Categories: Insights, Practice

Tag: Data Breach


2 Sep 2019

The form for notifying the Data Breach is ready

With Regulation 157 of 30 July 2019, which fully replaces all previous measures on the subject, the Guarantor for the Protection of Personal Data has provided the form for reporting computer incidents. Data Breach Pursuant to Article 33, paragraph 1, of the EU Regulation 2016/679 on the protection of personal data (the “GDPR“), the Data Controller is obliged, without undue delay and, where possible, within 72 hours of becoming aware of it, to notify the breach to the Supervisory Authority unless the breach of personal data is unlikely to pose a risk to the rights and freedom of individuals. In addition, the Data Controller who becomes aware of a possible violation is obliged to inform the owner in a timely manner so that he can take action. Notifications to the Guarantor made after the 72-hour period must be accompanied by the reasons for the delay. Furthermore, if the breach involves a high risk to the rights of the individuals, the holder must communicate it to all the persons concerned, using the most appropriate channels, unless he has already taken measures to reduce its impact. The Data Controller, regardless of the notification to the Guarantor, documents all breaches of personal data, for example by preparing a special register. This documentation allows the Control Authority to carry out any audits on the compliance with the regulations. Content of the notification to the Guarantor Pursuant to Article 33, paragraph 3, of the GDPR, the notification to the Guarantor must include the following information:
  • describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of records of the personal data concerned;
  • indicate the name and contact details of the Data Protection Officer (DPO) or other point of contact from whom more information can be obtained;
  • describe the likely consequences of the personal data breach;
  • describe the measures taken or proposed by the controller to remedy the personal data breach and also, where appropriate, to mitigate its possible adverse effects.
The above information is given in the form attached to the Regulation of 30 July 2019. Notification must be made via PEC to the following address  protocollo@pec.gpdp.it and must be digitally signed or signed by hand. In the latter case, the notification must be submitted together with a copy of the signatory’s identity document. The subject of the message must contain the words “NOTIFICATION OF VIOLATION OF PERSONAL DATA” and, optionally, the name of the data controller. In the event of a breach of the notification procedures, a financial penalty of up to €10 million or, in the case of companies, up to 2% of the total global annual turnover is applied.
Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Sep 2026

Company files deleted from the PC: dismissal lawful even without proof of damage

The matter arises from the disciplinary dismissal of an employee performing general secretarial duties who, upon returning the company computer following a change in her duties, handed back…

1 Sep 2026

Overtime work: a summary schedule is not enough, employees must provide strict evidence of both the hours worked and the extent of the overtime performed

With order no. 20700 of 18 June 2026, the Italian Supreme Court once again addressed the issue of overtime work, reiterating that employees claiming overtime pay must strictly…

1 Sep 2026

Did you know that… an individual allowance that has remained unchanged for years may become non-absorbable?

In judgment no. 24475 of 5 August 2026, the Employment Section of the Italian Supreme Court confirmed that an individual allowance (i.e. “superminimo”), although normally subject to the…

3 Aug 2026

Pay Transparency: the first requests from employees are starting to arrive (Il Sole 24 Ore, 3 august 2026 – Vittorio De Luca)

Two months after the decree. Since Legislative Decree 96/2026 came into force on 7 June, according to a flash survey conducted by GIDP, 8% of HR directors have…

30 Jul 2026

Corporate controls and data protection: what balance?

A recent judgment of the Court of Pisa, No. 800 of 13 June 2026, addresses a topic of particular interest for companies: the delicate balance between the protection…

30 Jul 2026

Unfair dismissal and reinstatement: the employee must repay the payment in lieu of notice

With order no. 22187 of 28 June 2026, the Italian Supreme Court addressed the issue of whether payment in lieu of notice paid to an employee must be…