Alessandro Del Ninno
Areas of practice
Digital Regulation of Personal and Non-Personal Data.
Specialised Legal Services on Personal and Non-Personal Data.


Digital Regulation of Personal and Non-Personal Data

Personal, industrial and technical data are now integral to companies’ assets and strategic processes. They are collected through digital platforms, connected products, cloud infrastructures, artificial intelligence systems, business applications, communications networks, and relationships with customers, employees, suppliers and business partners. Their proper management requires companies to reconcile innovation, economic exploitation, security, individual rights and the protection of corporate know-how.

Attorney Alessandro del Ninno advises companies, corporate groups, regulated entities and public bodies on the integrated management of personal and non-personal data, coordinating the GDPR and the Italian Data Protection Code with the Data Act, the Data Governance Act and the other European rules applicable to digital services, artificial intelligence, cybersecurity, cloud computing and data sharing.

The assistance provided is not limited to preparing mandatory documentation. Each engagement is tailored to the organisation’s actual operations and is designed to translate regulatory requirements into procedures, responsibilities, contractual arrangements and practical solutions. The Data Act governs, among other matters, access to and use of data generated by connected products, business-to-business data sharing, data-related contracts, switching between cloud service providers and interoperability. The Data Governance Act regulates the re-use of protected data held by public-sector bodies, data intermediation services and data altruism; in Italy, it has been implemented by Legislative Decree No. 144 of 7 October 2024. Where data flows include personal data, these rules must be applied in conjunction with the GDPR.

Governance, Audits and Compliance Programmes

Assistance may begin with a comprehensive audit of the organisation or with a review of a specific product, service, platform or process. The analysis identifies which data are collected or generated, their sources, who has access to them, where they are stored, the purposes for which they are used and the external parties involved.

The audit makes it possible to verify the correct classification of personal, pseudonymised, anonymised, industrial and non-personal data, as well as to identify mixed datasets in which different categories are closely interrelated. The review covers data protection roles, legal bases, access and usage rights, contractual restrictions, security measures, retention periods and any international transfers.

The engagement results in a practical mapping of data flows, a matrix of roles and responsibilities, the identification of critical issues and a prioritised compliance roadmap. The client therefore receives not merely formally compliant documentation, but a governance framework that is verifiable, sustainable and aligned with its organisational structure.

GDPR Compliance and Personal Data Protection

Attorney Alessandro del Ninno advises controllers and processors on the design and review of compliance frameworks under the GDPR, the Italian Data Protection Code and the measures adopted by the Italian Data Protection Authority, taking account of the guidance issued by the European Data Protection Board.

The services provided include the assessment of legal bases and the preparation and tailoring of privacy notices, records of processing activities, processor and sub-processor agreements, joint-controllership arrangements and instructions for authorised personnel. Assistance also covers internal policies, retention and deletion procedures, consent-management frameworks and organisational systems designed to ensure that decisions are properly documented and traceable.

Where processing is based on legitimate interests, the assistance includes the preparation of a Legitimate Interests Assessment, covering the identification of the interest pursued, the necessity test, the balancing of that interest against individuals’ rights and the adoption of appropriate mitigating measures. The EDPB Guidelines 1/2024, adopted as Version 1.0 and subsequently submitted to public consultation, provide operational criteria for carrying out that assessment and require a concrete examination of the processing, its context and any less intrusive alternatives.

Particular attention is devoted to processing involving health, biometric, genetic or criminal-conviction data, vulnerable individuals, profiling and automated decision-making. For processing operations likely to result in a high risk, Data Protection Impact Assessments are prepared on the basis of the actual functioning of the systems, the risks to individuals and the effectiveness of the proposed risk-mitigation measures.

Assistance may also include assessing participation in codes of conduct and certification mechanisms under Articles 40 and 42 GDPR, taking into account their actual usefulness in light of the processing activities carried out, the relevant business sector and the organisation’s accountability requirements.

