I. Introduction
Italy implements the General Data Protection Regulation (GDPR) through Legislative Decree No. 101 of August 10, 2018, which adapted the existing Italian Personal Data Protection Code (Legislative Decree No. 196/2003) to align with EU Regulation 2016/679 (GDPR). This framework ensures full compliance with European Union data protection requirements.
The Garante per la protezione dei dati personali (Garante), as the national supervisory authority, is responsible for overseeing, guiding, and enforcing the GDPR and its implementing regulations in Italy.
Thus, Italy has put in place a personal data protection system compliant with European Union requirements.
II. Scope of Application
The regulations implementing the GDPR in Italy apply to:
any data controller or processor established in Italian territory;
any organization located outside Italy that offers goods or services to individuals located in Italy, or monitors their behavior within Italian territory.
Regardless of the processing location, as long as it concerns the personal data of individuals located in Italy, the law applies.
It covers automated processing as well as non-automated processing that forms part of a filing system.
Activities of an exclusively personal or domestic nature are not covered by its scope.
III. Principles of Data Processing
Lawfulness, fairness, and transparency: All processing must be based on a clear legal basis and conducted with full transparency.
Purpose limitation: Data can only be used for specific and legitimate purposes.
Data minimization: Only strictly necessary data should be collected.
Accuracy: Data must be accurate and regularly updated.
Storage limitation: Data should only be kept for the strictly necessary period, then deleted or anonymized.
Security and confidentiality: Appropriate technical and organizational measures must be put in place to prevent any breach, alteration, or loss of data.
IV. Data Subject Rights
In accordance with the GDPR and Italian law, individuals have the following rights:
Right to information and access;
Right to rectification;
Right to erasure (right to be forgotten);
Right to restriction of processing;
Right to data portability;
Right to object.
For minors under 14 years old, processing of their data requires the consent of a parent or legal guardian, and information must be provided to them in clear and understandable language.
V. Processor Obligations
Processors must:
strictly comply with the written instructions of the data controller;
implement appropriate security measures;
assist the data controller in fulfilling their obligations, particularly in responding to data subject requests;
notify the data controller without undue delay in the event of a data breach, who must then inform the Garante within 72 hours.
Data controllers must maintain a record of processing activities and conduct a Data Protection Impact Assessment (DPIA) in cases of high risk.
Certain organizations must also designate a Data Protection Officer (DPO) and register with the Garante (Italian Data Protection Authority).
VI. International Data Transfers
When a transfer to a non-EU country is envisaged, the data controller must ensure an adequate level of protection. This can be achieved through:
an adequacy decision by the European Commission;
or the signing of Standard Contractual Clauses (SCCs).
Since the invalidation of the "Privacy Shield" on July 16, 2020, Italian companies must use the new Standard Contractual Clauses adopted on June 4, 2021, or any other legal mechanism.
VII. Control and Enforcement
The Garante has extensive powers, including:
issuing warnings or formal notices;
limiting or prohibiting certain processing operations;
imposing fines of up to 20 million Euros or 4% of global turnover, whichever is higher.
Italian law also allows individuals to provide instructions regarding the use of their data after their death. Failing this, processing must comply with applicable regulations.
The Italian framework for GDPR implementation aims to guarantee individual rights, enhance corporate compliance, and foster trust in the digital environment.
VIII. Contact
Store Name: Glam Furniture Outlet
Phone: +1 469 436 3602
E-mail: info@glamfurnitureoutlet.com
Address: 601 N Belt Line Rd, Irving, TX 75061, United States
Service Hours : Monday - Friday, 9:00 AM - 5:00 PM (CET)