Full text
DIGITAL AND DATA SOVEREIGNY: THE APPLICABLE LEGAL FRAMEWORKS AND THE CASE STUDY OF THE IOT ENFORCEMENT AND MONITORING OF DATA SOVEREIGNTY POLICIES (EMDAS) TASK 1.1 - UNIVERSITY OF TRENTO GIORGIA BINCOLETTO, RAZMIK VARDANIAN, GIUSEPPE BELLANTUONO, ROBERTO CASO, MATTEO FERRARI, PAOLO GUARDA
Pag. 2 Sommario 1. “EMDAS” Project in the context of SERICS .................................................................................. 3 2. Task 1.1. Analysis of the requirements deriving from the study of laws and regulations on digital sovereignty ........................................................................................................................................ 3 3. The notions of digital and data sovereignty ..................................................................................... 5 4. The EU legal framework on digital and data sovereignty .............................................................. 7 4.1 Before the European Data Strategy: the data protection framework ................................................... 7 4.2 Before the European Data Strategy: the Open Data framework ........................................................ 14 4.3 Before and during the European Data Strategy: the cybersecurity framework ................................. 15 4.4 Digital identity and the eIDAS Regulation ........................................................................................ 19 4.5 The impact of the European Data Strategy ........................................................................................ 20 4.6 Focus: the Data Governance Act and the Data Act ........................................................................... 24 4.7 The AI Act, Digital Services Act, Digital Market Act and the European Health Data Space Regulation ................................................................................................................................................ 27 4.8 The Proposal of the Digital Omnibus of November 2025 ................................................................. 31 5. The Italian legal framework on digital and data sovereignty....................................................... 33 5.1 The data protection framework at national level ............................................................................... 33 5.2 The cybersecurity framework at national level ................................................................................. 37 5.3 The impact of the European Data Strategy in the Italian legislation ................................................. 42 5.4 Digital Identity and sovereignty prospects in Italy ............................................................................ 44 5.5. Analysis of the Italian regulatory architecture for the DSA and DMA ............................................ 47 5.6. The impact of the PNRR in the Italian legislation ............................................................................ 52 5.7 AI implementation in the Italian legislation: Legge 132/2025 .......................................................... 58 6. Some reflections on digital and data sovereignty .......................................................................... 60 7. Digital and Data sovereignty in the context of the Internet of Things: legal requirements and good practices to guarantee data protection and cybersecurity ............................................................ 65 7.1 Data protection in the context of IoT devices .................................................................................... 67 7.2 Adopting data protection by design & by default to achieve data sovereignty in the Iot context ..... 71 7.3 Security and cybersecurity in the IoT context ................................................................................... 72 7.4 More access and portability to IoT data: the application of the Data act .......................................... 75 7.5 Beyond the Data Act: technological infrastructures for IoT data sharing ......................................... 77 7.6 Governance of IoMT data: applying the Data Act and the European Health Data Space Regulation ................................................................................................................................................................. 78 7.7 Conclusions: policies for the IoT context .......................................................................................... 81 References .................................................................................................................................................. 89
Pag. 3 1. “EMDAS” Project in the context of SERICS This report has been prepared in the context of the research and innovation programme entitled ‘SEcurity and RIghts in the CyberSpaceSERICS’ - theme 7 ‘Cybersecurity, new technologies and protection of rights’ and in particular for the project: ‘Digital sovereignty’ (DISE), financed, following the call ‘Human, social, and legal aspects’, to carry out activities in Spoke 1, no. 2, CUP: B53C22003950001, of Mission 4 ‘Education and Research’, component 2, (PE 0000014) of PNRR. Within the DISE project, the project proposal ‘Enforcement and Monitoring of Data Sovereignty policies’ (EMDAS) was funded, for the benefit of the partnership composed of the lead partner University of Naples Parthenope and the partner University of Trento (UNITN). The project was placed in WP1 of DISE. As indicated in the EMDAS project, the partnership’s activities aim at enhancing the cybersecurity and resilience of digital infrastructures, by enabling trust mechanisms in the data exchange, which is vital for their development, given the importance of data sharing for innovative business and public administration services in Italy and in the European Union. The research considers the complexity of ensuring high standards of confidentiality and reliability throughout the life cycle of such data. EMDAS includes the study, research and experimentation activities on: legal aspects of cybersecurity and privacy and digital technologies (Task 1.1. Analysis of the requirements deriving from the study of laws and regulations on digital sovereignty); tools and technologies for digital and data sovereignty (Task 1.2 Technologies to support digital sovereignty in particular for the definition and semi-automatic understanding of regulations); technologies for network security, technologies for security and data protection in the energy and transport domains (Task 1.3 Analysis of some socio-economic aspects of digital sovereignty). This report is included in Task 1.1. and is the result of research work carried out at the University of Trento. The legal unit consists of Prof. Paolo Guarda, Prof. Giuseppe Bellantuono, Prof. Roberto Caso (till September 2025), Prof. Matteo Ferrari, the researcher recruited for the project Dr. Giorgia Bincoletto (from February 2025) and the collaborator Razmik Vardanian. This report has been authored by Dr. Giorgia Bincoletto, Prof. Giuseppe Bellantuono, Prof. Roberto Caso, Razmik Vardanian, Prof. Paolo Guarda and Prof. Matteo Ferrari. Also a separate report on a case study is written by Prof. Giuseppe Bellantuono. 2. Task 1.1. Analysis of the requirements deriving from the study of laws and regulations on digital sovereignty The research activity of Task 1.1 investigates various legal profiles related to the topic of digital and data sovereignty, considering cybersecurity and data protection issues upfront. The analysis was firstly started at a general level and then focused on three key technological contexts during the project. At a first level, it is necessary to analyse the existing and evolving legal framework on digital and data sovereignty in order to investigate whether it is adequate to deal with the new and constantly changing challenges posed by the digital world, while always aiming to achieve an optimal balance between public and economic interests and the protection of the individual, and promoting fair and inclusive governance of the digital ecosystem. From a general point of view, several legal problems arise.