Privacy by Design, Security and Data Lifecycle Management

Data protection is embedded from the earliest stages of the design of new products, applications and services. The assistance supports Legal, Compliance, IT, Cybersecurity, Marketing, HR and Procurement teams in defining specifications, selecting suppliers and preparing contractual documentation.

The review covers authentication and authorisation mechanisms, segregation of environments, access controls, encryption, pseudonymisation, logging systems, backups, business continuity and deletion procedures. Pseudonymisation is assessed not as an abstract safeguard, but in light of who may access the additional information, the risk of re-identification and the specific risk to be mitigated. The EDPB Guidelines 01/2025, adopted in their initial version and submitted to public consultation, examine the role of pseudonymisation as a data protection and security measure and as a means of implementing the principles of privacy by design and by default.

Assistance also includes the development of data-retention policies, ensuring that retention periods are linked to the actual purposes pursued, statutory requirements and evidentiary needs, thereby avoiding the indiscriminate accumulation of information that is no longer required.

Artificial Intelligence, Algorithms and the Use of Datasets

The development and deployment of artificial intelligence systems require a coordinated assessment of data provenance, conditions of use, individual rights and the responsibilities of the various operators involved.

The assistance covers data used to train, validate, test and operate models, the quality and representativeness of datasets, discrimination risks, algorithmic transparency and output management. It also addresses the use of generative models, the retention of prompts, the re-use of user interactions to improve services and the contractual terms imposed by technology providers.

Particular attention is paid to web scraping and the large-scale collection of online information. The fact that data are publicly accessible does not automatically mean that they may freely be collected and used for different purposes, especially where personal data or information protected by third-party rights are involved. The Italian Data Protection Authority has issued specific guidance on measures that website and platform operators may adopt to protect personal data published online against large-scale collection for the training of generative AI systems.

The services provided also include drafting corporate AI-use policies, assessing suppliers, defining internal responsibilities, regulating permitted uses and integrating GDPR compliance with the obligations arising under the AI Act.

The Data Act, Connected Products and Data Generated Through Use

Attorney Alessandro del Ninno advises manufacturers, service providers, distributors, business users and technology operators on the application of the Data Act to connected products and related services falling within the scope of the Regulation.

Depending on the characteristics of the relevant product and related service, the analysis may concern industrial machinery, vehicles, medical devices, smart appliances, energy systems and IoT infrastructures. For the purposes of the Data Act, it is not sufficient for a product merely to generate information. It is necessary to establish that the product obtains, generates or collects data concerning its use or environment and is capable of communicating those data through an electronic communications service, physical connection or on-device access, in accordance with the statutory definition of a connected product.

The assistance identifies which product data and related service data actually fall within the scope of the Regulation. The assessment focuses in particular on readily available data, namely data that the data holder obtains or can lawfully obtain from the connected product or related service without disproportionate effort going beyond a simple operation, together with the metadata necessary for their interpretation and use. Such data are distinguished from information inferred or derived through additional processing, further investment or proprietary algorithms, which may fall outside the access right or be subject to a different contractual regime.

The assistance then defines the means by which users may access the data or request their disclosure to a third party. This includes pre-contractual information, access interfaces, APIs, export formats, user authentication and the processes required to respond to requests in a timely, secure and properly documented manner.

The service also covers coordination with the GDPR where product-generated data relate to natural persons, as well as the protection of trade secrets and confidential technical information. The objective is to comply with access and sharing obligations without unduly exposing the company’s know-how, proprietary architectures or industrial strategies.

The possible presence among user-designated recipients of undertakings designated as gatekeepers under the Digital Markets Act is also assessed. The Data Act excludes such entities from receiving data as third parties selected by the user under the access mechanism established by the Regulation.

Data Contracts and Protection of Corporate Information Assets

A central part of the practice concerns the drafting and negotiation of agreements governing access to, use of and sharing of data.

Attorney Alessandro del Ninno prepares and reviews data-sharing agreements, data licences, terms applicable to users of connected products, agreements between data holders and data recipients, and clauses governing relationships with industrial partners, distributors, maintenance providers, technology suppliers and group companies.

