MIFID II and GDPR Regulations

Following the mandate given by the European Commission, the European Securities and Markets Authority (ESMA) published its final technical advice on MiFID II on 19 December 2014, and on MAR on 3 February 2015. On 10 February 2016, the European Commission confirmed one year delay to the MiFID II timetable. The new target for implementation… Read More »

Record of processing activities

Article 30 of Gdpr “Records of processing activities” obliges the controller and processor to maintain a records of processing Activities under its responsibility. Specifically, that record shall contain all of the following information: the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer;… Read More »

Ethically GDPR

On last 15 March, during the three-days Clusit Security Summit, has been held in a full room of Atahotel Expo Fiera Rho-Pero, a meeting entitled “Practically GDPR” presented and moderated by Dr. Vallega in the formula of the “round table” with speakers – in addition to the president of Clusit – from companies representative of… Read More »

GDPR in practice

Everybody is talking about GDPR in every session at Security Summit this year, whatever the topic, but in practice what companies are doing to get prepared? Alessandro Vallega started from here to introduce the conference dedicated by Europrivacy to the new European Regulation, on the second day of the Summit organized by Clusit in Milan.… Read More »

How to engage processors

Articles 28 and 29 of the GDPR require a “by a contract or other legal act” in order to engage a processor. Such document must include: the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects; the confidentiality agreement; assurance that… Read More »