Categories: Insights, Practice

Tag: Data Breach


2 Sep 2019

The form for notifying the Data Breach is ready

With Regulation 157 of 30 July 2019, which fully replaces all previous measures on the subject, the Guarantor for the Protection of Personal Data has provided the form for reporting computer incidents. Data Breach Pursuant to Article 33, paragraph 1, of the EU Regulation 2016/679 on the protection of personal data (the “GDPR“), the Data Controller is obliged, without undue delay and, where possible, within 72 hours of becoming aware of it, to notify the breach to the Supervisory Authority unless the breach of personal data is unlikely to pose a risk to the rights and freedom of individuals. In addition, the Data Controller who becomes aware of a possible violation is obliged to inform the owner in a timely manner so that he can take action. Notifications to the Guarantor made after the 72-hour period must be accompanied by the reasons for the delay. Furthermore, if the breach involves a high risk to the rights of the individuals, the holder must communicate it to all the persons concerned, using the most appropriate channels, unless he has already taken measures to reduce its impact. The Data Controller, regardless of the notification to the Guarantor, documents all breaches of personal data, for example by preparing a special register. This documentation allows the Control Authority to carry out any audits on the compliance with the regulations. Content of the notification to the Guarantor Pursuant to Article 33, paragraph 3, of the GDPR, the notification to the Guarantor must include the following information:
  • describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of records of the personal data concerned;
  • indicate the name and contact details of the Data Protection Officer (DPO) or other point of contact from whom more information can be obtained;
  • describe the likely consequences of the personal data breach;
  • describe the measures taken or proposed by the controller to remedy the personal data breach and also, where appropriate, to mitigate its possible adverse effects.
The above information is given in the form attached to the Regulation of 30 July 2019. Notification must be made via PEC to the following address  protocollo@pec.gpdp.it and must be digitally signed or signed by hand. In the latter case, the notification must be submitted together with a copy of the signatory’s identity document. The subject of the message must contain the words “NOTIFICATION OF VIOLATION OF PERSONAL DATA” and, optionally, the name of the data controller. In the event of a breach of the notification procedures, a financial penalty of up to €10 million or, in the case of companies, up to 2% of the total global annual turnover is applied.
Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

1 Oct 2026

Corporate e-mail and defensive monitoring: when the GDPR and employment law lead to different outcomes 

The Piaggio case clearly illustrates how the same set of facts can give rise to profoundly different assessments depending on the perspective adopted. In its decision of 13…

1 Oct 2026

NASpI and Reinstatement: the Employee’s Election Causes Loss of the Benefit 

Headnote   In its recent judgment No. 24981 of 3 September 2026, the Italian Supreme Court held that, where a dismissal is set aside with an order of reinstatement…

1 Oct 2026

Did you know that… testimony given in court may have disciplinary relevance and, in the most serious cases, justify dismissal? 

The Italian Supreme Court, Labour Section, by order no. 25687 of 22 September 2026, addressed the issue of the disciplinary relevance of statements made by an employee in…

29 Sep 2026

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need…

24 Sep 2026

The concept of “territorial scope” in a non-compete agreement (Top24 Lavoro Ai – Il Sole 24 Ore, 24 September 2026 – Vittorio De Luca and Alessandro Ferrari)

Interpretative issues in light of the most recent case law on the nullity of non-compete agreements due to the indeterminacy of territorial scope By an order issued on…

16 Sep 2026

Did you know that… repeated violations of company procedures may justify the dismissal of a store manager?

The Italian Supreme Court (Labour Section), in Order No. 25231 of 11 September 2026, upheld the lawfulness of the dismissal for just cause of a store manager who…