Alessandro Del Ninno
Conferences
Regulating the Processing of Personal and Non-Personal Data in ICT Contracts. Drafting Contractual Clauses in Light of the GDPR, the Data Act, the DGA and the AI Act.
Conference organized by Paradigma S.p.A. - Rome, 23rd Aprile 2026.
23/04/2026
Regulating the Processing of Personal and Non-Personal Data in ICT Contracts. Drafting Contractual Clauses in Light of the GDPR, the Data Act, the DGA and the AI Act.

The Paradigma workshop “Regulating the Processing of Personal and Non-Personal Data in ICT Contracts. Drafting Contractual Clauses in Light of the GDPR, the Data Act, the DGA and the AI Regulation” was devoted to the contractual regulation of personal and non-personal data within the current European regulatory ecosystem.

During the session, Avv. Alessandro del Ninno analysed the new regulatory framework of the Value Data Economy, focusing on the interplay between the GDPR, the Data Act, the Data Governance Act and the AI Act, and on their respective impact on the drafting of ICT contracts. Particular attention was devoted to the qualification of data as a contractual asset, the distinction between personal and non-personal data, and the operational consequences in terms of contractual clauses, liability and risk management.

The workshop examined privacy-related issues in ICT contracts, with specific reference to essential clauses governing the processing of personal data, privacy notices and legal bases, joint controllership arrangements, the appointment of processors, and the management of subcontractors and the contractual chain. Contractual safeguards were also addressed, including audit rights, termination rights, compensation for damages and recurring practical issues, such as generic or excessively unbalanced clauses.

A substantial part of the session was dedicated to the Data Act, focusing on clauses governing access to, sharing and reuse of data, data generated by connected products and digital services, the contractual balance between openness and data circulation, the protection of trade secrets and the competitive interests of the parties. Avv. Alessandro del Ninno also addressed the management of data use licences, limits on economic exploitation, permissible contractual restrictions, portability, interoperability, switching and termination in contracts with digital and cloud service providers.

The programme also addressed the Data Governance Act, with reference to data sharing agreements, commercial data licences, access and reuse conditions, and the role of undertakings as data intermediaries. From this perspective, the session analysed new data-driven business opportunities, transparency clauses for intermediation services, neutrality and functional separation clauses, and liability and control issues in intermediation models.

With regard to the AI Act, Avv. Alessandro del Ninno examined the contractual qualification of the roles involved in the artificial intelligence value chain, including AI system providers, deployers and users, highlighting the consequences in terms of obligations, liability and data governance. Particular attention was paid to technical annexes, supporting documentation, system instructions for use, limitations of use, update management and technical documentation in contracts for the supply of artificial intelligence solutions.

The workshop also considered the clauses required to ensure regulatory compliance, system traceability, audit management, incident management, transparency towards clients and end users, and general terms of use for AI systems. The concluding part was devoted to the analysis of practical cases and recurring errors in data and AI contractual practice, including misalignment between contracts and actual processing operations, shortcomings in liability clauses, underestimation of data governance and failure to coordinate the GDPR, the Data Act, the DGA and the AI Act.