Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Part I Title I: National rules alongside the GDPR (arts 1 to 2-septiesdecies) – Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) Art. 2-quaterdecies.1: Art. 2-quaterdecies.1 Microenterprises: notify breaches through the Garante's simplified procedure

Businesses with fewer than five employees use, to meet the breach notification obligation of GDPR art. 33, a specific notification procedure set by the Garante, with guided self-assessment tools and a simplified assistance channel. Added by art. 12(1) of Decree-Law 19 February 2026 no. 19, in force 20 February 2026; the Garante's implementing measure governs the procedure.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part I Title I: National rules alongside the GDPR (arts 1 to 2-septiesdecies) – Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.