Pag. 4 One aspect concerns the a-territoriality and transnational character that characterise phenomena relating to data and their circulation. One example is the data entrusted by users to cloud computing or the use of Internet of Things - IoT systems, which circulate across legal borders. The innovative scenarios of digital technologies pose significant problems with reference to the exercise of state jurisdiction, which is typically tied to the borders of its own territory and raise questions about the capacity of the individual nation state to effectively regulate data flows and guarantee the protection of citizens’ rights in a global digital context. Then emerges the issue of ownership and control over data as well as over the infrastructures on which it is stored. In the current scenario where the big companies in the technology sector hold considerable power, the issue of ownership and effective control over data and infrastructure is not an easy one to resolve. Another relevant legal issue concerns the relationship between data protection and transparency and openness, especially for the public sector. It is therefore necessary to balance on the one hand the protection of data, especially sensitive data, in the hands of the individual, and on the other hand transparency for the benefit of the public, while limiting access to details that could compromise security, in the sectors indicated by the most recent European legislation on cybersecurity, which include energy sector. From a private law perspective, the objective of ensuring traceability and control over the personal data contained in the profiles of users of digital platforms and over those, personal and non-personal, entrusted for storage by the platforms, is worth mentioning. An important role in these areas should be attributed, in addition, to the contract: it seems clear that the construction of a careful contractual regulation can at least contribute to the containment of the risk for the protection of the rights of data subjects. In analysing the issues related to the topic of data control and data movement, the principle of data protection by design, enshrined in Article 25 of the EU Regulation 2016/679 (so-called GDPR), will represent the reference point. This principle of the GDPR implies that data protection should be integrated into the entire life cycle of a given technology or service or process, right from its design: in other words, that any project should be realised with the end user’s privacy and the protection of his or her personal data in mind from the outset - by design, in fact - with all the necessary supporting applications (IT and otherwise). This is an increasingly used approach to the problem of data protection, aimed at guaranteeing the best possible operability of the protection: when the data controllers intend to process data, they must already have proactively planned a system that, even before the start of the activity, is able to guarantee the best possible protection. Therefore, it could be assumed when designing new products, services or any business initiatives, projects or technologies of key contexts to determine which measures can by design protect rights and enhance security and transparency. Risk analysis, assessed in the so-called Data Protection Impact Assessment, which also includes security aspects, is relevant too. An attempt will be made to propose guidelines that balance data protection and security with transparency requirements, both in the public and private sector. The analysis of the issues at hand therefore requires the adoption of a multidisciplinary approach that integrates regulatory and technical solutions to balance the protection of rights and the need to enhance the value of data. In particular, the methodology of law and technology (Law&Tech) is adopted. In Y1 the legal research was started on the notions of “digital sovereignty” and “data sovereignty”. Attention was first paid to definition and clarification. Then the research group collected and systematised laws, regulations and policies already in place and currently under development related to these notions in the European Union (EU) and the Italian legal frameworks. The research of Task 1.1 in Y2 was devoted to highlight the implications of the spread of digital technologies and data management and their data protection and cybersecurity issues in the following key contexts: 1. Internet of Things (IoT), which often uses cloud and artificial intelligence technologies and raises various issues of cybersecurity, privacy and information control by consumers; 2. Smart agriculture, given the digitisation of energy infrastructures, the deployment of smart meters and the creation of a common energy data space at European level;
Pag. 5 3. Smart energy, given the progressive digitisation of agricultural activities, with implications for the management of agricultural data and the role of intermediaries in this management. In addition to this report on the legal framework for digital and data sovereignty and the analysis of the IoT context, a power-point presentation has been created on “Digital and Data sovereignty in the context of SmartFarming: an in-depth discussion” and a deliverable has been drawn up in a separated report for the “Digital and Data sovereignty in the Energy Sector”. 3. The notions of digital and data sovereignty Firstly, it is needed to clarify what “digital sovereignty” means since it may be defined in several ways (Finocchiaro, 2022; Resta, Simonetti, 2022; Moerer, Timmers, 2021; Christakis, 2020; Floridi, 2020; ZenoZencovich, 2015). The concept has been described by legal scholars as the prerogative of states to impose rules on network activities and economics, even if they are transnational and global, and when they affect their own citizens (Mangiameli, 2023; Bertola, 2022; Simoncini, 2017). Cyberspace is not confined in territorial boundaries; then the possibility of the states to regulate phenomena is challenging (Catanzariti, 2024; Pierucci, 2025). Digital technology challenges the sovereignty of states, which is already severely tested by global markets (Casini, 2024). However, national countries believe that they have been progressively and unduly deprived of their ruling power by big Internet