Fine anno 2021

The operator of a website that features a Facebook ‘Like’ button can be a controller jointly with Facebook in respect of the collection and transmission to Facebook of the personal data of visitors to its website

Court of Justice of the European Union - PRESS RELEASE No 99/19 - Luxembourg, 29 July 2019. Here the document: https://curia.europa.eu/jcms/upload/docs/application/pdf/2019-07/cp190099en.pdf

29 July 2019 · 1 min · NicFab
GDPR & Privacy

GDPR and privacy: awareness and opportunities - Reasoned analysis of personal data protection between ethics and cybersecurity

“GDPR and privacy: awareness and opportunities. Reasoned analysis of personal data protection between ethics and cybersecurity” is the title of my new book published yesterday by Goware. The volume - with a preface by Giovanni Buttarelli (European Data Protection Supervisor - EDPS) - is available on Amazon both in digital version and paper or printed version. It will soon also be available on other digital stores. This is the abstract: Today we increasingly hear about data protection: but what does it mean, what value do data have and why should they be protected? The book takes us on a journey through the new discipline introduced by EU Regulation 2016/679 (GDPR) to help us understand its historical evolution, the ethical and legal principles that guide it and the obligations related to processing. Central is the theme of IT security, with specific reference to the most current communication methods introduced by the use of the Internet and the development of new tools that offer us connection possibilities through smartphones, email and social networks, posing, however, severe risks, especially for minors. The new technological frontiers (blockchain, IoT, big data, artificial intelligence, drones) are therefore examined, which require necessary awareness also for the purpose of a correct ethical approach to the theme. An impressive regulatory bibliography constitutes a useful guide for those who wish to deepen this fundamental theme of our time. The theme of awareness in the field of personal data protection is truly relevant. On this topic I refer to the post published a few days ago on this blog. ...

28 May 2019 · 2 min · NicFab
Fine anno 2021

GDPR one year later: awareness firstly

After one year, many people make evaluations, while others forecast or organise events. My purpose is not celebratory but purposeful and prodromal: what are the aspects concerning the protection of personal data on which it would be appropriate to reflect and which deserve further investigation? One of the most relevant aspects is undoubtedly the “awareness” that it means “to have exact consciousness about himself”. Among the principles laid down in the GDPR, the “accountability” (art. 5, paragraph 2) is the central pillar. The data controller or the data processor who has to respect the “accountability” principle must necessarily be aware of “having a perfect consciousness about himself” on the knowledge of the GDPR rules and principles. It is not about a purely technical-juridical knowledge that would favour the jurist in the application of the laws. Reading the GDPR often goes beyond the qualification of the rules of conduct that are part of the legal system: there is much more over. We cannot ignore the fundamental rights provided for by the European Charter and by the Convention 108 plus. ...

25 May 2019 · 5 min · NicFab
Fine anno 2021

The ethics of data: an interview with Nicola Fabiano

Some weeks ago I gave an interview to Ingenium Magazine and it has been published here. Grateful to Sonia Montegiove.

23 May 2019 · 1 min · NicFab
European Data Protection Day 2019

European Data Protection Day 2019

occasion for reflection: the scenario relating to personal data, ethics, AI, robotics The European Data Protection Day (Data Protection Day), which is celebrated on January 28 of each year (in Italy the Data Protection Authority has organized an event to be held in Rome on January 29), offers the opportunity for some reflections. The issue of personal data protection is extremely important and should not be underestimated. Technologies are used daily especially through computers, smartphones, tablets and other devices. We provide our personal data to enjoy goods and/or services and the data controller is required to comply with the provisions of the GDPR and the privacy code, as amended by Legislative Decree 101/2018. Moreover, the issue of the transfer of personal data abroad or to international organizations assumes further importance, especially in the use of services or technologies whose infrastructures are not located within the European Union. ...

21 January 2019 · 5 min · NicFab
Identity theft

Identity theft, GDPR and personal data protection

Contribution by Nicola Fabiano and Filippo Bianchini The issue of identity theft is not new, since the phenomenon is ancient. In Italy, a definition of the phenomenon was provided by Article 30-bis of Legislative Decree no. 141 of 13/8/2010, concerning “Implementation of Directive 2008/48/EC on credit agreements for consumers, as well as amendments to Title VI of the Consolidated Banking Act (Legislative Decree no. 385 of 1993) regarding the regulation of operators in the financial sector, agents in financial activities and credit brokers”. The aforementioned Article 30-bis (entitled “Definitions”) states: ...

18 October 2018 · 6 min · NicFab
Modified privacy code (Legislative Decree 196/2003): the main novelties

Modified privacy code (Legislative Decree 196/2003): the main novelties

Legislative Decree 10/08/2018, no. 101 was published in the Official Gazette no. 205 of 4/9/2018, containing “Provisions for the adaptation of national legislation to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)”. ...

4 September 2018 · 5 min · NicFab
GDPR

GDPR: When the appointment of the representative pursuant to Article 27 is mandatory

EU Regulation 2016/679, relating to the protection of natural persons with regard to the processing of personal data, introduces the figure of the representative who, in Article 4, paragraph 1, is defined as follows: “17) ‘representative’: a natural or legal person established in the Union who, designated by the controller or the processor in writing pursuant to Article 27, represents them with regard to their respective obligations under this Regulation”. ...

31 August 2018 · 4 min · NicFab
GDPR Map

Map of EU Regulation 2016/679 - GDPR

I created the attached map showing the structure of the GDPR.

25 March 2018 · 1 min · NicFab
CNF Course

Advanced training course on personal data protection for professional training of the Data Protection Officer (DPO)

On January 12, 2018 the advanced training course on personal data protection for professional training of the Data Protection Responsible, better known as Data Protection Officer (DPO), will begin. The course - which enjoys the patronage of the Data Protection Authority - was activated in implementation of the Memorandum of Understanding of April 28, 2017, signed between the National Bar Council (CNF) and the National Council of Engineers (CNI), on a project by the Italian Foundation for Forensic Innovation (FIIF) and thanks to the interest of the two National Councilors Lawyer Carla Secchieri and Engineer Luca Scappini who assume its coordination. ...

4 January 2018 · 4 min · NicFab