In the pipeline is the Draft regulation on data protection on the internet.
8
As for Italy, after the first data protection law (n. 675 of 1996) since 2003 it has
enacted a lengthy 186 article long “Privacy Code” (Legislative Decree 2003/196) to
which are attached over fifteen equally long schedules which discipline data protection in various areas (workplace, genetic data, historical and research purposes,
associations, news gathering et cetera).
Since 1997, when the Italian Data Protection Commissioner (Garante per la
Protezione dei Dati Personali) was created, thousands of decisions have been taken
on the basis of individual requests or ex officio procedures.
A certain number of these decisions have been appealed in front of the courts.
One can therefore rely also on a significant body of case law even from the Italian
Court of Cassation.
The role of Italian practices in the formation of EU data protection cannot be
underestimated. Professor Stefano Rodotà, the first Italian data protection Commissioner was the drafter of Article 7 the ECFR. Giovanni Buttarelli, for 10 years the
Secretary general of the Italian Garante, was until 2019 the European Data Protection Supervisor. Many of the issues tacked with by the Article 29 [of Directive 1995/
46] Working Group were set by the Italian Garante which has been regularly liaising
with other European Commissioners.
2 Specific Features and Differences of the Italian Data
Protection
The normative system of data protection is—on its black-letter—mostly harmonized, and it is uselessly pointillistic to detect minor changes in the words used.
What changed is the general legal, ideological, social and economic context in
which such norms are immersed and with which they interact. One therefore has to
look more outside data protection laws to compare systems and understand the
differences between them.
Only “data protection radicals” see data protection as the sun around which all the
other legal institutions revolve. A more realistic approach brings us to consider how,
owing to external factors, same-worded rules may be applied differently in nearby
jurisdictions within the European Union.
One further premise is necessary: practically all activities that fall under data
protection regulations not only are digitalized, but also are put into place on
telecommunication networks, the most important being the internet. One can therefore say that data protection is and must be, necessarily, on the internet. One
8 Proposal for a Regulation of the European Parliament and of the Council concerning the respect for
private life and the protection of personal data in electronic communications and repealing Directive
2002/58/EC (Regulation on Privacy and Electronic Communications) COM/2017/010 final—2017/
03 (COD).
Italian National Report: Data Protection in the Internet
245
8
As for Italy, after the first data protection law (n. 675 of 1996) since 2003 it has
enacted a lengthy 186 article long “Privacy Code” (Legislative Decree 2003/196) to
which are attached over fifteen equally long schedules which discipline data protection in various areas (workplace, genetic data, historical and research purposes,
associations, news gathering et cetera).
Since 1997, when the Italian Data Protection Commissioner (Garante per la
Protezione dei Dati Personali) was created, thousands of decisions have been taken
on the basis of individual requests or ex officio procedures.
A certain number of these decisions have been appealed in front of the courts.
One can therefore rely also on a significant body of case law even from the Italian
Court of Cassation.
The role of Italian practices in the formation of EU data protection cannot be
underestimated. Professor Stefano Rodotà, the first Italian data protection Commissioner was the drafter of Article 7 the ECFR. Giovanni Buttarelli, for 10 years the
Secretary general of the Italian Garante, was until 2019 the European Data Protection Supervisor. Many of the issues tacked with by the Article 29 [of Directive 1995/
46] Working Group were set by the Italian Garante which has been regularly liaising
with other European Commissioners.
2 Specific Features and Differences of the Italian Data
Protection
The normative system of data protection is—on its black-letter—mostly harmonized, and it is uselessly pointillistic to detect minor changes in the words used.
What changed is the general legal, ideological, social and economic context in
which such norms are immersed and with which they interact. One therefore has to
look more outside data protection laws to compare systems and understand the
differences between them.
Only “data protection radicals” see data protection as the sun around which all the
other legal institutions revolve. A more realistic approach brings us to consider how,
owing to external factors, same-worded rules may be applied differently in nearby
jurisdictions within the European Union.
One further premise is necessary: practically all activities that fall under data
protection regulations not only are digitalized, but also are put into place on
telecommunication networks, the most important being the internet. One can therefore say that data protection is and must be, necessarily, on the internet. One
8 Proposal for a Regulation of the European Parliament and of the Council concerning the respect for
private life and the protection of personal data in electronic communications and repealing Directive
2002/58/EC (Regulation on Privacy and Electronic Communications) COM/2017/010 final—2017/
03 (COD).
Italian National Report: Data Protection in the Internet
245
