Alessandro Del Ninno
Conferences
The minute-taking of corporate bodies’ meetings. Data protection and AI aspects.
Lecture discussed at the Conference organized by Paradigma S.p.A. - 11 November 2025.
11/11/2025
The minute-taking of corporate bodies’ meetings. Data protection and AI aspects.

During the Paradigma conference dedicated to the minute-taking of corporate bodies’ meetings, Alessandro Del Ninno discussed a lecture focused on data protection and information security issues related to the drafting, management and retention of corporate minutes, with particular attention to the technological evolution of governance processes.

The speech provided a systematic analysis of the application of Regulation (EU) 2016/679 to the activities of corporate minute-taking, qualifying them as full-fledged personal data processing operations and examining their implications in light of the principles of lawfulness, data minimisation, fairness and accountability. Specific emphasis was placed on the nature and variety of personal data typically included in the minutes of shareholders’ meetings and boards of directors, as well as on the safeguards required when handling information relating to directors, statutory auditors and other individuals involved in corporate decision-making processes.

The presentation further addressed the technical and organisational security measures necessary to ensure the confidentiality, integrity and availability of minutes, particularly in the context of the increasing digitalisation of corporate bodies and the use of IT platforms for the management of meetings, electronic signatures and digital archives. In this framework, the delicate balance between transparency and traceability of corporate decisions, on the one hand, and the protection of personal data and the rights of data subjects, on the other, was thoroughly examined.

A specific segment of the presentation was devoted to the new minute-taking tools enabled by Artificial Intelligence, analysed from the perspective of their compatibility with the personal data protection regulatory framework. Attorney Del Ninno examined the use of speech-to-text solutions, automated drafting support systems and semantic content analysis tools applied to meetings, highlighting their potential benefits in terms of efficiency and standardisation, as well as the legal risks associated with large-scale data processing, the possible introduction of errors, bias or excessive data collection, and the traceability of decision-making processes. In this context, particular emphasis was placed on the importance of prior risk assessments, the correct qualification of privacy roles and the adoption of AI governance measures consistent with the principles of the GDPR.

The presentation also explored the role of the Data Protection Officer in minute-taking processes, including with regard to the adoption of Artificial Intelligence-based tools, highlighting the DPO’s advisory function in defining retention policies for minutes, assessing information security measures and managing the risks associated with medium- and long-term digital storage. Overall, the contribution aligned with the strongly practical approach of the event, offering participants an up-to-date, operational and legally sound perspective on the data protection and cybersecurity implications of corporate minute-taking in the context of digital transformation.