Author Archives: Alessandro Vallega

About Alessandro Vallega

He is Security Business Development Director for Oracle EMEA. He has the responsibility to lead a cross functional team on the GDPR (General Data Protection Regulation, EU 679/2016) at EMEA level (marketing, legal, sales, training, technology). He founded and coordinates an external blog on the same topic (https://blog.europrivacy.org). He has defined a European methodology to evaluate the database security degree of a data center and the advantages of identity and access management technology. He founded in 2007 the Oracle Community for Security, and in that context led the creation of several publications about security and privacy in the cloud, with mobile, in the social media, in healthcare, on return on security investments, about the role of the CISO, and how to prevent frauds. He is an author of the Italian annual ICT Security Report by CLUSIT and he is part of the CLUSIT board of directors.

Data Breach

The Regulation requires the Controller to notify, without undue delay, the personal data breach to the supervisory authority. Whenever the personal data breach is likely to adversely affect the protection of the personal data, the privacy, the rights or the legitimate interests of the data subject, the Controller must also communicate the personal data breach to the data… Read More »

Impact, Risk and Measures

Regulation states that Privacy Impact Assessment is the first step of a company’s security strategy, that consequentially enhances the analysis of risks related to personal data processing and security measures adopted to protect information. More than setting specific security measures, the Regulation requires the Controller to implement organizational and technical processes to identify, reduce and mitigate risks… Read More »

Roles and Liability

In essence, the main subjects are still the Controller and Processor, together with the Data Subject but a new figure appeared between Controller and Processor, the Data Protection Officer (see the specific category), as expert counselor on data protection issues. Pursuant to art. 77 of the Regulation, any person who has suffered damage as a result of unlawful… Read More »

Legal Framework

After a long consultation, on the 25th of January 2012, the Commission published the first draft of the proposal for a Regulation on the protection of individuals with regard to the processing of their personal data and on the free movement of such data (General Data Protection Regulation). The ordinary legislative procedure is still pending. The… Read More »