companies. They wish to regain control to promote their values and principles (Bertola, 2022; Ferrarese, 2022). The so-called “internal control paradigm” has been promoted by several countries all over the world, which are driven by their constitutional peculiarities (De Gregorio, Radu, 2023; Smorto, 2023). It has been reported that variants of digital sovereignty include cyber sovereignty, internet sovereignty, and information sovereignty (Roberts, 2024). As regards the position of the EU, in 2020, “digital sovereignty” has been defined as “Europe’s ability to act independently in the digital world” (Madiega, 2020). With its strategies of the last two decades, the EU decided to promote its leadership and strategic autonomy in the digital field. Being an EU “digital sovereign” implies creating both protective mechanisms and offensive tools to foster digital innovation in the Single Market, while safeguarding citizens’ rights, freedoms and liberties, which are recognised in the EU legal framework. The need of this new approach was attributed to the threats posed by high-technology companies, which are frequently based in non-EU countries and control the market of digital instruments and applications, managing Big Data flows (the so-called “Big-Tech”). As a result, it has been argued that the EU way to digital sovereignty is clearly political before legal (Finocchiaro, 2022; Resta, Simonetti, 2022). It has been reported that many EU institutions called for action to ensure the strategic autonomy of the EU and stressed the needs to protect EU’s data economy, ensure its global competitiveness to establish a secure and safe digital environment for citizens, by safeguarding privacy and data protection and other fundamental rights (Madiega, 2020). Scholars claimed that this approach can be also defined as the “strategic autonomy of the EU” (Casolari et al., 2023). The EU aims at preserving its core values and principles in the digital world, including human dignity, freedom, democracy, accessibility, equality, sustainability, the rule of law, and human rights. In the EU Commission’s communication on “2030 Digital Compass” 1 is stated that the EU should be «digitally sovereign in an interconnected world by building and deploying technological capabilities in a way that empowers people and businesses to seize the potential of the digital transformation, and helps build a healthier and greener society». Four cardinal points have been set out: 1 Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions 2030 Digital Compass: the European way for the Digital Decade. COM/2021/118 final.
Pag. 6 1. digital skills; 2. digital infrastructures; 3. digitalisation of businesses, 4. and of public services. Data regulation and policies play a crucial role in digital sovereignty since the digital economy is data driven. Data is at the basis of economic growth, competitiveness, innovation, and progress in general. Data is, in fact, regarded as the new raw material of the economy, an absolutely essential source for growth, innovation, and value creation. Therefore, a new term has been identified and found in documents, policies, and doctrinal contributions: “data sovereignty”. This term should be considered as an embedded component of digital sovereignty. Data is an essential resource for technological innovation, and its availability is fundamental for products and services, including the most advanced as the Internet of Things (hereinafter: IoT) and Artificial Intelligence (AI) systems. Data is considered an asset in the legal sense (e.g. Art. 810 of the Italian Civil Code) and may be the object of economic activity and trade. With the European strategy for data adopted in 2020 (“Data Strategy”) 2 , the EU laid down a path of policies and future legislation to create an EU single market for data. According to this strategy, “data sovereignty” implies re-gaining control over data in the digital market to use it in the economy and society of the EU. It means that the Union should find its “own way, balancing the flow and wide use of data, while preserving high privacy, security, safety and ethical standards”. The Commission explained that “data sovereignty” will be achieved by: ● the adoption of legislative measures on data governance, access and re-use. This implies improving data sharing; ● making data more widely available by opening up high value publicly held datasets across the EU and allowing their reuse for free. In particular, the EU aims at creating nine common data spaces in strategic sectors and domains of interest: the industrial (manufacturing), Green Deal, mobility, health, financial, energy, agriculture, public administration, skills, and common data spaces. The creation of these spaces needs infrastructural investments both at EU and national levels, the creation of governance mechanisms and new legislation for each contexts; ● investing in the development of data processing infrastructures, data sharing tools, architectures and governance mechanisms, federate energy-efficient and trustworthy cloud infrastructures and related services. Many projects already started this trend (e.g. Gaia-X); ● enabling access to secure, fair and competitive cloud services. This is a key aspect related to cybersecurity, and EOSC is one of the leading initiatives. In the European Declaration on Digital Rights and Principles for the Digital Decade it is specified that «the EU way for the digital transformation of our societies and economy encompasses in particular digital sovereignty in an open manner, respect for fundamental rights, rule of law and democracy, inclusion, accessibility, equality, sustainability, resilience, security, improving quality of life, the availability of services and respect of everyone’s rights and aspirations». It can be argued that there are two perspectives or categories of digital sovereignty: the more general and public one, which concerns the increase in power held by states (“collective sovereignty”), and the individual one, which concerns the power held by individuals and businesses with regard to threats in the digital world (“individual sovereignty”). It is important to investigate both perspectives. 2 Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions, A European strategy for data. COM/2020/66 final.
