Author Archives: Silvia Stefanelli

About Silvia Stefanelli

Senior Lawyer, Owner Studio Legale Stefanelli&Stefanelli Specialized in: Health service legislation, e-Health, Privacy and Data protection, Product Legislation (CE Marking), National and International Agreements (sale and distribution in particular), Health Authorizations, Health Advertising, Corporate Compliance (Law nr. 231/2001)

First GDPR sanctions are underway: the German case

On 22 November 2018, the Baden-Württenberg Data Protection Authority (LfDI) announced, with a press release available here in German, of having imposed a € 20.000 sanction on the chat site Knuddels.de, for breach of Art. 32 of the GDPR. Knuddels is an online chat service that was popular in the 2000s, before the Facebook era.… Read More: First GDPR sanctions are underway: the German case »

The ‘good officer’ that controls our data. How to appoint a DPO

The appointment of the Data Protection Officer (DPO) is one of the most controversial points of the implementation of the new Reg. EU 2016/679 on data protection. The Data Protection Authority provides guidance on this matter through a series of FAQs. The DPO is a key figure that is mandatory for public and private health facilities… Read More: The ‘good officer’ that controls our data. How to appoint… »

Clinical trials and GDPR

Clinical trials data are the ones more frequently processed by pharma and medical device companies: trial centers are also involved in this data processing. Under the data protection legislation, pharma and medical device companies are controllers and trial centres are processor, most of the time. But these roles are not always clear. In the WP… Read More: Clinical trials and GDPR »

Data Portability impact on healthcare facilities

The new right  to data portability (art. 20 GDPR) shall also apply to health data. This interpretation is clearly illustrated in the recent Guidelines on the right to data portability, issued by the WP 29 on December, 13 2016. At point III, the Guidelines states three necessary conditions to apply the right:  personal data concerning… Read More: Data Portability impact on healthcare facilities »

European Commission presents EU-U.S. Privacy Shield

On February, 29 the European Commission issued the legal texts that will put in place the EU-U.S. Privacy Shield and a Communication summarising the actions taken over the last years to restore trust in transatlantic data flows since the 2013 surveillance revelations. The Commission has (i) finalised the reform of EU Data protection rules, which… Read More: European Commission presents EU-U.S. Privacy Shield »