Attorney Alessandro del Ninno participated as a keynote speaker in Paradigma’s specialist executive programme on the legal, organisational and technological aspects of recording and managing the minutes of corporate bodies, an area that has become increasingly central to the digital transformation of corporate governance.
His presentation provided a comprehensive analysis of the data protection implications arising from the preparation, management and preservation of minutes of shareholders' meetings, board meetings and other corporate bodies. Particular attention was devoted to the processing of personal data throughout the entire lifecycle of corporate records—from their creation and digital recording to their storage, consultation and disclosure—both in traditional environments and through advanced digital platforms powered by artificial intelligence.
The session explored the legal and regulatory implications of deploying AI-based technologies for automated transcription, summarisation and drafting of corporate minutes, examining not only the efficiency gains offered by these solutions but also the compliance challenges they raise under European data protection law. The discussion addressed key accountability obligations under the GDPR, the implementation of privacy by design and privacy by default, Data Protection Impact Assessments (DPIAs), international data transfers, cybersecurity safeguards, and the digital preservation of statutory corporate books.
The workshop also examined the interaction between the GDPR, company law, electronic document regulation and the broader European digital regulatory framework, including the AI Act, the Data Act, the Data Governance Act, DORA, the NIS 2 Directive and the revised eIDAS framework. Particular emphasis was placed on balancing technological innovation with the protection of fundamental rights, ensuring that digital governance processes remain legally robust, secure and fully compliant.
Finally, the presentation analysed data subjects' rights in relation to corporate minutes, including the right of access, the relationship between company law disclosure obligations and data protection principles, and the latest case law of the Court of Justice of the European Union. Through a practical, business-oriented approach supported by real-world examples, the session provided board members, company secretaries, general counsel, compliance officers, data protection professionals and corporate advisers with practical guidance on designing and implementing governance processes capable of supporting the digital evolution of corporate decision-making while ensuring full legal compliance.