Pulsantiera di navigazione Home Page
Pagina Facebook Pagina Linkedin Canale Youtube Italian version
Conventions and conferences
Conventions and conferences of Alessandro Del Ninno

Managing Data Breaches Between Data Protection and Cybersecurity.

Conference organized by Paradigma S.p.A. - 3 Aprile 2025.

Managing Data Breaches Between Data Protection and Cybersecurity.
This training day, organized by Paradigma, is aimed at providing companies and public/private operators with a practical and up-to-date guide to properly manage data breaches in light of the latest European guidelines, supervisory authorities’ interpretations, and recent cybersecurity regulations.

The program features technical-legal presentations by leading experts in the field. Key topics include:
  • Definition and types of data breaches under the GDPR and EDPB Guidelines 1/2021: ransomware attacks, data exfiltration, human errors and misdirected communications, lost or stolen devices, breaches caused by poor password management or AI misuse.
  • Risk assessment and criteria triggering the notification obligation: ENISA methodology, accountability, and the DPO’s role.
  • Sanctioning and remedial consequences of data breaches: corrective powers of supervisory authorities, administrative fines, and compensatory liability, with analysis of the most recent case law.
Alessandro Del Ninno’s presentation is a central, practice-oriented part of the event, addressing notification obligations and legal strategies in the event of data breaches, with a focus on recent regulatory and operational updates.

1. Notification to the Supervisory Authority (Article 33 GDPR)
  • The moment when a controller becomes “aware” of a breach.
  • Obligations of processors and joint controllers.
  • Mandatory contents of the notification and the possibility of phased reporting ("without undue further delay", Article 33.4).
  • Situations where notification is not required.
2. Communication to Data Subjects (Article 34 GDPR)
  • When and how to inform affected individuals.
  • What information to provide and in what format.
  • Criteria for exemption from notification (e.g., encrypted data or risk mitigation measures).
3. EDPB Guidelines 9/2022
  • Official interpretations and practical scenarios clarifying notification thresholds.
  • Analysis of common errors in notifications submitted by organizations.
4. Operational Issues
  • How to prepare for a breach: internal templates and procedures.
  • Managing the tight GDPR timeframe (72 hours).
  • Coordinating with the DPO and internal incident response teams.
The presentation serves as a practical guide to avoiding errors in breach notification and to structuring the required documentation and communications with authorities and data subjects. Frequent references are made to EU and national case law and regulatory guidance. Workshop Schedule
Stampa la pagina