the information necessary to confirm and verify the authenticity and validity of such certificates.In this regard, Whereas Clause 37 &nbsp;of the Proposal identifies the legal basis for the processing of personal data under Article 6(1)( c) of the GDPR (<em>i.e.</em>, processing is necessary for compliance with a legal obligation to which the controller is subject) and Article 9(2)(g) of the GDPR (<em>i.e.</em>, processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject), as necessary for the issuance and verification of the interoperable certificates provided for by the Proposal. <a href="/en/news#_ftn3" name="_ftnref3">[3]</a>Furthermore, the Commission specifies that, in accordance with the principle of &nbsp;minimisation of personal data, the certificates should only contain the personal data necessary for the purpose of facilitating the exercise of the right to free movement within the Union during the COVID-19 pandemic, underlining the necessity to set out specific categories of personal data and data fields to be included in the certificates, with a decentralised verification system that does not involve the storage of the &nbsp;assessment results, and limited to the continuation of the state of emergency as declared by WHO. The Commission indeed clarifies that the Proposal does not create a legal basis allowing &nbsp;the Member State of destination or the cross-border passenger transport services operators, which are required by national law to implement certain public health measures during the COVID-19 pandemic, to retain personal data obtained from the certificate.More specifically, in order to allow for the secure issuance and &nbsp;verification of the certificates, the Commission and&nbsp; the Member States&nbsp; shall&nbsp; under Article 4 of the Proposal set up and maintain a trust framework digital infrastructure. Such trust framework shall ensure, where possible, interoperability with technological systems established at international level.Furthermore, personal data &nbsp;personal data may be transmitted/exchanged across borders with the sole purpose of obtaining the information necessary to confirm and verify the holder’s vaccination, testing or recovery status.Finally, the Proposal provides that the &nbsp;authorities responsible for issuing the certificates referred to in Article 3 shall be considered as controllers referred to in Article 4(7) of Regulation (EU) 2016/679.&nbsp;</p><ol start="4"> <li><strong>The EDPS-EDPB joint opinion</strong></li></ol><p>By a joint opinion (04/2021 of 31 March)<a href="/en/news#_ftn4" name="_ftnref4">[4]</a>, the European Data Protection Board (the “<strong>EDPB</strong>”) and the European Data Protection Supervisor (the “<strong>EDPS</strong>”) suggested certain significant actions that are illustrated below:</p><ul> <li>first, to avoid any discrimination based on the health condition of a person, clarification is requested as to the obligation for Member States to accept all three types of digital green certificates – including the vaccination certificate &nbsp;– as well as the unlawfulness of any use of the green certificate that may cause, even <em>de facto </em>only, any such that is &nbsp;discriminatory or in any event disproportionate with respect to the aim pursued;</li> <li>the need is underlined for any national rules legitimising further uses of the digital green certificate to precisely set out the scope and purposes of the processing<a href="/en/news#_ftn5" name="_ftnref5">[5]</a>;</li> <li>it is also requested that the European regulation better defines the purpose of the digital green certificate and provides for a mechanism for monitoring its use by Member States, as well as the introduction of adequate technical and organizational measures safeguarding against falsification of the certificates and any other type of abuse, especially with regard to data belonging to "special" categories<a href="/en/news#_ftn6" name="_ftnref6">[6]</a> and those subject to automated processing;</li> <li>it is also requested to further clarify, also through a specific sunset clause, the illegitimacy of access to the data contained in the certificates once the pandemic emergency has ended and to exclude, by means of a delegated act of the Commission, that the digital green certificate system can be reactivated following suspension for ceased needs, in the presence of a further declaration of the existence of a pandemic from Sars-Cov-2, a variant thereof or similar infectious diseases with epidemic potential;</li> <li>it is requested to clarify whether the creation of the certificate itself or only its issuance is subject to the request of the party and, in order to exclude discriminatory effects, it is suggested to oblige the States, with a regulatory wording strengthened with respect to the current one, to issue the certificate not only in digital but also in paper form, as well as to limit, where technically possible, the verification techniques to those not implying the transmission of personal data;</li> <li>as to the categories of data used, it is stated that the Proposal in its recitals should provide additional substantiation as to the need for data fields such as the vaccine medicinal product, vaccine marketing authorisation holder or manufacturer and number in a series of vaccinations/doses administered, specifying that the amendments that may be made by delegated acts of the Commission should be limited to operating within the subcategories of the catalogue data&nbsp; set out in the Annex;</li> <li>it is also considered preferable to leave to an executive act of the Commission the identification of only the technical details of the measures for the security of the processing, indicating already in the Proposal, thus raising the source, the obligation for controllers and processors to take technical and organizational measures appropriate to the risk of the processing;</li> <li>similarly, in view of the possibility given to the Commission to introduce, by means of its own executive act, specifications on the relationship between data controllers and data processors for the purposes of allocating the respective responsibilities, it is hoped that the Member States will make public a list of the subjects involved in the processing, in order to allow the effective exercise of rights by the data subjects, in compliance with the principle of transparency;</li> <li>it is also hoped for a more precise definition of the maximum periods of retention of data functional to the issuance of the pass, or alternatively the criteria by which to define them, however, not beyond the end of the pandemic;</li> <li>finally, it is suggested to better specify the conditions of legitimacy and the guarantees for the international data transfers, ensuring that data is used exclusively for the purposes set out in the Proposal.</li></ul><p>Said remarks are aimed at an overall, further refinement of proposals that, however, already involve an adjustment of the balance between the protection of personal data, public health needs and freedom of movement, demonstrating, once again, how the discipline of data protection represents an increasingly important prerequisite for a sustainable management of innovation as much as of the emergency.