By Federico Alessandri – Of Counsel – New Technologies and Cyber Security

foto avvocato Federico Alessandri, logo Bacciardi Partners, testo: The Italian Data Protection Authority has approved the ‘Code of Conduct for the processing of personal data by companies that develop and produce management software’. Published in the Official Gazette of 27 November 2024, this measure represents a significant novelty for Italian companies that develop management software, and aims to guarantee the protection of personal data right from the design of the software in full compliance with the principles of privacy by default and by design enshrined in Regulation (EU) No 2016/679 (GDPR).

What the Code of Conduct contains and why adhering to it can gain a competitive advantage

The Code of Conduct provides a set of guidelines and specific rules (best practices) for the processing of personal data by companies of all types and sizes (including SMEs) that develop and produce management software. It was developed with the intention of encouraging the adoption of technical and organisational measures to process personal data in accordance with the core principles of the GDPR.

The adherence to the Code of Conduct will be on a voluntary basis, but it is evident that it will soon constitute, even for those companies that do not adhere to it, a market benchmark with the consequence that developing software without complying with the provisions of the Code of Conduct regarding the design, development and management of software or providing assistance and maintenance without following the principles of safety and security will probably mean developing and marketing software that will not have the quality standard required by the market.

The contents of the Code of Conduct

The Code of Conduct sets out rules to ensure that data processing operations are carried out in a lawful, transparent and secure manner, minimising risks to the rights of data subjects. In particular, the code provides guidance on how companies in the sector should handle data, focusing on protecting the privacy of individual users and making companies accountable.
In particular, it provides:
On software design: developer companies must implement technical and organisational features that enable their customers to comply with the GDPR and ensure that risks related to personal data processing are assessed and mitigated during software development.
On data security and protection: developers must adopt documented technical and organisational measures to ensure the security of processing and the effective management of security incidents.
On contractual agreements on the processing of personal data: Relationships between developers and their clients must be formalised through specific agreements aimed at regulating the processing of personal data, with particular attention to cases where the developer acts as a data controller or sub-processor pursuant to Article 28 GDPR.

The Role of the Garante and the Monitoring Body

The Garante per la Protezione dei Dati Personali played a key role in the approval of this code, exercising the power of approval under the GDPR. In addition, it accredited the Monitoring Body (MoB) proposed by the Italian Association of Software Manufacturers (ASSOSOFTWARE), confirming that it meets the necessary requirements for monitoring compliance with the provisions of the code. The MNO will be independent, impartial and endowed with the necessary competences to perform its verification functions and will have the task of verifying compliance with the provisions of the code by its member companies.

Benefits for Companies

Businesses that adopt this code of conduct will reap several benefits. First and foremost, this measure represents a guarantee of compliance with the GDPR, an increasingly important factor for companies operating on the international scene and facing increasingly stringent data protection regulations. Moreover, adhering to the code helps to strengthen the company’s reputation by demonstrating a concrete commitment to data protection.

Conclusions

The Code of Conduct for the Processing of Personal Data by Management Software Companies is an important step towards the adoption of good practices in the processing of personal data in Italy. SMEs operating in this sector now have a clear framework to manage data correctly and securely, reducing risks and increasing transparency towards users. With the accreditation of the GMO and the official publication of the code, the Garante has provided an effective tool to ensure that data processing rules are properly complied with.

Interested companies will now have to adhere to the code, using the assistance of the GMO to monitor their compliance, while at the same time benefiting from the advantages of a data protection system in line with best practices.

Contact us

Bacciardi Partners can provide you with personalised assistance in GDPR compliance and implementation of best practices for the proper management of personal data.