Digital technology continues to profoundly change our lives as well as market scenarios: meeting the challenges of optimizing productive processes, client-supplier relationships, and innovation requires data, connectivity and the use of digital platforms. In this context, novel development models are creating new market outlets and amplifying traditional ones, generating new products and services, and forming new production and sales processes that irrevocably change interactions with the world of work.
The EU, conscious of this historical revolution, predicts a 530% increase in the volume of data treatment compared to 2018.
Concurrently, the birth of new technologies has invented new ways of collecting and using data, the nature of which generates risks surrounding issues of fundamental individual freedom.
Unfortunately, a lack of trust persists in the European digital economy in terms of size and future perspectives. In 2018, the market value of the European digital economy was € 301 billion (2.4% of GDP); should its full potential be reached, this value could soar to € 829 billion within 2025. By reducing concerns surrounding lack of trust we will be able to exploit extraordinary employment opportunities in this sector which are estimated to reach almost 11 million in 2025, compared with 5.7 million professionals in 2018.
The EU recently signalled its support of the global data economy by announcing an upcoming political and investment strategy to be rolled out over the next five years with a focus on innovation that revolves around people.
To set the scene for success and take full advantage of the potential of the data economy, there has to be effective data governance policies that address first and foremost personal data, in compliance with the GDPR, the e-Privacy Directive and all relevant legislation.
IUSINTECH, in close collaboration with experienced IT professionals (see our precious Advisory Board), is fully equipped to assist clients with company data governance, including cybersecurity profiles, from definition and design to implementation, with regard to:
- Mapping, analyzing and regulating the legal, technical and organizational aspects of corporate personal data processing
- Assessment of IT systems, of the current data processing procedures, of the characteristics of both the internal organization and the network of outsourcers – by understanding how these impact current processes –, of the risk management practices adopted (e.g. codes of conduct, certifications, DPO presence), definition of privacy roles and competencies at all levels: group, business line and/or individual legal entity, including roles and relationships whether infra-group or with external suppliers and purchasers
- Identification of specific security measures structured by activity sector / data processing category, detecting threats and vulnerability level, setting appropriate alert levels, identification of the need for review with respect to previous risk assessments, assessment of the level of consistency with the principles of privacy by design and by default
- designing a framework of appropriate security measures, defining policies and procedures (e.g. for staff, data retention, verification and control, management of IT security incidents and personal data breaches, notification of data breaches to supervisory authorities and data subjects, etc.)
- selection of technical IT solutions and resilience plans plus supervision of the implementation, maintenance and updating of technical IT security measure assessment (measurement, monitoring and control of the level of implementation achieved), pre- and post-adaptation
We provide added value to clients through our expertise in developing specific projects related to personal data processing:
- Direct participation in the various design and implementation phases
- Disclosure of the operating strategy with the Client
- Compliance activity
- Drafting opinions, contracts ad hoc.
We work with the client to design and implement marketing and profiling strategies, analysing legal profiles and developing all the necessary documentation (privacy and cookie policies, data collection forms, processing instructions and scripts for operators, designations of data controllers, contracts linked to promotional actions, including lead generation, comarketing, list broking).
We are also experienced in performing due diligence in the context of mergers and acquisitions, including:
- Identification of the target company and relative risk assessment
- Pinpointing necessary milestones in the development of new market strategies e.g. new market entry points or product sectors, internationalization processes, implementation of new organizational or production methods
In all of these steps, we are right beside our Clients to facilitate discussions with Public Authorities on matters related to personal data protection, on the occasion of litigation and voluntary proceedings as well as during inspections or requests for information by such Authorities.
Ultimi articoli del blog
SERVIZI CLOUD E LOGICHE AS A SERVICE – Verso una più equa distribuzione del rischio contrattuale e nuove tutele30 April 2021 - 11:13
Report del Parlamento Europeo del 5 Ottobre su AI Liability10 October 2020 - 18:20- LH ROMA LEX DRINK COOK YOUR COOKIES9 December 2021 - 18:17
- LEGAL INNOVATION CONFERENCE RAFFAELLA AGHEMO26 November 2021 - 18:44
CLOUDPLANET23 November 2021 - 18:45
Address
Iusintech
Via Vincenzo Bellini, 10
20122 Milano (Italia)
Email: hello@iusintech.com
Skype: iusintech
Phone: +39.02.799.991