&nbsp;</p><ol start="5"> <li><strong>The action of the Italian Data Protection Authority</strong></li></ol><p>On the subject of vaccination certificates and the related data protection implications, the Italian Data Protection&nbsp; Authority expressed its view as well. The Authority highlights how data on vaccination status is particularly sensitive data and its incorrect processing can seriously impact the life and fundamental rights of people. Such impact, in case of solutions – including digital solutions (e.g. apps) – implemented to meet the need to make information on vaccination status a condition for accessing certain premises or using certain services (e.g. airports, hotels, stations, gyms, etc..) can result in discrimination, violation and unlawful restriction of constitutional freedoms.If one intends to resort to the above solutions, &nbsp;public decision-makers and Italian private operators should, in the Data Protection&nbsp; Authority’s view, focus on the obligation to comply with the rules on the personal data protection.The Data Protection&nbsp; Authority therefore believes that the processing of data relating to the vaccination status of citizens for the purpose of accessing certain premises or using certain services should be regulated by a national rule, in accordance with the principles of&nbsp; personal data protection (particularly, the principles of proportionality, purpose limitation and minimization of data).In the absence of such legal basis, according to the Data Protection&nbsp; Authority, the use, in whatever form, by public and private providers of services to the public, of apps and passes designed to distinguish between the vaccinated and unvaccinated, should be deemed unlawful.In the above context, Decree Law No. 52 of 22 April 2021&nbsp; (so-called “<em>Decreto Riaperture</em>” – “Reopening Decree” –) stands out, which provides for the introduction, on the national territory, of the so-called "Covid-19 green certificates", proving the status of vaccination against SARS-CoV-2 or the recovery from the infection or the performance of a rapid molecular or antigenic test with a negative result.In particular, it is expected that vaccination certificates and recovery certificates will be valid for six months, while &nbsp;a negative Covid-19 test certificate will be valid for 48 hours. The certificates issued in the Member States of the European Union will be recognised as equivalent, as will also those issued in a third country following a vaccination recognized in the European Union.However, as reiterated by the Data Protection&nbsp; Authority, from the wording of the Reopening Decree it can be inferred that the issue of privacy will be dealt with in a subsequent Prime Minister’s &nbsp;Decree, since the decree merely establishes the need for the pass and defines the application areas, but not the approach from a privacy perspective.According to the Authority, however, “<em>it is difficult to discuss the proportionality of the data processed, security measures or retention times with respect to a decree-law that to date lacks any implementation concerning such aspects" </em><a href="/en/news#_ftn7" name="_ftnref7">[7]</a><em>.</em> In other words, there are a number of crucial nodes from a privacy point of view that should be discussed and evaluated before starting to use the certificate.&nbsp;</p><ol start="6"> <li><strong>Conclusion</strong></li></ol><p>In conclusion, it seems clear that data protection is not an obstacle for fighting the Covid-19 pandemic, nor to implement solutions such as the vaccination certificate and, more generally, the Digital Green Certificate.However, it is necessary to provide for solutions that are fully in line with the EU data protection legislation not only for the sake of legal certainty, but also in order to avoid that the Proposal has the effect of directly or indirectly jeopardising the fundamental right to the protection of personal data.In this regard, it would be desirable that EU law may achieve a fair balance between the objectives of general interest pursued by the Digital Green Certificate and the individual interest in self-determination, as well as the respect for the fundamental rights to privacy, data protection and non-discrimination, and other fundamental freedoms such as freedom of movement and residence.At the same time, the need to ensure compliance with the fundamental principles of accuracy, necessity and proportionality in the processing of data, and the need to mitigate risks to the fundamental rights of data subjects, including risks of (unintended) secondary use of the Digital Green Certificate, as well as of direct and/or indirect discrimination, requires that the processing of data contained in vaccination certificates for purposes other than to ensure the free movement of persons to be specifically regulated by national law, in accordance with the principles of personal data protection, &nbsp;so as to achieve a fair balance between the public interest to be pursued and the individual interest in confidentiality.According to the Authority, <em>“We all want and hope to be able to move again soon, but we also don't want the price to be paid for moving again to be a substantial expropriation of privacy”.</em>&nbsp;<a href="/en/news#_ftn8" name="_ftnref8">[8]</a>&nbsp;<em><i>This article is for information purposes only and is not, and cannot be intended as, a professional opinion on the topics dealt with.&nbsp;For further information please contact&nbsp;</i><a href="mailto:ilaria.todaro@advant-nctm.com">Ilaria Todaro</a>&nbsp;and&nbsp;<a href="mailto:claudia.colamonaco@advant-nctm.com">Claudia Colamonaco</a>.</em>&nbsp;&nbsp;<a href="/en/news#_ftnref1" name="_ftn1">[1]</a> The proposal for a Regulation of the European Parliament and of the Council is available at <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52021PC0130" target="_blank" rel="noreferrer">https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52021PC0130</a><a href="/en/news#_ftnref2" name="_ftn2">[2]</a>&nbsp;Council Recommendation on a common framework for the use and validation of rapid antigen tests and the mutual recognition of COVID-19 test results in the EU (2021/C 24/01) (OJ C 24, 22.1.2021, p. 1).<a href="/en/news#_ftnref3" name="_ftn3">[3]</a> The Proposal indeed does not regulate the processing of personal data related to the documentation of a vaccination, test or recovery event for other purposes, such as for the purposes of pharmacovigilance or for the maintenance of individual personal health records. The legal basis for processing for other purposes is to be provided for in national law, which must comply with Union data protection legislation.<a href="/en/news#_ftnref4" name="_ftn4">[4]</a> The text of the Joint Opinion is available at the following link:&nbsp;<a href="https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_edps_joint_opinion_dgc_en.pdf" target="_blank" rel="noreferrer">https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_edps_joint_opinion_dgc_en.pdf</a><a href="/en/news#_ftnref5" name="_ftn5">[5]</a> According to the two boards, indeed,&nbsp; the extension of the application of the digital green certificate to other situations to ease the restrictions currently in place has already been suggested and Member States might plan to introduce it as a de facto requirement, e.g. to enter shops, restaurants, clubs, places of worship or gyms or to use it in any other context as in the employment context. Any such further use of the digital green certificate and its associated framework under a national legal basis should not legally or factually lead to discrimination based on having been (or not) vaccinated or recovered from COVID-19. For this reason, the&nbsp; two boards highlight that any possible further use of the&nbsp; digital green certificate and the personal data related to it at Member States level must&nbsp; be in compliance with the GDPR. This implies the need for a proper legal basis in Member State law, complying with the principles of effectiveness, necessity, proportionality and including strong and specific safeguards implemented following a proper impact assessment, in particular to avoid any risk of discrimination and to prohibit any retention of data in the context of the verification process.<a href="/en/news#_ftnref6" name="_ftn6">[6]</a> The data belonging to special categories are those referred to in Article 9(1) of the GDPR, namely, i “<em>personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation</em>”.<a href="/en/news#_ftnref7" name="_ftn7">[7]</a> So said Guido Scorza, a member of the Board of the&nbsp; Italian Data Protection Authority, a in an Open nnline interview on 22 April 2021.<a href="/en/news#_ftnref8" name="_ftn8">[8]</a> <em>Ibidem</em>.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-5055</guid>
                        <pubDate>Tue, 25 May 2021 04:37:14 +0200</pubDate>
                        <title>Happy Birthday, GDPR!</title>