These agreements define which data are made available, in what format, at what frequency, for which purposes and subject to which restrictions. They regulate further use, the aggregation or combination of data, disclosure to third parties, liability for unauthorised use, security measures and obligations following termination of the relationship.

Where a data holder is required under the Data Act or other Union law to make data available to a recipient in a business-to-business context, the applicable terms must be fair, reasonable, non-discriminatory and transparent. These requirements do not apply indiscriminately to every access request or voluntary agreement, but to the mandatory data-sharing scenarios governed by the Regulation.

Assistance includes determining and negotiating any compensation payable for the mandatory provision of data, taking account of the costs directly related to making the data available, the investments required to collect and generate the data and the more favourable rules applicable, where relevant, to microenterprises, small and medium-sized enterprises and non-profit research organisations.

Contractual terms are also assessed for compliance with the prohibition on unilaterally imposed unfair terms relating to data access and use, liability and remedies. The review takes account of the parties’ actual bargaining power, the nature of the relevant clause and whether the contract can remain in force without the potentially invalid provision.

When drafting agreements, account is also taken of the non-binding model contractual terms for data access and use and the standard contractual clauses for cloud computing contracts published by the European Commission in 2025. Their use is voluntary, and the models may be adapted by the parties to reflect the characteristics of the product, service and market and the actual allocation of risk. The EDPB’s earlier statement concerned the draft submitted for consultation before the Commission published the final models.

The advice also addresses coordination with copyright, the sui generis database right, trade-secret law, competition law and consumer protection. In particular, the existence and scope of rights in datasets, the lawfulness of contractual restrictions, the potentially exclusionary effects of data-sharing agreements and the accuracy and completeness of pre-contractual information provided to consumers are assessed.

Cloud Services, Switching and the Prevention of Vendor Lock-In

The Data Act has a significant impact on contracts for cloud services and other data-processing services.

Attorney Alessandro del Ninno advises clients on the negotiation and review of SaaS, PaaS and IaaS agreements, with particular regard to exit arrangements, migration to another provider, the return of data, deletion of residual copies and operational continuity during the switching process.

The review covers exportable data, available formats, technical interfaces, transferable digital assets, the level of cooperation required from the outgoing provider and any technological dependencies that may give rise to vendor lock-in.

The assistance supports the preparation of a genuine exit plan, identifying responsibilities, timelines, costs, security measures and verification procedures. In regulated sectors, these activities are coordinated with the obligations arising under DORA, the NIS 2 framework and the rules governing ICT outsourcing and service continuity.

Public-Sector Data Requests and Data Act Disputes

Assistance includes the management of data requests submitted by public-sector bodies, the European Commission, the European Central Bank or Union bodies in situations of exceptional need under the Data Act.

The support provided covers verification of the requesting body’s competence, the reasons for the request, its necessity and proportionality, and the identification of the data that must actually be disclosed. The assessment also addresses restrictions arising from personal data protection, trade secrets and security, the methods of transmission and any entitlement to compensation. The Data Act does not establish a general power to obtain data, but permits such requests only under the strictly defined conditions laid down by the Regulation.

Attorney Alessandro del Ninno also assists companies in disputes concerning access to data, the determination of financial terms, the protection of trade secrets, the fairness of contractual provisions and compliance with switching obligations. The services may include negotiation, the use of alternative dispute-resolution mechanisms provided for by the Data Act and proceedings before competent authorities or courts.

The Data Governance Act, Re-Use of Public-Sector Data and Data Intermediation

Attorney Alessandro del Ninno advises public bodies, companies, research centres and economic operators on the application of the Data Governance Act and Italian Legislative Decree No. 144/2024.

The practice covers the re-use of data held by public-sector bodies that cannot be made available as ordinary open data because they are protected by commercial or statistical confidentiality, intellectual property rights or personal data protection law. Assistance includes preparing re-use requests, assessing access conditions, using secure processing environments, anonymising or pseudonymising data and negotiating the applicable re-use terms.

Advice is also provided to entities intending to offer data intermediation services by bringing data holders, data subjects and data users together. The service includes classifying the operating model, assessing notification requirements, separating activities, preventing conflicts of interest, managing metadata, preparing contractual terms and coordinating the service with the GDPR.

