Specialist Training, Workshops and Corporate Programmes
Legal and regulatory training is genuinely effective only when it is built around the organisation’s actual processes, responsibilities and risks. A purely theoretical update rarely enables directors, senior management and operational staff to understand how the rules should be applied in day-to-day decision-making, supplier management, product development and incident response.
Attorney Alessandro del Ninno designs and delivers training programmes, practical workshops and continuing education courses for companies, corporate groups, public-sector bodies, regulated operators and trade associations in the fields of data protection, Artificial Intelligence, cybersecurity, Information Technology, digital regulation, intellectual property and technology contracting.
Each engagement is tailored to the client’s sector, size and organisational model, the intended audience, the technologies used, the responsibilities assigned and the applicable legal requirements. Content may be differentiated for boards of directors, senior management, Legal and Compliance teams, DPOs, CISOs, CIOs, HR, Procurement, Marketing, Internal Audit, developers, product managers and operational staff.
The objective is to translate complex legal requirements into practical decision-making criteria, procedures and conduct, strengthening the organisation’s ability to prevent risk, manage critical events effectively and document the measures adopted.
Programme design may begin with a preliminary assessment of the organisation’s needs, activities, principal use cases and any issues identified through audits, incidents, inspections, supervisory activities or changes to business processes.
On the basis of that assessment, the learning objectives, intended participants, level of detail, duration and delivery method are defined. The programme may take the form of a single workshop, a series of sessions, a modular course, periodic updates or an annual training plan.
Content is adapted to the participants’ actual responsibilities. Training for directors and senior management focuses on governance, oversight duties and strategic decision-making; training for specialist functions addresses procedures, controls and compliance obligations in greater depth; and modules for operational staff translate corporate policies into instructions and behaviours applicable to day-to-day activities.
Where appropriate, the programme is coordinated with policies, procedures, contracts, governance models and compliance plans already adopted or under development, so that participants understand not only the applicable legal framework, but also the internal tools they are expected to use.
Attorney Alessandro del Ninno delivers executive sessions for boards of directors, committees, senior management and heads of function.
Programmes may address the responsibilities of corporate bodies, the approval and oversight of organisational measures, reporting flows, risk assessment, supplier management, business continuity and incident response.
Particular attention is paid to the training and continuing education requirements arising under the NIS 2 and DORA frameworks, as well as to the governance of data, Artificial Intelligence systems and technology projects. These sessions enable directors to understand the legal, operational and reputational consequences of their decisions without requiring specialist technical knowledge.
Tailored modules are also developed for Legal, Compliance, DPO, CISO, CIO, Risk Management, Internal Audit, Procurement, HR, Marketing and business functions according to their respective responsibilities. Joint workshops involving legal, technical and commercial teams may also be organised to improve coordination in projects and crisis situations.
Programmes may cover, in particular:
Data protection and data regulation. GDPR principles, legal bases, transparency, data subject rights, personal data breaches, DPIAs, profiling, automated decision-making, international data transfers, controller-processor arrangements, employee data, marketing, cookies, advertising platforms, the Data Act and access to data.
Artificial Intelligence and AI literacy. Classification of AI systems, provider and deployer roles, prohibited practices, high-risk systems, transparency obligations, human oversight, data quality, use of generative AI, protection of confidential information, verification of outputs and copyright. For providers and deployers, programmes may be structured to ensure an appropriate level of AI literacy among staff and other persons involved in the operation and use of AI systems.
Cybersecurity and digital operational resilience. Cybersecurity governance, NIS 2, DORA, cybersecurity risk-management measures, incident response, regulatory notifications, business continuity, supply-chain risk, ICT suppliers, evidence preservation, the Cyber Resilience Act and the security of digital products.
Information Technology and technology contracts. Software development, licensing, cloud services, SaaS, outsourcing, systems integration, maintenance, open-source software, service levels, testing and acceptance, change management, source-code ownership, data management, liability, vendor lock-in and exit strategies.
Intellectual property and digital content. Software, databases, trade marks, copyright, know-how, trade secrets, chain of title, open-source licences, images, audiovisual content and the use of works generated or modified through Artificial Intelligence.
Digital services regulation. E-commerce, consumer protection, online platforms, the Digital Services Act, electronic communications, digital payments, electronic identification, electronic signatures, electronic documents, accessibility, digital media and online advertising.
Programmes are updated in line with legislative developments, regulatory practice and the specific characteristics of the client’s sector.
In addition to conventional training, interactive workshops may be organised to address concrete operational scenarios.
Exercises may concern a personal data breach, a NIS incident, a ransomware attack, a compromised supplier, the unavailability of a critical service, the malfunction of an AI system, a dispute arising from a software project or a crisis involving the security of a digital product.
Participants are required to reconstruct the facts, identify responsibilities, activate escalation procedures, assess notification obligations and make decisions within timeframes consistent with the scenario.
Negotiation simulations may also be organised in relation to technology agreements, cloud services, ICT suppliers, software licences, data use and intellectual property clauses. Reviewing standard terms and contractual scenarios helps participants identify common imbalances and understand which risks may be negotiated and which require specific approval.
Issues identified during workshops may be used to update policies, procedures, response plans, contractual templates and compliance programmes.
Each programme may be accompanied by tailored materials, presentations, practical guides, checklists, decision trees, FAQs, case studies and templates for use in day-to-day activities.
Where required, preliminary and final tests, self-assessment questionnaires, learning assessments, certificates of attendance and summary reports identifying the topics covered and the participants involved may also be prepared.
This documentation enables the organisation to evidence the training delivered, monitor attendance and identify areas requiring further intervention.
Materials may be prepared in Italian or English and adapted for in-person sessions, webinars, remote learning or hybrid delivery.
The engagement may be structured as an annual or multi-year programme comprising an initial common training module, function-specific sessions, executive workshops, periodic exercises and updates following legislative, organisational or technological changes.
Programmes may include modules for new hires, refresher sessions, training following incidents or audits, and courses designed for multinational groups or personnel operating across different jurisdictions.
Attorney Alessandro del Ninno may also develop train-the-trainer programmes for internal trainers, function representatives and managers responsible for disseminating procedures and operational guidance within the organisation.
The service may include supporting Legal, Compliance, DPO, HR, IT and Cybersecurity functions in defining the training plan, selecting participants, scheduling updates and periodically reviewing the adequacy of the programme.
The overall objective is to deliver training that goes beyond formal compliance and enables directors, senior management and staff to identify risks, apply procedures correctly, involve the appropriate functions promptly and make informed, well-documented decisions.