                        <link>https://www.advant-nctm.com/en/news/buon-compleanno-gdpr</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Regulation (EU) 2016/679, also called “General Data Protection Regulation” (the “<strong>GDPR</strong>”), turns three.The GDPR indeed came into force on 25 May 2018, becoming the global benchmark for personal data protection as well as a convergence factor in the development of standards. With the adoption of the GDPR, the European Union took a leading role in the international data protection landscape, prompting several third countries to align their data protection regulations with the GDPR. New solutions remain to be found that reconcile the protection of personal data with its circulation, for example with regard to relations and trade with the United States after the Schrems II judgment of the European Court of Justice, which invalidated the Privacy Shield.The GDPR has certainly revolutionised the approach of businesses and citizens to privacy, which has gone from being the Cinderella of law to a priority subject, and there are many reasons for this.First on the list of reasons is, certainly, the introduction of a wide range of administrative sanctions. The main change is the duration, scope and severity of some of such fines, which can range (i) from up to 10 million Euros or, alternatively, up to 2% total global &nbsp;turnover in certain cases, or (ii) up to Euro 20 million Euros or up to 4% total global &nbsp;turnover in the most serious cases. In some cases, (the most serious) breaches may even amount to a criminal offence.This has led to an exponential increase in the number of companies adapting to the rules introduced by the GDPR and to a greater level of attention to privacy risk also on the part of top management.Another important novelty was the creation of a new job figure: the Data Protection Officer, also known as the DPO, a new "actor" in the "privacy system" that has contributed significantly to the success of the GDPR. Indeed, the presence of numerous DPOs (there are now thousands of DPOs), apart from the work done within the structure of the controller who made the appointment, has given rise to a peculiar phenomenon: seeking &nbsp;&nbsp;compliance, or any elements of the compliance requirement, from other owners with whom the owner interacts to establish, continue, maintain commercial or other relationships. This caused an unforeseen domino effect, which has triggered a need for compliance that in past years was primarily linked to fearing control by the &nbsp;Authority for the protection of personal data (the "Data Protection Authority").Furthermore, reference must be made to the principles of privacy by design &amp; by default, accountability and the many rights of data subjects, including the right to be forgotten.In Italy, the Data Protection Authority Protection Authority has announced that, from the entry into force of the GDPR to 31 March 2021,</p><ul> <li>59,838 communications&nbsp; of DPO contact details,</li> <li>27,192 complaints and reports, and</li> <li>3,873 personal data breach notifications were received.</li></ul><p>Three years after its entry into application, the GDPR can be considered to be an overall success, though there is still a long challenge ahead: the focus must continue to be on the improvement of implementation and on actions to strengthen the enforcement of data protection laws, and there is a need for strict and effective enforcement of the GDPR and increased awareness of the management of personal data and its fundamental importance in the information society, as well as for increased "digital maturity" on the part of data subjects and increased accountability on the part of owners of large digital platforms, integrated companies, and other digital services, particularly in the areas of online advertising, micro-targeting, algorithmic profiling, science and genomics, and the ranking,&nbsp; &nbsp;dissemination and amplification of content.In conclusion, the GDPR has garnered considerable interest and attention in light of the &nbsp;&nbsp;digital marketplace and big data boom. The EU Institutions have foresightedly overcome the – to say the least – jagged legal system governing data protection among Member States. The GDPR certainly represents a revolution in European data protection law.&nbsp;<em>This article is for information purposes only and neither is nor can be considered as a professional opinion on the topics covered. For further information, please contact&nbsp;<a href="mailto:marco.cappa@advant-nctm.com">Marco Cappa</a>&nbsp;and&nbsp;<a href="mailto:claudia.colamonaco@advant-nctm.com">Claudia Colamonaco</a>.</em></p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-5179</guid>
                        <pubDate>Fri, 11 Dec 2020 05:02:19 +0100</pubDate>
                        <title>Transfers of personal data from the European Union to the United States following the “recommendations” adopted by the European Data Protection Board</title>
                        <link>https://www.advant-nctm.com/en/news/i-trasferimenti-di-dati-personali-dallunione-europea-agli-stati-uniti-a-seguito-delle-raccomandazioni-adottate-dal-comitato-europeo-per-la-protezione-dei-dati-personali</link>
                        <description></description>
                        <content:encoded><![CDATA[<p><em>[<strong>IMPORTANT NOTE: </strong>This document is updated as of 10 December 2020, therefore, should the public consultation on EDPB (Recommendations 01/2020 result in amending the current framework, the content of this article may be further amended and/or supplemented]</em><strong>&nbsp;</strong></p><ol> <li><strong>Introduction</strong></li></ol><p>As is known, on &nbsp;16 July 2020, the Court of Justice of the European Union (hereinafter "<strong><em>CJEU </em></strong>") handed down its judgment in the case referred to as "<em>Schrems II</em>".In its judgment, on the one hand, the CJEU examined the validity of European Commission’s decision 2010/87/EU on standard contractual clauses (hereinafter, "<strong><em>SCCs</em></strong>") and declared its validity, due to the existence of effective mechanisms that make it possible, to ensure compliance&nbsp; a level of protection substantially equivalent to that ensured by Regulation (EU) 2016/679 (hereinafter, the "<strong><em>GDPR</em></strong>") within the European Union (hereinafter the “<strong><em>EU</em></strong>").On the other hand, with the above judgment, the CJEU examined the validity of the “<em>Privacy</em> <em>Shield” decision</em><a href="/en/news#_ftn1" name="_ftnref1">[1]</a>, as the transfers of personal data in the context of the dispute that led to the request for a preliminary ruling took place between the EU and the United States. In this respect, the CJEU held that &nbsp;&nbsp;&nbsp;US domestic law &nbsp;requirements and, in particular, certain programs that allow the US public authorities to access personal data transferred from the EU to the United States for national security purposes, impose limits on the protection of personal data that are not set out in such a way as to satisfy requirements substantially equivalent to those laid down by EU law and that such legislation does not grant data subjects rights enforceable in legal proceedings against US authorities.In light of the above degree of interference with the fundamental rights of persons whose data is transferred to the said third country (i.e. a country that is not part of the EU), the CJEU declared the decision on the adequacy of the <em>Privacy Shield</em><a href="/en/news#_ftn2" name="_ftnref2">[2]</a> invalid.As readers will recall, the alternatives to the <em>Privacy Shield</em> for transfers of personal data from Italy to the United States were explained in our previous article on this subject, by examining the various possible solutions that could be taken into consideration<a href="/en/news#_ftn3" name="_ftnref3">[3]</a>.So, the aim of this paper is to present concrete solutions to companies based in the EU that have hitherto relied on the SCCs<a href="/en/news#_ftn4" name="_ftnref4">[4]</a> to transfer personal data from Italy to the United States, in light of the recent recommendations issued by the European Data Protection Board (hereinafter, the "<strong><em>EDPB</em></strong>").&nbsp;</p><p style="padding-left: 30px;">2.