Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018)
Italy Codice Security + DPO

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) ItalyCodice-Security-CPO-DPO-PublicBodies-BreachNotification-Art31-34-DPIA-ROPA-JointControllers-Processors: Italy Codice Security - Article 31 Designation of CPO + Italian DPO Requirements + DPO Mandatory for Public Bodies + Article 34 Breach Notification + DPIA + ROPA + Joint Controllers + Processors + Italian-Specific Requirements

Italian Codice Privacy security framework supplements GDPR Article 32 with Italian-specific obligations. (1) Article 31 Designation of Chief Privacy Officer (CPO) / Data Protection Officer (DPO): mandatory for (a) public authorities and bodies (with sole exemption for courts in judicial capacity); (b) controllers/processors core activities consisting of regular and systematic monitoring of data subjects on a large scale; (c) controllers/processors core activities consisting of large-scale processing of special categories of data + criminal data. Italian-specific clarifications include (a) Italian Garante Decision on DPO 2018; (b) Italian public bodies must appoint DPO from public administration personnel or external; (c) DPO independence + reporting to highest management; (d) sufficient resources + qualifications + access to data + cooperation with Garante; (e) Italian Government DPO portal for public bodies. Italian DPO often called Responsabile della Protezione dei Dati (RPD). (2) Article 34 Notification of Personal Information Breach: per GDPR Article 33 + 34 + Italian Garante operational guidance - 72-hour breach notification to Garante + Italian notification template + Italian language + Italian Garante portal + content per GDPR + Italian-specific elements + breach categories taxonomy + reporting threshold + low-risk exemption + ongoing notification update + remedial actions report + lessons learned + collaboration with Italian Cyber Security National Agency (ACN Agenzia per la Cybersicurezza Nazionale). (3) DPIA Data Protection Impact Assessment per GDPR Article 35 + Italian Garante DPIA Methodology + Italian DPIA threshold list updated periodically + including (a) systematic large-scale monitoring of public areas; (b) large-scale processing of special categories; (c) automated decision-making with legal effects; (d) systematic evaluation including profiling; (e) processing of vulnerable data subjects (minors + workers + patients); (f) innovative technology + AI/ML profiling; (g) Italian-specific DPIA requirements for AI systems. (4) ROPA Records of Processing Activities per GDPR Article 30 + Italian-specific requirements including (a) Italian language; (b) Italian Garante template; (c) inter-agency + cross-border + transfer details; (d) integration with Italian sectoral records. (5) Joint Controllers Arrangements per GDPR Article 26 + Italian Garante guidance + Italian Civil Code + Italian Civil Procedure jurisdiction + transparent allocation of responsibilities + data subject contact point + complaint handling. (6) Processor (Responsabile del Trattamento) Contracts per GDPR Article 28 + Italian Garante Standard Contractual Clauses + Italian language + Italian governing law where applicable + subcontractor flow-down + audit rights + breach notification timelines + return/deletion at end. (7) Italian-Specific Security Standards: Italian Garante guidelines on (a) password security + biometric authentication; (b) network security + intrusion detection; (c) anti-malware; (d) backup + DR; (e) audit logging + retention; (f) employee training; (g) physical security; (h) third party assurance. (8) Italian Cyber Security Coordination: Italian Agency for National Cybersecurity (ACN Agenzia per la Cybersicurezza Nazionale) cybersecurity guidelines + CERT-AGID + Italian National CSIRT + critical infrastructure protection + Decree-Law 105/2019 National Cybersecurity Perimeter + DORA + EU NIS2 implementation. Coordinates with GDPR Articles 24 + 25 + 28 + 30 + 32 + 33 + 34 + 35 + 37 + 38 + 39 + Italian Garante DPO Guidelines + DPIA Methodology + ROPA Template + Standard Contractual Clauses + ACN Italian Cybersecurity + DORA + EU NIS2. Italy Codice Security + DPO applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.