Regulating the Processing of Personal and Non-Personal Data in ICT Contracts.
Workshop organized by Paradigma S.p.A. - Rome, 18 March 2026.
Avv. Alessandro Del Ninno took part as a speaker in the Paradigma workshop entitled “Regulating the Processing of Personal and Non-Personal Data in ICT Contracts”, held on 18 March 2026 and devoted to the drafting of contractual clauses in light of the GDPR, the Data Act, the Data Governance Act and the AI Act. The workshop addressed, from a practical perspective, the main legal issues surrounding data governance in ICT relationships, with particular focus on contractual structure, allocation of roles, risk management and the interaction between the most recent European instruments governing data and digital technologies.
During his presentation, Avv. Del Ninno outlined the new European regulatory ecosystem for data, explaining that ICT contracts can no longer treat personal and non-personal data separately, since in practice datasets are often mixed and therefore require contractual mechanisms capable of governing, at the same time, data protection, access, reuse, portability, trade secrets and liability. In this context, he also referred to the Digital Omnibus as a broader simplification and coordination initiative affecting the legal framework on data, artificial intelligence and cybersecurity.
A central part of the presentation was devoted to the methodology for drafting contractual clauses on data. Avv. Del Ninno stressed that an effective clause should not merely restate a legal rule, but should translate risk into concrete processes, documentary evidence, response times, remedies and control mechanisms. From this perspective, he highlighted the importance of building a proper contractual architecture for ICT arrangements, distinguishing between the main agreement and specialised annexes, such as the Data Schedule, the Data Processing Agreement, the Security Schedule, annexes on portability, switching and exit, as well as data sharing and intermediation agreements.
He then focused on the GDPR dimension of ICT contracting, addressing the correct qualification of the parties as controller, processor or joint controllers, the need for data processing agreements that are genuinely descriptive rather than merely formal, the regulation of subcontracting chains, and the contractual handling of DPIAs, data breaches and data subject requests. Particular emphasis was placed on the fact that supplier assistance in these areas should be structured as a real contractual process, with clearly defined channels, timelines, minimum content requirements and documentary obligations.
Significant attention was also given to the Data Act, especially as regards data generated by connected products and related services, the conditions for access, sharing and reuse of data in business-to-business relations, the limits imposed on unfair clauses unilaterally imposed by one party, and the contractual models that can be used to regulate portability, compensation, trade secrets and business continuity. Avv. Del Ninno highlighted that the Data Act is set to have a direct impact on commercial and cloud contracting, requiring greater precision in the definition of the relevant data, permitted uses and exit-related obligations.
In the final part of his presentation, he addressed the impact of the AI Act on ICT contracts, with particular regard to high-risk AI systems, the need to document data governance arrangements, the quality of datasets, bias-related controls, the possible use of special categories of personal data, and the relationship between customer and supplier in the management of technological and cyber risk. He also highlighted the need to address contractually issues such as supplier dependency, data localisation, subcontracting, audits, incident assistance and termination rights in ICT contracts, also in light of the broader European framework on digital resilience and security.
Conference Schedule