<strong>Introduction to the recommendations on supplementary measures for personal data transfers</strong></p>In order to be able to provide useful guidance tools, on 11 November 2020 , the EDPB adopted “<em>Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data"</em>, and “<em>Recommendations 02/2020 on the European Essential Guarantees for surveillance measures</em>"<a href="/en/news#_ftn5" name="_ftnref5">[5]</a>.Starting with <em>Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data</em>, they effectively describe the activities that data controllers and processors who act as <em>data exporters</em> to third countries must carry out, on the basis of the principles expressed by the aforesaid <em>Schrems II</em> judgment, initially, to map all transfers made outside the European Economic Area (hereinafter referred to as the "<strong><em>EEA</em></strong>") and, thereafter, to assess whether or not it is necessary to adopt supplementary measures to transfer the data in accordance with EU law, to better protect the data subjects.Indeed, as a result of the <em>Schrems II</em> judgment, data controllers and processors are required to verify, on a case by case basis, if the law of the third country ensures a level of protection of the personal data transferred that is essentially equivalent to that guaranteed within the EEA and to adopt any measures that are supplementary to the transfer safeguards envisaged in Chapter V of the GDPR to guarantee effective enforcement of that level of protection, whenever the transfer safeguards alone are not sufficient.The recommendations therefore are meant to assist data controllers and processors acting as data exporters with identifying and implementing appropriate supplementary measures where needed to ensure an equivalent level of protection for the data transferred to third countries.In this way, the EDPB aims to consistently enforce the GDPR and the Schrems II judgment throughout the EEA.&nbsp;<p style="padding-left: 30px;">3.<strong>The content of Recommendations 01/2020</strong></p>As anticipated, Recommendations 01/2020 are devised as a sort of "roadmap" or a series of steps<em>,</em> which data exporters must comply with, in order to assess the need to put in place supplementary measures to be able to transfer personal data outside the EEA in accordance with applicable regulations in the EU, and contain a non-exhaustive list of supplementary measures and conditions for the effectiveness thereof.Therefore, the steps indicated by the EDPB which data exporters must take in compliance with the principle of accountability<a href="/en/news#_ftn6" name="_ftnref6">[6]</a> will be analyzed below:<ol> <li>So, in bearing in mind that the Recommendations are addressed both to data controllers and data processors wishing to identify any sub-processors, the first step indicated is to <strong>map all transfers</strong> of personal data that the controller makes to third countries<a href="/en/news#_ftn7" name="_ftnref7">[7]</a>. Such activity might be particularly complex, especially when several persons are designated as data processors and sub-processors, but it is a first fundamental step to be taken in accordance with the principle of accountability. Precisely because of said complexity, the data processing register required by the data controller pursuant to Article 30 of the GDPR could be of help in this phase. Finally, it should be emphasized that, in this phase, the controller shall necessarily assess compliance with the principle of minimization together with the possible existence of sub-processors in countries outside the EU.</li> <li>Subsequently to the mapping described above, the <strong>transfer tool the transfer relies on</strong> must be verified, amongst those listed in Chapter V of the GDPR<a href="/en/news#_ftn8" name="_ftnref8">[8]</a>. In this respect, the EDPB clarifies that in the presence of an adequacy decision by the European Commission declaring that the third country ensures an appropriate level of protection of the personal data to be transferred, it will not be necessary to carry on any further in the assessment and the transfer will be deemed legitimate, without prejudice to the need for the controller to monitor said decision in order to verify that the same is not revoked or invalidated.<a href="/en/news#_ftn9" name="_ftnref9">[9]</a></li> <li>So, in the absence of an adequacy decision, the third step identified by the EDPB requires the controller to <strong>assess whether the transfer tool is effective</strong><a href="/en/news#_ftn10" name="_ftnref10">[10]</a> with respect to the transfer to be made. In other words, an assessment must be made as to whether the third country has laws or practices that impinge on the efficiency and effectiveness of the appropriate safeguards referred to in Article 46 of the GDPR that legitimize the transfer. In this regard, the EDPB invites data controllers to consider the case where the legislation of the third country allows access to personal data by the public authorities for surveillance purposes. Well, in the event that such legislation is ambiguous or not available to the public, an analysis of the legislation must take into account objective and relevant factors and, finally, must include the necessary checks and be documented according to the principle of accountability.</li></ol><p>At this point, if the data controller (or the data processor) considers that there is no interference and that the transfer tool the transfer relies on is effective, the data controller (or the data processor) will not need to take any supplementary measures and may continue or begin to transfer personal data to the third country. Otherwise, the <strong>supplementary measures</strong> that must be taken to ensure an appropriate level of protection shall be identified.</p><ol start="4"> <li>However, where the assessment referred to in the preceding step identifies obstacles to the effectiveness of the appropriate safeguards, the controller will be obliged to <strong>take supplementary (additional) measures</strong> for the transfer that guarantee the data subjects a level of protection equivalent to that afforded to them in the EU. For this step, Annex 2 to the Recommendations must be taken into account that provides a non-exhaustive list of such measures. Said supplementary measures may be technical (such as: encryption, separation of data processing, pseudonymization, etc.), contractual (such as: transparency of obligations, people’s rights, etc.) and organizational (such as: internal policies, transparency, etc.). In any case, supplementary measures may concern several factors, such as: format of the data, nature of the data, complexity of data processing workflow, number of actors involved in the processing, subsequent transfers, etc.</li></ol><p>In the event that, despite the adoption of supplementary measures, the data transfer does not provide appropriate safeguards for the data subjects, the controller must refrain from transferring the data or, if already in progress, suspend the transfer.</p><ol start="5"> <li>If, on the other hand, the adoption of supplementary measures proves sufficient to ensure the data subjects a level of protection equivalent to that afforded to them in the EU, depending on the transfer tool the transfer relies on, it will be necessary to implement any <strong>formal procedures</strong> required by the supplementary measures to be adopted.<a href="/en/news#_ftn11" name="_ftnref11">[11]</a></li> <li>Lastly, it will be appropriate to <strong>monitor, update and periodically verify </strong>that <strong>the measures</strong> taken remain effective over time<a href="/en/news#_ftn12" name="_ftnref12">[12]</a>.</li></ol><p>Finally, the EDPB clarifies that data exporters must document the assessment process described above, as they are "responsible" for the decisions they make, in line with the principle of accountability.&nbsp;</p><ol start="4"> <li><strong>The content of Recommendations 02/2020</strong></li></ol><p>On the other hand, "<em>Recommendations 02/2020 on the European Essential Guarantees for surveillance measures</em>” are complementary to those described so far.The recommendations on the European essential guarantees<a href="/en/news#_ftn13" name="_ftnref13">[13]</a> provide data exporters with useful elements to determine whether the legal framework governing public authorities’ access to personal data in third countries for surveillance purposes can be regarded as a justifiable interference with rights to privacy and the protection of personal data, and therefore is not in breach of the commitments made by the exporter and importer through the transfer tool relied on among those referred to in Article 46 of the GDPR.