HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Topic · Compliance

Privacy and personal data

The GDPR, the authority that enforces it in Italy, and the principles that matter.

Dossiers in this section

4 dossiers

The topic in brief

The GDPR and who enforces it

The General Data Protection Regulation (EU) 2016/679 (GDPR), in force since 25 May 2018, governs the processing of personal data in the Union. In Italy the supervisory authority is the Garante per la protezione dei dati personali, an independent administrative authority responsible for monitoring application of the regulation under Article 51.

Principles, not just rules

The GDPR revolves around principles: lawfulness and transparency, data minimisation (collect only what's necessary), purpose limitation, accuracy, integrity and confidentiality. And it grants people rights: access, rectification, erasure, portability, objection. A personal-data breach must be notified to the authority, generally within 72 hours where a risk to people's rights is likely.

Security and privacy are the same thing

There's no data protection without data security. The appropriate technical and organisational measures the GDPR requires are the same cyber-hygiene practices this whole site talks about: encryption, access control, incident handling. A data breach is, almost always, first a security incident.

FAQ

Who is the Garante per la protezione dei dati personali?
Italy's independent authority that supervises GDPR application, under Article 51 of the regulation.
Within what deadline must a data breach be notified?
Generally within 72 hours of discovery, where the breach may pose a risk to people's rights and freedoms.