Avv. Alessandro Del Ninno took part as a speaker in the Paradigma conference entitled “Managing Data Breaches Between Data Protection and Cybersecurity”, held on 11 March 2026 and devoted to the analysis of personal data breaches and cybersecurity incidents in light of the GDPR, EDPB Guidelines, ACN guidance and the most recent sector-specific rules on digital resilience and cybersecurity. Within the programme, his presentation focused on notification obligations relating to data breaches and cyber incidents from the perspective of cybersecurity regulation, with particular attention to the DORA Regulation, Legislative Decree No. 23/2025 and Italian Law No. 90/2024.
During his presentation, Avv. Del Ninno explained that breach management can no longer be viewed solely through the lens of the GDPR, but must instead be placed within a broader regulatory framework in which the notion of incident extends to the availability, integrity, authenticity and confidentiality of both data and digital services. In this context, he referred to the development of European cybersecurity law, focusing on the interaction between data protection, NIS 2, DORA, the Italian implementing framework and the national cybersecurity legislation.
A central part of the presentation was devoted to the DORA Regulation and to the obligations imposed on banking, financial and insurance entities concerning the identification, management, classification and notification of ICT-related incidents. Avv. Del Ninno discussed the distinction between ICT-related incidents, operational or payment-security incidents, major incidents and significant cyber threats, focusing on classification criteria, internal escalation procedures, reporting flows towards competent authorities and customers, and the notification system structured around an initial notification, intermediate reports and a final report.
He then addressed Legislative Decree No. 23/2025, highlighting the Italian coordination rules for DORA, in particular the allocation of powers among the Bank of Italy, CONSOB, IVASS and COVIP, the coordination with CSIRT Italy for certain categories of financial entities, and the sanctioning framework applicable in the event of non-compliance with reporting obligations. He stressed that this regulatory framework strengthens the organisational dimension of incident management, requiring structured cooperation and timely information-sharing between authorities and supervised entities.
In the final part of his presentation, Avv. Del Ninno examined the notification obligations introduced by Italian Law No. 90/2024, with particular attention to the public and quasi-public entities subject to the regime, the two-step mechanism consisting of an initial report within 24 hours and a full notification within 72 hours, as well as the taxonomy of incidents defined by ACN in February 2026. In this respect, he referred to incidents involving loss of confidentiality, loss of integrity and breaches of service levels, highlighting the practical implications for administrations and entities required to incorporate incident notification procedures into their security and response frameworks.
Through this contribution, Avv. Alessandro Del Ninno provided participants with an integrated reading of the relationship between data breaches and incident reporting, showing how breach management now requires effective coordination between privacy compliance, operational resilience, internal escalation procedures and notification duties towards multiple competent authorities.