Pag. 7 Considering these strategies and the brief clarification of the terms “digital and data sovereignty” under EU policies, the work of Task 1.1. then focused on tracing the existing, evolving and applicable legal framework at EU level. 4. The EU legal framework on digital and data sovereignty It has been stated that the way in which a state exercises power over cyberspace is primarily given by legislation (Mangiameli, 2023). The EU tried to position itself as a leader in regulatory production to ensure that the European model becomes a global reference and can be adopted in other legal frameworks (Finocchiaro, 2022). With the “Brussels effect”, some EU rules have been imitated elsewhere (Bradford, 2020). Beyond the presented normative provisions, it should be pointed out that the primary law is usually integrated by the jurisprudence of the Court of Justice of the EU and when the EU law is a directive, the Member States’ law implementing the rules should be considered. In addition, a multitude of guidelines, recommendations, technical standards, and codes of conduct deal with privacy, data protection and cybersecurity. These documents are useful tools for the interpretation and application of primary law. This section summarizes the legal research carried out to collect the key legislative measures already adopted or planned for the immediate future on digital and data sovereignty by the EU. The following analysis will also show which rules empower people and businesses and help gain control over digital technologies. Once systematised the legal frameworks, the legal analysis will investigate whether these rules are adequate to handle the new and constantly changing challenges posed by the digital world, while always aiming at achieving an optimal balance between public and economic interests and the protection of the individual, and promoting fair and inclusive governance of the digital ecosystem. 4.1 Before the European Data Strategy: the data protection framework Before the implementation of the European Data Strategy, several pieces of legislation already involved the protection and control over data and set rules on cybersecurity. The first acts here presented can be considered preliminary, but essential solid bases for fostering digital and data sovereignty. In recent years, data protection has emerged as a pivotal legal context, significantly shaping the European digital economy. In contrast to other legal systems that, from a predominantly liberal standpoint, regard personal data as being of secondary importance in terms of consumer protection (e.g. the United States), the European Union has witnessed a process of elevating data protection to the status of an inalienable individual right through constitutionalisation (Rossi Dal Pozzo, 2020). This recognition was firstly enshrined in Art. 8 of the European Convention on Human Rights 3 , which pertains to the protection and respect for private life (i.e. “right to privacy”). That provision has been subject to interpretation by the European Court of Human Rights (ECHR), which has extended its application to the protection of personal data, recognising that the collection and processing of personal information can constitute an interference with the right to privacy (ECHR, 2024). 3 Art. 8: «1 Everyone has the right to respect for his private and family life, his home and his correspondence. 2 There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others».