&nbsp;</p><ol start="5"> <li><strong>Practical solutions for the transfer of personal data into the United States</strong></li></ol><p>In light of the above and to sum up the matter, what should we do if we use the SCCs with a data importer in the United States?Well, the CJEU has established that the laws of the United States do not ensure a substantially equivalent level of protection.Therefore, as also clarified by the EDPB<a href="/en/news#_ftn14" name="_ftnref14">[14]</a>, the possibility or not of transferring personal data on the basis of the SCCs depends on the outcome of the assessment that the data exporter must carry out, taking into account the circumstances surrounding the transfer and any supplementary measures possibly put in place. The supplementary measures together with the SCCs, in light of a case-by-case analysis of the circumstances surrounding the transfer, should ensure that US law does not interfere with the appropriate level of protection guaranteed by the SCCs and the supplementary measures themselves.If the conclusion is reached that, taking into account the circumstances surrounding the transfer and any supplementary measures, appropriate safeguards cannot be provided, then it is necessary to suspend or terminate the transfer of personal data. However, if the intention is nevertheless to continue to transfer data, the competent supervisory authority must be informed.It is also necessary to understand and consequently assess on a case by case basis, what happens if the condition of legitimacy for the transfer is based on the other transfer tools provided for by Article 46 GDPR or is based on one of the derogations referred to in Article 49 GDPR.In any case, it should be considered that, if the transfer is based on the SCCs, Article 6 of the draft decision by the European Commission, submitted for public consultation, with the draft SCCs integrated on the basis of the decision of the CJEU<a href="/en/news#_ftn15" name="_ftnref15">[15]</a> stipulates that, for a period of one year from the entry into force of the decision and the new SCCs, the exporter and importer of the data may continue to rely on the previous clauses, laid down with Decision 2001/497/EC and updated with Decision 2010/87/EU, to perform any contract concluded before the entry into force of the decision.In this period of time, the contract between the parties may however be integrated with the supplementary measures required to ensure that the transfer takes place with the appropriate safeguards and security.In conclusion, it is evident that the EDPB leaves it up to the data exporter and data importer, to assess whether the level of protection required by EU law is complied with in the third country in order to determine whether the safeguards provided by the chosen transfer tools can be complied with in practice, with the result that only in the event that said level cannot be complied with, will it be necessary to assess whether it is possible to provide supplementary measures to ensure a substantially equivalent level of protection to that envisaged in the EEA.In other words, the supplementary measures will be able to fill the gap, where the transfer tool identified among those of Article 46 of the GDPR alone fails to ensure a level of protection of personal data substantially equivalent to that envisaged in the EEA, provided that the legislation of the third country does not permit interference with the said supplementary measures such as to effectively compromise their effectiveness<a href="/en/news#_ftn16" name="_ftnref16">[16]</a>.&nbsp;<i>This article is for information purposes only and is not, and cannot be intended as, a professional opinion on the topics dealt with.&nbsp;For further information please contact your counsel.</i>&nbsp;&nbsp;<a href="/en/news#_ftnref1" name="_ftn1">[1]</a>Decision 2016/1250 on the adequacy of the protection provided by the EU-US Privacy Shield.<a href="/en/news#_ftnref2" name="_ftn2">[2]</a> The full text of the judgment can be found at the following link: <a href="http://curia.europa.eu/juris/documents.jsf?num=C-311/18" target="_blank" rel="noreferrer">http://curia.europa.eu/juris/documents.jsf?num=C-311/18</a>.<a href="/en/news#_ftnref3" name="_ftn3">[3]</a> All data controllers or data processors could in the <u>short term</u>:</p><ul> <li>reassess the need to transfer personal data overseas and consider the possibility of replacing suppliers based in the United States with suppliers established in the EU or the need to store data at an establishment within the EU;</li> <li>base transfers of personal data on the SCCs, after having established a procedure for assessing the level of data protection in the country or territory to which such data is transferred and impose appropriate technical and organizational measures for such level of protection;</li> <li>rely on the express consent from data subjects, based on the indications of the Data Protection Board;</li></ul><p>whilst, in the <u>medium-long term</u>:</p><ul> <li>for multinational groups, define binding corporate rules and submit them for approval to competent authorities pursuant to and for the purposes of Article 47 of the GDPR; or</li> <li>wait for the issue of codes of conduct or certification mechanisms and then endorse them.</li></ul><p><a href="/en/news#_ftnref4" name="_ftn4">[4]</a> In most cases, companies with headquarters in the United States that do not comply with the Privacy Shield have based the flows of personal data from the EU on the SCCs. The SCCs consist of a set of “standard” clauses that exporters and importers of personal data sign, in order to guarantee, through contractual obligations that comply with the provisions of the GDPR, an appropriate level of protection for personal data that leaves the European Economic Area. So far, the European Commission has approved up to three sets of standard contractual clauses: two for data transfers from data controllers based in the EU to data controllers based outside the EU or the EEA and one for data transfers from data controllers based in the EU to data processors based outside the EU or the EEA. SCCs have not yet been issued that relate to transfers from a data processor based in the EU to a data controller based outside the EU nor that relate to transfers from data processors (or sub-processors) based in the European Union to data processors (or sub-processors) based outside the EU. In this respect, on 12 November 2020, the European Commission published a draft decision, submitted for public consultation until midnight on 10 December 2020 (Brussels time), with the draft SCCs integrated on the basis of the decision of the CJEU, which repeals Decision 2001/497/EC and Decision 2010/87/EU. In particular, the annexes to the draft currently under discussion govern four types of transfers: (i) transfer from controller to controller; (ii) transfer from controller to processor; (iii) transfer from processor to processor; (iv) transfer from processor to controller.<a href="/en/news#_ftnref5" name="_ftn5">[5]</a> Recommendations 01/2020 are subject to public consultation until 21 December 2020 and will be applicable immediately after their publication.<a href="/en/news#_ftnref6" name="_ftn6">[6]</a> Indeed, according to the principle of accountability, envisaged in the GDPR, it is the data controller’s responsibility to be able at all times to demonstrate compliance with the regulations on the processing of personal data.<a href="/en/news#_ftnref7" name="_ftn7">[7]</a> On this subject, the EDPB specifies that remote access from a third country (in support situations) and/or storage in a cloud located outside the EEA is also considered to be a transfer outside the EU.<a href="/en/news#_ftnref8" name="_ftn8">[8]</a> Pursuant to the GDPR, in the absence of an adequacy decision, transfers of personal data to third countries can be carried out only if the data controller or processor transferring the personal data to a third country has provided appropriate safeguards and data subjects have enforceable rights and effective legal remedies. Appropriate safeguards referred to in Article 46 of the GDPR may be provided by: (i) SCCs; (ii) binding corporate rules ("BCR"s); (iii) codes of conduct; (iv) certification processes; (v) <em>ad hoc</em> contractual clauses. In addition to the cases described above, the transfer can also be based on the derogations referred to in Article 49 (including, among others, the explicit consent of the data subject).