The GDPR Compliance Decree
The long-awaited legislative decree adapting national legislation to the General Data Protection Regulation (GDPR) has finally been published.
Legislative Decree No. 101 of August 10, 2018, enacted pursuant to Article 13 of the European Delegation Law 2016-2017 (Law No. 163 of October 25, 2017), aims to harmonize the Privacy Code with European legislation, which became fully operational on May 25.
The Privacy Code is not completely repealed (as envisaged in an initial draft of the decree) but remains in force, with amendments aimed at harmonizing it with the principles established in the General Data Protection Regulation, first and foremost that of accountability.
The provision requires the Privacy Guarantor to define simplified procedures for fulfilling data controller obligations with regard to micro, small, and medium-sized enterprises.
The provisions of the Privacy Guarantor continue to apply, as they are compatible with the GDPR and the decree itself.
For the first eight months from the date of entry into force of the decree, the Data Protection Authority must take into account, for the purposes of applying administrative sanctions and to the extent compatible with the provisions of the GDPR, the initial application phase of the sanctions provisions.