Pag. 8 At EU level, the right to data protection is even more directly established in Art. 8 of the Charter of Fundamental Rights of the European Union (CFREU) 4 , which expressly states that everyone has the right to the protection of personal data concerning them, and that such data must be processed fairly, for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. It should be recalled that, pursuant to Art. 6 Treaty on European Union, the CFREU has the same legal value as the Union’s Treaties. Data protection as an EU fundamental right can be balanced with other rights according to Article 52 of the same Charter. In the European literature the right to data protection is conceived as part of the civil law category “diritti della personalità” - “droits de la personalité” - “derechos de la personalidad” (Alpa, Resta, 2019), meaning the notion that groups the individual rights that are granted to a natural person for protecting intimate spheres, private life and personality in a physical and psychological dimension in contrast with economic rights (e.g. right to property). In particular, the right to data protection gives to the natural person the information is related to, the power to claim fair and lawful data processing. Article 16 of the Treaty on the Functioning of the European Union provides the basis for EU legislation on data protection 5 . The European Union fundamental rights-centric approach to data protection led to the enactment of ambitious legislation, Regulation 2016/679 or “General Data Protection Regulation”, notably GDPR 6 . This Regulation, building on the initial harmonisation efforts of Directive 95/46/EC (Streinz, 2021), unified data protection across the entire EU, yielding a considerable global impact (s.c. Brussels Effect) (Brandford, 2012). It lays down the requirements applicable to every data processing activity in all the European Economic Area (EEA) since the act has been incorporated into the Agreement governing this framework. Scholars argued that the GDPR sets the global standard for data protection legislation (Kuner et al. 2020). Integrated within the Digital Single Market, the GDPR acts as a dual catalyst: it aims to guarantee the free movement of personal data between Member States, crucial for the development of a cross-border digital economy, while simultaneously ensuring a high level of protection for fundamental rights and freedoms, particularly the right to data protection (Caggiano, 2020). By adopting this approach, Europe elevates data protection to a constitutional safeguard, thereby seeking to transcend the “commodification of data”, i.e. its perception as a mere economic resource. The monetisation of personal data, by emphasising its significance primarily for advertising and consumer trend analysis, raises serious concerns due to information asymmetry and the potential manipulation of users through so-called “dark patterns”, i.e. manipulative techniques that fall into a grey area between legitimate commercial persuasion and undue influence on consumer decision-making (Gatelli, 2024). This process involves the commercialisation of an aspect intimately connected to individual identity and dignity. 4 Art. 8: «1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority». 5 Art. 16: «1. Everyone has the right to the protection of personal data concerning them. 2. The European Parliament and the Council, acting in accordance with the ordinary legislative procedure, shall lay down the rules relating to the protection of individuals with regard to the processing of personal data by Union institutions, bodies, offices and agencies, and by the Member States when carrying out activities which fall within the scope of Union law, and the rules relating to the free movement of such data. Compliance with these rules shall be subject to the control of independent authorities. The rules adopted on the basis of this Article shall be without prejudice to the specific rules laid down in Article 39 of the Treaty on European Union». 6 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), O.J. L. 119, 4.5.2016. Before the GDPR, data processing activities were regulated by the Directive 95/46/CE – Data Protection Directive.
Pag. 9 The drift from monetisation to the commodification of personal data is a subject of strong criticism and serious concern from many perspectives, including the legal one. This process risks transforming a fundamental individual right into a negotiable commodity, undermining informational self-determination and personal freedom, especially for the most vulnerable segments of the population who might be compelled to “pay” with their privacy to access essential services. Most recently, this is exemplified by the phenomenon of “cookie walls” which were the subject of a consultation by the Italian Data Protection Authority in 2025 (EDPB, 2024). Providing instruments to allow more control over personal data should be part of any data sovereignty strategy. The GDPR does not explicitly prohibit monetisation, even in the context of free data flow. However, the lawfulness of such practices is dependent on the existence of a valid legal basis, which is often identified as either the conclusion of a contract with the data subject or the provision of consent (Mursia, Trovato, 2021; Bataineha, Mizouni, El Barachi, Bentahara, 2016; Ricciuto, 2019). Other examples of lawful legal grounds are the compliance with a legal obligation and the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller 7 . It may be stressed that the GDPR serves as the cornerstone of this European regulatory framework. Characterised by its direct applicability across all Member States as regulation, it introduced groundbreaking principles and mechanisms. This Regulation represents a complex but key framework (Guarda, Bincoletto, 2021), and it contains some rules that should be carefully taken into account in EMDAS research since they may be considered manifestations of the notions of digital and data sovereignty. First of all, the GDPR redefined and reinforced the core principles of personal data processing: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability (Art. 5). These principles influence data governance. In particular, the principle of accountability requires controllers to demonstrate compliance with legal provisions, which implies that the data controller must proactively implement — based on an autonomous assessment of the risks arising from the processing — all necessary technical and organisational measures to prevent and mitigate them (WP29, 2010). Documentation should provide proof of compliance. The main reference is Art. 24 of the Regulation. Another defining features of the GDPR, which directly influence the data governance, is the application of data protection by design and by default requirements, aimed at embedding data protection from the initial system design and as a default setting (Cavoukian, 2011; Bincoletto, 2021), and the requirement for a Data Protection Impact Assessment (DPIA) for high-risk processing operations (EDPB, 2017). Art. 25 of the GDPR establishes a principle which will be adopted for the future analysis of the issues related to the topic of control over data and their circulation, and the use cases in specific contexts: “data protection by design”. This principle implies that data protection should be integrated into the entire life cycle of a given technology or service or process, from the beginning: in other words that any processing activity should be planned with the protection of data subjects’ personal data in mind from the outset - by design, in fact - with adequate organisational and technical measures. This is an increasingly used approach aimed at guaranteeing the best possible data protection: at the moment when the data controller intends to process data, he or she must already have proactively envisaged measures that protect data subject’s rights and during the processing these measures should be revised and updated according to the risks (Bincoletto, 2021). Then, controllers, both private and public entities which process personal data, shall implement appropriate technical and organisational measures that achieve data protection principles in an effective manner and integrate the necessary safeguards into the processing at the time of the determination of the means for processing and at the time of the processing itself. They shall consider some criteria, which are the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the same processing operations. Technical 7 Art. 6 GDPR. As regards particular data, the legal bases are provided by Art. 9.
