Cookie

Website Terms of Use

af9cb3d8-fd0a-424c-bed5-443fc47c25b6
329b7d3c-41a3-41bd-964d-9873f7036681

ON THE INSPECTION ACTIVITIES OF THE PRIVACY GUARANTOR

By Margherita Grassi Catapano and Francesca Sutti 

6 November 2019

Period of intense inspection activity by the Privacy Authority. As can be seen from the Newsletter of October 28, 2019, from the same Authority, the inspections scheduled with the help of the special unit of the Guardia di Finanza are about a hundred. In the first half of 2019, 779 cases were registered, and another 500 will soon be registered.


The inspection activities are mainly dedicated to certain sectors specifically identified, first and foremost the banking sector. In this sector, the focus is on the flows towards the current account registry: it is reasonable to assume that the Authority will want to verify that appropriate policies and control mechanisms have been established and that processes have been structured for the periodic review and evaluation of the effectiveness of data protection policies.


Since banking data are extremely sensitive for the user, it is crucial that institutions start with risk analysis and consequently with the assessment of the adequacy of the safeguards in place. Furthermore, as with all processing considered to be of significant risk, for example the registry of current account flows, it is often advisable to proceed with an impact analysis (Data Protection Impact Assessment, DPIA).


Among the sectors that will be subject to inspections, one that is particularly sensitive is the processing of health data by private companies.


Since they are able to reveal very private details about a person, health data are included in the broader category of those subject to special processing (art. 9 GDPR) and, therefore, to enhanced protection. More precisely, the GDPR establishes that the processing of personal data carried out for the purpose of protecting the health and physical safety of the data subject or of third parties or of the community must be carried out in accordance with specific provisions.


As with the registry of bank current accounts, here too an impact assessment is advisable, remembering that if, as a result of this process, a residual risk emerges, it is always possible to contact the Authority for its evaluation.


It is not surprising, but in some way alarms companies, the focus on procedures for reporting possible violations of laws, regulations, orders of public authorities or even just internal rules of the organization (so-called whistleblowing). This is an issue that involves any company and the fact that the Authority has listed it among its intervention priorities has caused some concern among the compliance legal teams of many companies. Many are rushing to review their internal reporting management scheme in order to integrate it with privacy management.


The core of both systems is the protection of the confidentiality of the whistleblower, also and above all, to protect them from possible retaliation, but, in fact, a management system compliant with the so-called 231 does not necessarily meet the requirements of data protection legislation. For example, it is necessary to request specific consent for the processing of data from the employee making the report, the general consent is not sufficient. Furthermore, the same must be specifically informed about the retention methods of the data contained in the report and in any documents attached to it.

In any case, a risk assessment of the rights and freedoms of the data subjects involved, and of the proportionality of the system, is always necessary. Incidentally, the Privacy Authority had already focused its attention on whistleblowing regulations in 2009, highlighting a problem in the system designed by 231.


Among the other sectors in the Authority's sights are also marketing and electronic invoicing.
In general, it must be said that this broad inspection activity is certainly carried out for deterrence purposes (as evidenced by the publicity given to it by the Authority itself), but it will be very useful to everyone to derive application principles that can guide companies in this ever more intricate regulatory sector.

Published on "Diritto24"

Milan, Corso Europa, 10 - 20122 - Italy

Phone: 0039 02 877820 Mail: info@wlex.it

Cookie

Website Terms of Use