<a href="/en/news#_ftnref9" name="_ftn9">[9]</a> However, at the same time, it should be pointed out that adequacy decisions do not prevent data subjects from submitting a complaint, nor do they prevent supervisory authorities from bringing a case before a national court in case of doubt about the validity of a decision, so that the national court can then submit a request for a preliminary ruling to the CJEU with a view to examining its validity.<a href="/en/news#_ftnref10" name="_ftn10">[10]</a> The term "effective", means that personal data must be guaranteed a level of protection equivalent to that guaranteed in the EU.<a href="/en/news#_ftnref11" name="_ftn11">[11]</a> In particular, if the transfer is based on the SCCs, as long as the identified supplementary measures do not infringe the rights of the data subjects or contradict the provisions of the SCCs, it will not be necessary to request the supervisory authority’s authorization to be able to take such measures. Otherwise, if the controller wishes to amend the SCCs or if the additional measures identified contrast with the SCCs, the competent supervisory authority’s authorization must be requested, pursuant to Article 43, section 3, letter a) of the GDPR.<a href="/en/news#_ftnref12" name="_ftn12">[12]</a> In particular, the controller must adopt mechanisms to immediately suspend the transfer when the importer is no longer able to comply with the transfer tool relied on and/or the additional measures are no longer sufficient to guarantee an appropriate level of protection for the data subjects.<a href="/en/news#_ftnref13" name="_ftn13">[13]</a> In particular, Recommendations 02/2020 identify the following "essential guarantees": (i) clear, precise and accessible rules for the processing of personal data, (ii) need to demonstrate the necessity and proportionality with regard to the legitimate objectives pursued; (iii) existence of an independent oversight mechanism, (iv) existence of effective remedies for individuals.<a href="/en/news#_ftnref14" name="_ftn14">[14]</a> See the "<em>Frequently Asked Questions on the judgment of the Court of Justice of the European Union in Case C-311/18 - Data Protection Commissioner/Facebook Ireland Ltd and Maximillian Schrems</em>".<a href="/en/news#_ftnref15" name="_ftn15">[15]</a> See Note 4.<a href="/en/news#_ftnref16" name="_ftn16">[16]</a> On this subject, the fact should be considered that clause 3 of the draft decision by the European Commission, submitted for public consultation, with the draft SCCs integrated on the basis of the decision of the CJEU, includes a series of obligations incumbent on the importer in case of requests for access to personal data by the government. Among these is the obligation to notify the exporter of the Authority’s request, and to communicate to the latter as much information as possible on the requests received (number of requests, type of data requested, authority or requesting authority, if the requests have been disputed and the outcome of such disputes, etc.).</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-5292</guid>
                        <pubDate>Wed, 01 Apr 2020 09:23:12 +0200</pubDate>
                        <title>CORPORATE &amp; COMMERCIAL | COVID-19: issues of concern to businesses in the field of personal data protection*</title>
                        <link>https://www.advant-nctm.com/en/news/corporate-commercial-privacy-covid-19-profili-di-interesse-per-le-imprese-in-materia-di-protezione-dei-dati-personali</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>*<strong>IMPORTANT NOTE</strong>: this memorandum is updated as of 31 March 2020 at 1 pm. Since the state of emergency and the related regulatory framework are constantly evolving every day, the contents of this memorandum may be subject to continuous changes.</p><h2>1. Foreword and applicable regulatory framework</h2>Following the increase in cases of Coronavirus COVID-19 infection in various areas of the world in addition to Italy, the Italian Government decided to adopt extraordinary and urgent measures to counter the spread of the virus and to strengthen the national health system, starting with the state of emergency declaration made by the Council of Ministers on 31 January 2020.For further information on the measures adopted by the Italian Government and for any further updates, please consult the relevant institutional websites of the <a href="http://www.governo.it/it/approfondimento/coronavirus/13968" target="_blank" rel="noreferrer noopener">Italian Government</a>&nbsp;and of the <a href="http://www.salute.gov.it/portale/nuovocoronavirus/archivioNormativaNuovoCoronavirus.jsp" target="_blank" rel="noreferrer noopener">Ministry of Health</a>, the web pages set up by the individual Regions as well as the updates for businesses and explanatory notes provided by Confindustria, including those provided by <a href="https://www.assolombarda.it/servizi/assolombarda-e-confindustria/informazioni/coronavirus-covid19" target="_blank" rel="noreferrer noopener">Assolombarda</a>. See also the <a href="https://www.garanteprivacy.it/temi/coronavirus" target="_blank" rel="noreferrer noopener">information page</a> prepared and updated by the Italian Data Protection Authority.<h2>2. Issues of concern to businesses in the field of personal data protection</h2>The protection of personal data is of central importance in the context of the measures to combat the spread of COVID-19.&nbsp;Several of the possible measures to prevent infection that have been considered in the last few weeks (e.g. the provision of questionnaires to ascertain the state of health of workers, the release of self-declarations, the detection of body temperature upon accessing company premises, the adoption of digital contact tracing measures, in respect of which the Government and the Data Protection Authority are currently cooperating) indeed involve the processing of personal data of citizens, and particularly workers, including health data.As is known, the legislation on personal data protection, besides requiring compliance with the general principles set out in Article 5 of Regulation (EU) 2016/679, known as the “<strong>GDPR</strong>” (and, particularly, with regard to the processing at issue, with the principle of proportionality and data minimisation) and with general information and data governance requirements, makes the lawfulness of processing conditional upon the existence of one or more of the conditions under, respectively, Article 6 of the GDPR, as to “common personal data”, and Article 9 of the GDPR, as to special categories of personal data (to be interpreted in the light of the requirements set out by the Authority by means of general authorisations, as amended following the entry into force of the GDPR and the amendments to Legislative Decree No. 196/2003 introduced by Legislative Decree No. 101/2018).On the one hand, the processing of “<span style="text-decoration: underline;">common personal data</span>” (such as, for example, the data coming from the collection and subsequent processing of information about the worker or visitor movements or contacts with people from the infected areas, etc.) can well be justified by the employers’ <span style="text-decoration: underline;">legitimate interest</span> in protecting their personnel from possible risk factors.The processing by employers of health data should be based on the condition set out in Article 9(b) of the GDPR, which allows the processing of health data when it is “<em><span style="text-decoration: underline;">necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law</span>, insofar as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject</em>”.However, the processing of health data in the performance of obligations regarding health and safety at work can - in principle - only be carried out as part of the performance of health surveillance activities, which the Safety Consolidation Act entrusts <span style="text-decoration: underline;">exclusively to the competent doctor</span>. Any collection of health data shall therefore be conditional on the carrying out of a new risk assessment by the employer and the updating, as a result of such assessment, of the company's health protocol. Accordingly, only the competent doctor should be allowed to carry out the processing, either alone or - if necessary - through his or her own expressly authorised assistants.Nevertheless, in consideration of the current