Pag. 16 the basis for EU legislation in this matter since it refers to the harmonisation of national rules regarding the establishment and functioning of the internal market. The Directive NIS (2016/1148) 24 (NIS1) laid the groundwork for a first harmonisation of cybersecurity measures among the European Union (ENSA, 2016). NIS1 stipulated that Member States should adopt national cyber strategies, designate competent authorities and a Computer Security Incident Response Team (CSIRT; for both was designated the Agenzia per la Cybersecurity Nazionale), and establish security and incident notification obligations for Operators of Essential Services (OES) and Digital Service Providers (DSPs). Despite its importance, this Directive nevertheless showed significant limitations in the face of inconsistent transposition resulting from the excessive discretion granted to Member States, due to a heterogeneous identification of OES, lack of specificity in security obligation and incident notification and application of divergent standards and reporting practices (European Commission, 2020). This weakened the effectiveness of supervision and cooperation mechanisms, highlighting the need for a more prescriptive and more harmonised regulatory framework (ENISA, 2020). At the European and national levels, the regulatory response to cybersecurity challenges has intensified through the EU Cybersecurity Strategy for the Digital Decade. Its aim is to strengthen the EU’s cyber resilience, promoting its technological sovereignty and protecting critical data, services and interests with the introduction of a complex and articulated legislative corpus (European Commission, 2020). The Regulation (EU) 2019/881 25 , known as the Cybersecurity Act, marked a crucial step, enhancing the mandate of the authority in this matter: European Union Agency for Cybersecurity or “ENISA” (Markopoulou, Papakonstantinou, Hert, 2019) and establishing a voluntary European cybersecurity certification framework. The underlying ambition is to structurally elevate the level of trust in the digital market, promoting a paradigm shift through the adoption of the principles of “security by design” and “by default”. It is evident that these principles are interconnected by an underlying logic and are fully integrated with their counterparts in the GDPR. This integration is fundamental to ensure comprehensive protection within the cyber context. However, it is important to note that within this domain, these concepts evolve independently, thereby driving the development of a digital ecosystem that is inherently more resilient (and obviously concentrated only on security). The Act requires that security is no longer a belated addition or a mere feature (Del-Real, De Busser, van den Berg, 2025), but a fundamental requirement integrated into the entire architecture of ICT products, services, and processes from the very earliest design phases. This proactive approach aims to prevent vulnerabilities at the root, rather than correcting them retrospectively. The principle of “security by default” is a concept that is closely related to this. This principle ensures that, once the product is on the market, it is configured with the most secure settings active. This transfers the burden of protection from the end-user, who may not always be an expert, to the manufacturer, guaranteeing a high level of “out-of-the-box” security (Del-Real, De Busser, van den Berg, 2025). The joint adoption of these two principles is strategic for creating an intrinsically more robust digital ecosystem and for preventing the fragmentation of security standards in the internal market, thereby promoting a unified, distinguishable risk assessment model linked to European specificities. This results in the establishment of a European cybersecurity certification framework by the Cybersecurity Act (Art. 51) based on common cybersecurity criteria (Art. 54) and a harmonised risk assessment (Art. 52) with the objective of providing a uniform approach across the Union (Recital 66) to cybersecurity assessment. Although voluntary, certification 24 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. O.J. L. 194, 19.7.2016. 25 Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act), OJ L 151, 7.6.2019.
