The Garante, Experian and the system that scores you
On 3 July 2026 Italy's data protection authority, the Garante, ordered Experian Italia S.p.A. to pay 120,000 euros, in a decision touching bedroc…
Topic · Compliance
The GDPR, the authority that enforces it in Italy, and the principles that matter.
On 3 July 2026 Italy's data protection authority, the Garante, ordered Experian Italia S.p.A. to pay 120,000 euros, in a decision touching bedroc…
Italy's data protection authority (the Garante) fined Wind Tre €1,715,600 for serious shortcomings in system security. According to the authority…
"You have 72 hours to notify" is the line everyone repeats and few explain. This explainer lines up what the GDPR actually says: when the cl…
On 19 February 2026 Mississippi's largest health system went dark: 35 clinical sites shut, the state's only Level I trauma center paralysed.…
The General Data Protection Regulation (EU) 2016/679 (GDPR), in force since 25 May 2018, governs the processing of personal data in the Union. In Italy the supervisory authority is the Garante per la protezione dei dati personali, an independent administrative authority responsible for monitoring application of the regulation under Article 51.
The GDPR revolves around principles: lawfulness and transparency, data minimisation (collect only what's necessary), purpose limitation, accuracy, integrity and confidentiality. And it grants people rights: access, rectification, erasure, portability, objection. A personal-data breach must be notified to the authority, generally within 72 hours where a risk to people's rights is likely.
There's no data protection without data security. The appropriate technical and organisational measures the GDPR requires are the same cyber-hygiene practices this whole site talks about: encryption, access control, incident handling. A data breach is, almost always, first a security incident.