emergency, the above regulatory framework has - for the time being - been superseded by the provisions contained in the “<em>Shared Protocol for the regulation of measures to combat and contain the spread of the COVID-19 virus in the workplace</em>” (“<strong>Protocol</strong>”), entered into, pursuant to Article 1, paragraph 1, No. 9 of the Decree of the President of the Council of Ministers of 11 March 2020, by the main employers’ associations and unions. Although such document does not have the force of law but contains the main recommendations shared by the parties aimed at containing the COVID-19, it is unlikely that the activities allowed thereunder may be challenged at a later date by the businesses that have implemented the same, as it was substantially endorsed by the Government and, among others, by the Data Protection Authority.That being said, the Protocol allows businesses to carry out the following activities and, therefore, the related processing operations involving personal data (including health data):<ul> <li>measurement of body temperature before accessing company premises (if higher than 37.5°, access is not allowed), with the legal grounds for that being identified in the obligation to implement the security protocols against the spread of COVID-19 pursuant to Article 1, No. 7, d) of the Decree of the President of the Council of Ministers of 11 March 2020 and the end of the state of emergency being referred to as the conservation period. Temperature data should not, as a rule, be recorded, but it is permitted to identify the person and record such data if the temperature exceeds the threshold set out in order to document the reasons for preventing access to the company's premises. In any case, the relevant information must be provided to the person concerned. The relevant data shall not be disclosed or communicated to third parties, unless expressly provided for by law (for example, if so requested by the health authority for the reconstruction of the chain of close contacts of any person tested positive for COVID-19);</li> <li>request for a statement whereby one confirms that he/she is not coming from at-risk areas and that in the last 14 days has not been in contact with individuals tested positive for COVID-19. Such processing is likewise based on the obligation to implement the security protocols against the spread of COVID-19 pursuant to Article 1, No. 7, d) of the Decree of the President of the Council of Ministers of 11 March 2020. It is also clarified that only the data that is necessary, adequate and relevant for the purpose of preventing the spread of the virus shall be collected and processed (for example, if information is requested on contacts with people tested positive for the virus, it is necessary to refrain from requesting additional information regarding the person tested positive);</li> <li>request for a self-declaration by a person who has developed COVID-19 symptoms while at the company premises by reporting to the personnel department. Following such reporting, the person must be temporarily isolated and the company must notify the competent authority thereof, cooperating with the latter to identify any person who may have had “close contact” with the isolated person. For the duration of the investigation period, the company may ask possible close contacts to leave the premises, as a precautionary measure.</li></ul><p>It should be noted that the above provisions are supposed to apply to external visitors too.Following the adoption of the Protocol, Confindustria prepared an <a href="https://www.rsppitalia.com/media/posts/823/NOTA%20CONF.pdf" target="_blank" rel="noreferrer noopener">explanatory note</a> aimed at assisting companies with the application of the same; in such context, further indications are specified regarding the role of the competent doctor, who is <em>inter alia</em> required to notify the employer of any situations of particular “fragility” and current or past underlying pathologies of employees and, accordingly, the employer shall procure their protection in accordance with privacy requirements.Finally, for the sake of completeness, it is also worth mentioning the “<em>Statement on the processing of personal data in the context of the COVID-19 outbreak</em>”, adopted by the European Data Protection Board (“<strong>EDPB</strong>”) on 19 March 2020.First, the EDPB confirms the principle that data protection rules do not hinder the measures taken in the fight against the coronavirus pandemic. Nevertheless, data controllers and processors must ensure the protection of the personal data of the data subjects, the general principles of law must in any event be respected and, finally, any measure taken in such context must not be irreversible. In other terms, emergency may legitimise restrictions of freedoms provided that such restrictions are proportionate and limited to the emergency period.That being said, concerning data processing in the employment context, the EDPB confirms that the employer may process specific health information concerning employees and visitors, in the COVID-19 context, only to the extent allowed by national law.Concerning, in general, the processing of location data, compliance is required with the provisions of Directive 2002/58/EC (known as the “<strong>e-Privacy Directive</strong>”), which in principle allows the use of location data by the operator when made anonymous or with the consent of individuals. However, Article 15 of said Directive enables Member States to introduce legislative measures to safeguard public security insofar as they are necessary, appropriate and proportionate measures within a democratic society.More specifically, the Authority seems to allow the use by Member State governments of mobile location data as a possible way to monitor, contain or mitigate the spread of COVID-19, which may imply, for instance, the possibility to geolocate individuals or to send public health messages to individuals in a specific area. Nevertheless, public authorities should first try to process location data in an anonymous way, processing data aggregated in a way that individuals cannot be re-identified. When data anonymisation measures are not adopted, the Member State concerned will be required to put in place adequate safeguards such as providing individuals of electronic communication services the right to a judicial remedy. In any event, the Member State should always prefer the least intrusive solutions that are sufficient for prevention purposes.<em>This paper is for information purposes only and is not, and cannot be intended as, a professional opinion on the topics dealt with.&nbsp;For further information please contact your reference lawyer or send an email to the following address: <a href="mailto:corporate.commercial@advant-nctm.com" target="_blank" rel="noopener">corporate.commercial@advant-nctm.com</a> or to the following lawyers: <a href="mailto:p.gallarati@advant-nctm.com" target="_blank" rel="noopener">Paolo Gallarati</a> or <a href="mailto:f.bonino@advant-nctm.com" target="_blank" rel="noopener">Francesca Bonino</a>.</em><em>The following associates contributed to the drafting of this memorandum: <a href="mailto:v.paparozzi@advant-nctm.com" target="_blank" rel="noopener">Virginia Paparozzi</a>, <a href="mailto:g.uras@advant-nctm.com" target="_blank" rel="noopener">Giulio Uras</a> and <a href="mailto:l.lorenzini@advant-nctm.com" target="_blank" rel="noopener">Lucrezia Lorenzini</a>.</em></p>]]></content:encoded>
                        
                            
                                <category>Corporate and Commercial</category>
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-5545</guid>
                        <pubDate>Tue, 09 Apr 2019 06:42:17 +0200</pubDate>
                        <title>Blockchain and shipping insurance</title>
                        <link>https://www.advant-nctm.com/en/news/blockchain-ed-assicurazioni-trasporti</link>
                        <description></description>