Pag. 17 based on such criteria can therefore become a de facto requirement, acting as a catalyst for greater and more homogeneous security. The subsequent Directive NIS2 (2022/2555) 26 arises precisely from the need to overcome the previous limitations, responding to a constantly changing threat landscape and the application inconsistencies that emerged among Member States (Stirone, 2023). NIS2 has thus set a more rigorous and harmonised approach, raising the common level of resilience in identified critical sectors. This Directive should be coordinated with Directive 2022/2557 on the resilience of critical entities (then, physical security) 27 , as explained in the Cybersecurity Strategy for the digital Decade 28 . With NIS2, NIS1 has been repealed. The qualifying element of the Directive NIS2 is its renewed adherence to the risk-based approach, which mandates that designated entities, classified as “essential” and “important”, must strengthen their cybersecurity and digital resilience according to the accountability principle (De Minico, 2025) analogous to the GDPR (ACN, 2022a). This system is overseen by the National Cybersecurity Agency (ACN), whose regulatory intervention translates normative principles into operational obligations. However, the burden of accountability is not limited to technical measures but directly involves top management: Art. 20 of the Directive, in fact, assigns to management bodies the responsibility for approving and overseeing cyber risk management strategies, exposing them to direct sanctions in case of non-compliance. This structure is reinforced by a more stringent incident notification regime (Amenta, Deluca, 2024), which imposes multi-stage reporting to the national CSIRT (within 24 and 72 hours), and by enhanced cross-border cooperation through the CSIRT Network (Schmitz-Berndt, 2023) and the EU-CyCLONe network (Radan, 2023). The entire regulatory framework, therefore, does not represent a mere compliance exercise but mandates a profound revision of cyber risk governance, placing entities before the challenge of having to demonstrate - and not just implement - a mature and resilient security posture. Complementing the NIS2 framework, further regulations, both sectoral and systemic, strengthen the European digital resilience system, creating a comprehensive legislative ecosystem. Furthermore, the Regulation (EU) 2022/2554 (DORA) 29 introduces a harmonised regime for the financial sector (Buttigieg, Zimmermann, 2024), based on five pillars: i) a rigorous ICT risk management framework; ii) a unified incident reporting system; iii) a digital operational resilience testing programme which for critical entities includes advanced Threat-Led Penetration Testing (TLPT); iv) granular management of third-party risk with direct oversight of critical providers; v) and the promotion of threat intelligence sharing (Annunziata, 2024). While DORA focuses on digital resilience in a particular critical sector, the Regulation (EU) 2024/2847 (Cyber Resilience Act - CRA) 30 shifts the focus on “upstream”, imposing security obligations directly on 26 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive), OJ L 333, 27/12/2022. Before, the Directive (EU) 2016/1148 (NIS 1 Directive), which was the first piece of legislation on cybersecurity, was applicable. 27 Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC, OJ L 333, 27.12.2022. 28 European Commission on High Representative of the Union for Foreign Affairs and Security Policy, Joint Communication to the European Parliament and the Council, The EU’s Cybersecurity Strategy for the Digital Decade, JOIN (2020)18finale. 29 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, O.J. L. 333, 27.12.2022. 30 Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act), OJ L 2024/2847, 20.11.2024.
Pag. 18 manufacturers of products with digital elements. This means that CRA will have a significant impact on the security of the IoT and, indirectly, on 5G infrastructures, addressing the inherent vulnerabilities of these ecosystems. All manufacturers must conduct risk assessments, apply the CE marking as an attestation of conformity, provide security updates for a defined period, and, crucially, notify ENISA within 24 hours of any actively exploited vulnerability (European Commission, 2022). If the CRA acts preventively on product security, Regulation (EU) 2025/38, i.e. the Cyber Solidarity Act (CSA) 31 , conversely, intervenes to strengthen the Union’s reaction capacity and mutual assistance, establishing a common operational framework (Villani, 2025). Falling within cybersecurity policies, the CSA aims to strengthen the EU’s capabilities to detect, prepare for, and respond to significant and large-scale threats and attacks. This is structured around mechanisms such as a European alert system based on a network of Security Operations Centres (SOCs), an Emergency Mechanism which includes a “European Cybersecurity Reserve” of trusted providers, and an Incident Review Mechanism for drawing ex-post lessons. Finally, the ENISA is the technical and operational lynchpin of the entire ecosystem. Its mandate, originating from the Cybersecurity Act, has been progressively expanded. Pursuant to NIS2, it manages entity registers for specific categories of entities that provide cross-border services (i.e. DNS service provider, top-level domain (TLD) name registries, cloud computing service providers). With the CRA, it becomes the central reference point for vulnerability notification, acting as a central hub for the coordinated management of vulnerabilities at a European level. Moreover, the Cybersecurity Act provides for the establishment of the European Cybersecurity Reserve and formally defines ENISA’s corresponding duties. These operational mechanisms and ENISA’s central role represent the concrete expression of a much broader European regulatory strategy, progressively strengthening and harmonising. This vision, whose fundamental pillars are illustrated in the following table, aims to consolidate true “digital sovereignty” by creating a unified and secure digital space. It does this by ensuring that the EU has control over its data, technology, and infrastructure, reducing dependence on external actors (i.e. collective EU sovereignty). This proactive approach elevates cybersecurity from a purely technical issue to a foundational element of economic competitiveness and common security (Bellanova, Carrapico, Duez, 2022). By setting high standards and adopting a coordinated approach, Europe is building a digital ecosystem that is resilient, trustworthy, and aligned with its core values, ensuring its autonomy in the global digital landscape (European Commission, 2025). The following table shows the complex cybersecurity framework applicable at EU level. Law Objective Subjects interested Regulation 2019/881 (Cybersecurity Act) ENISA upgrade: establish EU cybersecurity certification framework. ENISA, ICT producers/deployers, certification bodies. Directive 2022/2555 (NIS2) Strengthens and expands NIS1 obligations, improves cooperation and crisis management. “Essential” and “important” entities across multiple sectors (energy, transport, health, digital, public administration, etc.). 31 Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents and amending Regulation (EU) 2021/694 (Cyber Solidarity Act), O.J. L. 2025/38.
