During the Paradigma conference, Avv. Alessandro Del Ninno addresses, with a practical and operational focus, the data protection and information security issues arising from the preparation of minutes and records by corporate bodies (boards of directors, committees, statutory auditors’ boards and, more generally, any corporate body or function responsible for drafting, approving, circulating and retaining minutes and resolutions). The session explains how to properly govern the entire document lifecycle—from the collection of information to digital archiving—so as to reduce legal and operational risk.
The presentation first frames how the GDPR applies to corporate minutes, clarifying when and why minutes constitute processing of personal data, and the resulting implications in terms of roles, accountability and organisational obligations. Avv. Del Ninno then focuses on the types of personal data typically recorded in minutes of corporate bodies, how to identify and classify them, and—most importantly—how to manage them consistently with the principles of data minimisation, purpose limitation, fairness and accountability, distinguishing between information strictly necessary for the corporate purpose of the minutes and additional details often included as a matter of practice.
A core part of the session is dedicated to information security measures for corporate minutes, analysed across three critical phases: protecting data within the platform (access management, role-based segregation, logging and audit trails, authorisation controls), protecting data during transmission (secure channels, encryption, controlled sharing and distribution, and the risk of improper forwarding), and protecting data during retention and archiving (integrity, availability, backups, digital retention arrangements, and managing the risk of unauthorised access over time). In this context, Avv. Del Ninno discusses organisational choices that materially affect security in practice: who can access what among directors, corporate secretariat functions and support teams; how consultations and disclosures are evidenced; which ex post controls are sustainable; and what minimum set of evidences makes the process defensible in the event of audits or disputes.
The session also addresses, from an operational standpoint, the handling of data subjects’ rights (access, rectification, erasure and other relevant rights) when personal data are embedded in minutes and resolutions: how to manage requests in the presence of corporate retention obligations and the need to preserve document integrity; which room exists for rectifications, annotations or selective redactions; and how to avoid “automatic” responses that increase legal and reputational exposure. A specific focus is devoted to the role of the DPO, understood as a governance and methodology function: Avv. Del Ninno clarifies expected contributions in terms of risk assessment, internal policies, training and auditability of the minutes management process, as well as common misunderstandings that may weaken the overall control framework.
Finally, Avv. Del Ninno examines digital retention of minutes of corporate bodies and the related information security safeguards, highlighting the technical and procedural choices that make retention not only compliant, but also robust over time: access controls, protection of integrity, management of copies, retention policies, and incident/data breach handling as it relates to corporate documentation. The overall aim is to provide a clear, actionable framework to secure corporate minutes management processes, reduce risk exposure and improve the operational quality of compliance.