Author Archives: PG Legal

THE ITALIAN DATA PROTECTION SUPERVISOR PRESENTS THE 2020 ANNUAL REPORT

On 2 July 2021, the Italian Data Protection Supervisor presented to Parliament its annual report on its activities in 2020. In the year of the pandemic, the social distancing imposed to prevent the Covid-19 contagion has led us to digitalize most of the fundamental aspects of our lives, from social relations to the performance of […]

COVID-19 Vaccination In The Workplace: The Authority’s Guidelines

On 13 May 2021, the Authority for the Protection of Personal Data (after this referred to as “the Authority”) adopted a policy document on Covid-19 vaccination in the workplace, providing general guidance on processing personal data in this context. This document, therefore, contributes to regulating, from the point of view of personal data protection, the […]

The Case Of The Online Publication Of A Patient’s Data: The Privacy Authority Intervenes

On 15 April 2021, the Authority for the protection of personal data issued three particularly interesting measures concerning an episode of a personal data breach involving a doctor, an AUSL (local health authority), and an association of surgeons. The case concerned a doctor working at the AUSL in question, who had projected during a medical […]

Video Surveillance in the Workplace between Workers’ Privacy and Protection of Company Assets

In its recent judgment no. 3255/2021, the Court of Cassation, Criminal Section III, ruled on whether or not the offense referred to in Article 4 of Law no. 300/1970 (the so-called “Workers’ Statute”) can be committed if an audiovisual system is installed in the workplace without prior agreement with trade union representatives or without the […]

Aggressive Telemarketing And Privacy: Fastweb Fined 4.5 Million Euros

The trend of unlawful data processing by well-known telecommunications operators for unsolicited promotional activities through telephone contact continues. The Italian Data Protection Authority (after this also referred to as “the Authority”) started investigations following numerous reports received from various interested parties, who complained of being contacted with insistence for promotional purposes by or on behalf […]

Data Protection in Corporate Communication: the Use of Electronic Devices and Instant Messaging in Smart Work

One of the effects of the current epidemiological emergency is undoubtedly a rapid increase in the use of technology in daily activities and, in particular, in professional activities. The need to pursue smart working activities has led to increased use of electronic devices and communication tools different from those provided by the company to which […]

SUBJECTIVE FIGURES OF DATA PROCESSING: SANCTION OF THE AUTHORITY TO THE LAZIO REGION FOR FAILURE TO APPOINT A MANAGER

By order no. 9 of 14 January 2021, the Authority for protection personal data imposed a fine of €75,000.00 on the Lazio Region for failing to appoint a company in charge of a call centre service as a data processor. The activity at issue concerned the processing of users’ data through the portal “Salute Lazio,” […]

Cookies And Other Tracking Tools: The Italian Data Protection Authority’s Guidelines

The Italian Data Protection Authority, with provision no. 255 of 26 November 2020, has resolved to launch the public consultation procedure relating to the “Guidelines on the use of cookies and other tracking tools“. The relevant notice was published in the Official Journal of the Italian Republic on 11 December 2020 and will expire thirty […]

DATA BREACH: The Italian Privacy Authority Sanctions UniCredit S.p.A. for 600.000 Euro

With an injunction order dated 10 June 2020, the Privacy Guarantor ordered Unicredit S.p.A. to pay € 600.000 following a given breach caused by abusive access to the personal data of over 700.000 customers. The abusive accesses, concerning a multiplicity of information, had been made using the utilities of some employees of an external business […]