Assistance extends to data-altruism projects, under which individuals and companies voluntarily make data available for objectives of general interest, and to participation in common European data spaces, consortia and collaborative platforms. The Data Governance Act establishes a specific European framework for the re-use of protected public-sector data, data intermediation services and recognised data altruism organisations.

For common European data spaces and collaborative platforms, the support includes defining participation rules, access and usage conditions, dataset quality and description requirements, licences, responsibilities, security measures and interoperability requirements. The advice coordinates the Data Governance Act, the Data Act, applicable sector-specific legislation and the contractual rules governing the relevant data ecosystem.

International Transfers and Third-Country Access

The assistance covers transfers of personal data to third countries through adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, Transfer Impact Assessments and supplementary measures.

Contracts with cloud providers, group companies and international partners are reviewed with regard to processing locations, the use of sub-processors, requests from foreign authorities and remote access to systems.

For non-personal data, the safeguards required by the Data Act and the Data Governance Act against access or transfers that conflict with Union law are assessed, with particular attention to commercially and industrially sensitive information. The Data Governance Act provides specific safeguards for non-personal data in relation to requests from third-country authorities.

Data Breaches, Incidents and Crisis Management

Attorney Alessandro del Ninno assists organisations in designing procedures for the prevention, detection and management of personal data breaches and incidents affecting industrial data, platforms, connected products or cloud services.

In the event of an incident, the assistance covers reconstruction of the facts, preservation of evidence, identification of the data and parties involved, risk assessment and verification of any notification or communication obligations.

The work is carried out in coordination with the DPO, Legal, IT, Cybersecurity, Compliance and Communications functions, ensuring consistency between the requirements arising under the GDPR, NIS 2, DORA, contractual arrangements and sector-specific legislation. The documentation required to substantiate the decisions taken is also prepared, including where the conclusion is that the incident does not require notification.

Regulated Sectors and Specialist Processing Activities

The assistance is tailored to the specific characteristics of the client’s sector and may cover, among others, banking, insurance, healthcare, publishing, telecommunications, digital platforms, public administration, credit, research, business information and technology services.

A dedicated area concerns the processing of data in the employment context, including the management of corporate email, metadata, logs, devices, security systems and tools capable of monitoring employees’ activities. The assistance includes preparing privacy notices, policies and internal rules, managing accounts following termination, internal investigations, defensive monitoring and coordination with Italian employment law, including the Workers’ Statute.

Advice is also provided on marketing, CRM, loyalty programmes, profiling, personalised advertising and the use of cookies, SDKs and other online identifiers, with particular attention to preference management, data sharing with platforms and partners and the handling of users’ rights.

Regulatory Proceedings and Litigation

Attorney Alessandro del Ninno represents and advises clients in proceedings before the Italian Data Protection Authority, AgID and other competent national and European authorities.

The practice includes the management of inspections, information requests, complaints, corrective and sanctioning proceedings, and the regulatory engagement required to present the measures adopted and the organisation’s compliance programme.

Litigation services cover challenges to decisions issued by supervisory authorities, damages claims, disputes concerning access to and use of data, protection of trade secrets, conflicts between data holders and recipients, and disputes arising from cloud contracts and data-sharing agreements.

DPO Support, Training and Ongoing Assistance

Support may also be provided on an ongoing basis, assisting the Data Protection Officer, General Counsel and business functions in assessing new projects, reviewing contracts, managing suppliers and updating internal procedures.

Attorney Alessandro del Ninno also designs training programmes for boards of directors, senior management, DPOs, Legal, Compliance, HR, Marketing, Procurement, IT, Cybersecurity and product teams. Training is built around the organisation’s actual processes and uses practical cases to turn knowledge of the applicable rules into effective decision-making and operational capability.

The overall objective is to provide companies with a single specialist point of reference for governing data throughout its entire lifecycle: from collection to exploitation, from sharing to retention, and from contractual protection to incident management and litigation.