                        <content:encoded><![CDATA[<p>Blockchain technology <a href="/en/news#%5B1%5D">[1]</a>has recently become a hot topic. Given its increasing and growing popularity, it seems interesting to see its possible implications in the sector of insurance, especially shipping insurance.Blockchain technology – given its structure involving shared and immutable data being entered without third-party intervention – seems to have a high potential of application in the insurance field.In view of the presence of an immutable and objective software code, which enables some functions once certain pre-determined conditions are met, particular attention should be given to the so-called “smart contracts”. Such contracts, which are based on and work through blockchain technology, are, in essence, automated contracts.So, considering that the insurance business is mainly based on information gathering, blockchain technology can help manage all such information in an easier, safer and faster way, with obvious benefits in terms of cost reduction for the insurance companies using it.At the same time, blockchain technology might enable the solution of two big issues inherent in the insurance business: (i) the fact of customers losing control of their data when put into the insurer’s hands and (ii) repeated data entry. Blockchain technology might resolve these issues through a transparent, reliable and immediate insurance process. This is actually the goal of Etherics, the first insurance based on Ethereum, a platform that allows the sharing of smart contracts.Insurance companies are approaching such technology in different ways, namely, by creating insurance or inter-sector consortiums, making investments in start-ups operating in the blockchain field and partnerships with other companies, or by developing said technology within the company itself.An example of insurance consortium (among AEGON, Allianz, Munich Re, Swiss Re, Zurich) is the project called “Blockchain Insurance Industry Initiative” (B3i). Its mission is to create an ecosystem in which insurance transactions may take place in an automated, integrated and transparent way. The final goal is to make transactions easier not only for the individual company but within the whole insurance value chain, by establishing common operating standards.In practical terms, the insurance contract is generated in the form of a smart contract and published in the blockchain. In this way, the terms of the policy can be seen by each participant in the blockchain. The function of a smart contract is to verify independently the contract terms by obtaining data from multiple sources. As a consequence, there is no more need to fill in plenty of forms, which allows insurance companies to manage all the insurance processes (including claim settlement) in a faster and cheaper way. Moreover, the insured will retain control over its data, once automatically checked and certified by the Company. Indeed, since the insured only has the key to access its data, the insured is also the only person who can authorize access.Therefore, the application of blockchain technology to insurance, especially (but not only) in the shipping sector, might have several advantages in terms of higher efficiency and speed of operational processes, thanks to the automatization of operations occurring in real time (e.g. determination of premiums, management of inspections, etc.). This may entail reduction of costs and a higher level of security, given the reliability and unchangeability of data.Moreover, blockchain technology would also protect information, its origin and traceability as well as its, since only the participants within the blockchain network are in a position to access the data. As a consequence, insurance companies will gain trust from customers. Furthermore, thanks to decentralisation, blockchain technology may allow a more accurate assessment of a customer’s risk profile and the relevant data, once entered, may be stored in a permanent and detailed way without having to be entered repeatedly, which will allow avoiding mistakes and cutting down paper forms.There are, however, certain limits that still need to be solved concerning the application of blockchain technology to insurance.First of all, some partnership issues might arise (considering that potential partners are often competitors). Moreover, there may also be a need of developing a new type of governance and know-how, since not all insurance companies are familiar with blockchain technology.There are also some issues related to the technology itself such as the need for more storage space as a consequence of the constant increase of data, the necessity to analyse cyber risks and improve software stability, considering the large amount of both participants and transactions as well as the need to identify common standards and protocols and create an easily accessible platform notwithstanding the complexities behind it.Some tests are, however, already in place concerning the applicability of blockchain technology to the insurance sector. For example, a popular application was launched by an insurance company in Italy, by which a user can underwrite a blockchain-powered insurance flight delay policy. The insured whose flight is delayed will receive automatic compensation upon landing. The amount is calculated by parametric method based on the historical data of the previous seven years. Any delay is verified automatically and so is compensation, without the need to provide documents to prove the delay or fill-in any paper forms.Another example in the shipping sector is the launch of a new platform based on blockchain and distributed ledger technologies<a href="/en/news#%5B2%5D">[2]</a>, Microsoft Azure infrastructure and ACORD data standards. Such platform, launched by some leading players of the insurance world, is intended to support more than half a million automated transactions and help manage risk for more than one thousand commercial vessels in the first year. One of the most famous Danish shipping companies has played an important role, as a pilot client, in the development of such technology and decided to remain in the platform with its vessels’ portfolio.Even some Lloyd’s Syndicates specialising in maritime risk, together with NTT Data Corporation, have tested blockchain technology to develop new policies in connection with trade, especially maritime trade.Moreover, recent surveys concerning the insurance sector, show that 40% of insurers are expecting to introduce this technology into their business model within two years and more than 80% recognize that blockchain technology and smart contracts will revolutionise the relationships with their partners. However, to benefit from such technology, it is fundamental that companies’ employees, managers and other professionals may acquire the IT skills required for dealing with such technology. There is, however, still much to be done in this respect.Today, several insurance companies prefer to wait for some time until the new technology is more widely used and known. On the other hand, insurtech start-ups are carrying out various experiments. The risk is that traditional insurance companies may lag behind, leaving the market to the new entities emerging from such technological revolution.The new opportunities that may arise from the new technology suggest that it is time to take action by identifying business priorities, selecting the right technology, prioritising cases based on practical applicability and, most importantly, experimenting as much as possible.&nbsp;&nbsp;&nbsp;<i>This article is for information purposes only and is not intended as a professional opinion. For further information, please contact <a href="mailto:o.dallafior@advant-nctm.com">Ottavia Dalla Fior</a> or&nbsp;<a href="mailto:g.boursier.niutta@advant-nctm.com">Guglielmo Boursier Niutta.</a></i>&nbsp;&nbsp;&nbsp;<a name="[1]"></a>[1]A blockchain is set of shared and immutable data. In other words, it is a distributed digital ledger, whose items are clustered in “pages” chained in a chronological order and whose integrity is guaranteed by cryptography.<a name="[2]"></a>[2]In a Distributed Ledger Technology (DLT) network, consisting of a set of participants, each participant has to manage a node of this network. Each node updates the Distributed Ledgers independently but subject to the consensual control of the other nodes.</p>]]></content:encoded>
                        
                            
                                <category>Digital and Data</category>
                            
                        
                        
                    </item>
                
            
        </channel>
    </rss>


