Legal Tips

Cybersecurity & Privacy Legal Tips

A clear understanding of Cybersecurity legal issues is esssential for anyone working in the area. Our Legal tips section updates you on all Legal news on Cybersecurity and privacy issues!

GDPR & NIS Directive raises awareness of the two major legislative tools that are having a major impact on the EU cybersecurity landscape: The GDPR (Regulation 679/2016 on the protection of personal data) which becomes effective on 28 May 2018; and the NIS Directive (Directive 2016/1148 concerning measures for a high common level of security of network and information systems across the Union) which will be transposed by Member States by the 9th of May 2018. These two legislative instruments are  strictly intertwined with the NIS Directive refers to the applicable data protection law as to a necessary complementary set of rules.

How helps

In addition to our regularly updated news below, we'll also be publishing a series of recommendations documents, which will help organisations to understand the interplay of the two legal frameworks, in order to clarify their intricacies, to solve potential conflicts of interpretation and to effectively enable R&I projects focussed on privacy and cybersecurity to effectively participate to the policy making debate of the next two years, both at national and EU level, on these matters. The project will therefore focus on the following activities:
•    Monitoring of the regulatory framework;
•    Understanding the legal complexity of the regulatory framework;
•    Drafting a list of policy issues to be solved at EU and/or national level;
•    Supporting R&I teams and proactively proposing areas of research and policy solutions

Our legal experts from ICT Legal Consulting are here to guide you through the most common and important terms. 


Source: ICT Legal Consulting  ICT Legal Consulting


Handbook on European data protection law : 2018 edition

The European Union Agency for Fundamental Rights has released the updated 2018 edition of the “Handbook on European data protection law”.

The Italian Budget Law and its impact on legitimate interest (and portability)

On 29 December the Italian Budget Law for 2018 was published in the Italian Official Journal. The law at stake, which is probably one of the most relevant laws issued at the end of each year in Italy, contains some provisions that impact key elements of the forthcoming EU data protection framework – Regulation EU 2016/679 (“GDPR”)

Guidelines on the application of Article 28 of GDPR

Under Article 28 of the General Data Protection Regulation (“GDPR”), controllers must only appoint processors who can provide “sufficient guarantees” to meet the requirements of the GDPR. Processors must only act on the documented instructions of the controller and they can be held directly responsible for non-compliance with the GDPR obligations, or the instructions provided by the controller, and may be subject to administrative fines or other sanctions and liable to pay compensation to data subjects.

The e-privacy regulation: new rules for analytics cookies

On 8 September 2017, the Council of the European Union reviewed the draft of the new e-Privacy Regulation (“EPR”) – previously published by the European Commission on 10 January 2017 -, which allows the use of first-party and third-party analytic cookies without express consent of the end-user.

Global Cybersecurity Index 2017 reveals that 50% of countries have no cybersecurity strategy in place

The UN's International Telecommunication Union (ITU) has recently released the second version of its Global Cybersecurity Index which measures countries' commitment to cybersecurity and helps them to identify areas for improvement.

The Italian DPA issued its first guidelines on the GDPR


On 28 April 28 the Italian Data Protection Authority (“Garante”) issued its first guidance on the new provisions of the General Data Protection Regulation (“GDPR”), consisting of a schematic overview of the changes in the current legal framework and recommendations on how to face them.

The Garante focused on six specific aspects:

Knowing more on GDPR: video interview from Infosec 2017

Do you want to know more about the GDPR*?
Watch this live talk, streamed during the last Infosec event in London, where three experts in the field of cyber security & privacy give their perspective on GDPR compliance in reference to the European landscape.


PAPAYA: Platform for PrivAcY preserving data Analytics

PAPAYA: Platform for PrivAcY preserving data Analytics is one of the GDPR cluster projects that will help companies to follow a privacy-by-design approach & adopt #PrivacyEnhancingTechnologies to ensure their clients’ privacy is protected.

Future Events

Brussels - Second CW Concertation Meeting, 04/06/2019

Resilience. Deterrence. Defence – Calls to action for future cybersecurity and privacy policy
Concertation meeting of H2020 projects from unit "Cybersecurity & Privacy"


Join us at the second Concertation meeting, 04 June 2019!

Annual Privacy Forum 2019
13/06/2019 to 14/06/2019

LOCATION: LUISS Guido Carli - Rome, Italy

The event encourages dialog with panel discussions and provides room for exchange of ideas in between scientific sessions. Participate to the discussions during APF days, but also by being involved online on our community channels using #APF19

Even theme: