Category Archives: Privacy & identity

The controller’s responsibility

quando non si applica il gdpr

The Regulation is based on the accountability principle of the controller of the processing. The Accountability principle foresees that the controller should adopt measures which guarantee a processing in accordance with the Regulation and that should demonstrate its concrete actualization and its objective effectiveness. The performance criterion was already known in the Italian legal system […]

The “legal basis” of the data processing and the consent

quando non si applica il gdpr

The Regulation assumes that data processing is illicit if there is no legal basis consenting it. The consent is no longer the only legal basis. There are other basis which are placed on an equal footing to consent. The legal basis is different whether it deals with general or sensitive data. The legal basis for […]

The Information and the rights of the data subject

quando non si applica il gdpr

A fundamental condition for a lawful processing is that the data subject receives an adequate Information on the processing before giving the consent or during the collection if the consent is not necessary. The Information should include the following indications: –       Data subject’s identity; –       Purposes of the processing; –       Judicial base of the processing; […]

Who is the controller of the data processing

quando non si applica il gdpr

  The controller is the one who determines the purposes and the means of the processing. In case of a company, the controller is the company itself and not the person representing it or charged to manage privacy. The controller may appoint one or more external processors to whom assign some particular activities (computer maintenance, […]