Pag. 19 Regulation 2022/2554 (DORA) Digital operational resilience for the financial sector. Financial entities (banks, insurance companies, investment firms, etc.) and their critical third-party ICT service providers. Regulation 2024/2847 (Cyber Resilience Act) Cybersecurity requirements for products with digital elements (“security by design” and lifecycle). Manufacturers, importers, and distributors of hardware and software products with digital elements. Regulation 2024/223 (Cyber Solidarity Act) Strengthens EU preparedness and response to large-scale cyber threats and incidents. Member States, EU institutions, ENISA, cybersecurity hubs, cybersecurity service providers (for the EU Reserve). The following section will present another relevant framework that may improve digital and data sovereignty. 4.4 Digital identity and the eIDAS Regulation The notions of “digital and data sovereignty” include the issues of the digitalisation of public services. In the EU Commission’s communication on “2030 Digital Compass” it is stated that public services should be fully accessible online for everyone, embedding tools with high security and privacy standards. The deployment of a trusted, user-controlled digital identity is fundamental to achieve this goal. In this sector, Regulation 910/2014 “on electronic identification and trust services for electronic transactions in the internal market” (Reg. eIDAS) should be briefly mentioned and studied since it sets rules on identification, authentication and digital identity 32 . This Regulation has been recently revised in 2024 with significant new rules by Regulation 2024/1183 33 . This last act, in fact, created the EU digital Identity Framework. The Member states should create new secure means to manage identity for many private and public purposes. In brief, Regulation 910/2014 contains a uniform framework for identity and authentication, it lays down conditions for the mutual and cross-border recognition and interoperability of electronic identification means and schemes between Member States and for the creation of the European digital identity wallets. It also provides rules for trust services for electronic transactions and sets requirements for several technical and electronic solutions: signatures, seals, time stamps, documents, registered delivery services, certificate services for website authentication, archiving, attestation of attributes, signature creation devices, seal creation devices and ledgers. The European digital identity wallet aims at «ensuring that all natural and legal persons in the Union have secure, trusted and seamless cross-border access to public and private services, while having full control over their data» (Art. 5a Reg. 2024/1183). The wallet should be provided at Member state level. As a result, with 32 Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC, OJ L 257, 28.8.2014. 33 Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. PE/68/2023/REV/1. O.J. L. 2024/1183, 30.4.2024.
Pag. 20 one digital wallet the user can authenticate to a wide range of services, store and share digital documents, and sign in a way that is legally binding. Since the system is implemented at national level, 27 versions of the wallet will be created but the technical standards should be the same. The software should be open and based on the Architecture and Reference Framework 34 . Wallet providers will provide the software on behalf of Member States. Mobile applications will be developed. The eIDAS Regulation represents an important point of reference for public administrations, businesses and citizens dealing with online public services. The digitalisation of these services is essential for the digital transformation of the EU and its digital sovereignty. Having a digital identity is the inevitable requisite to being able to access to public services, which may include the request of birth and medical certificates, the possibility to store a medical prescription that can be used anywhere in the EU while travelling, but also the opportunity to report a change of address, to file tax returns and even to apply for a university or a job position. From 2026 the European Digital identity framework will be fully operative. A single authentication method and access to all digital public services provided by public administrations empowers citizens and businesses and simplifies the administrative burden. In this way, data related to natural and legal persons and held by public bodies is accessed more easily and then is subject to more control. The use of the wallet is free of charge for non-professional purposes. For these purposes, charges will be imposed. The identity mechanism should be secure, reliable, and user-centric. The implementation of security measures, including encryption and verification protocols, is necessary to protect identity against fraud. It has been argued that the digital identity model should be the result of an interplay of technical and legal aspects (RoblesCarrillo, 2024). This framework should be coordinated with the data protection and cybersecurity frameworks analysed above. Regulation 2024/1183 takes into account the data protection issues while requiring data minimisation (only essential data is shared), mandating the limitation of tracking and profiling and promoting the creation of a privacy dashboard to directly control personal data. It is necessary to implement privacy and “security by design”. It may be argued that the creation of the EU digital Identity Framework is promising. However, some problems may be briefly mentioned. Firstly, what will happen to the digital identity systems already in place in the Member states is not clear. There have already been many private and public investments. Who will bear the economic consequences? Moreover, given the potentiality to collect personal data of many areas of life, the government surveillance risk should be avoided. With a single wallet supplier, even the risks and consequences of cyberattacks increase. The impact on individuals’ lives will be greater with a single wallet that includes information on health, work, finance, travelling, etc. The traditional way to verify identity should be maintained for those who are disconnected or do not have the skills to be online, e.g. elderly people. Infrastructures and technologies should be concretely reliable and trustworthy. A public-private cooperation between EU actors is desirable to avoid dependence on very large and private non-EU online platforms. Other new frameworks created under the European Data Strategy are investigated in the next section. 4.5 The impact of the European Data Strategy 34 See https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/latest/.
Pag. 21 The European Data Strategy, put forth by the European Commission, aims to establish a single digital market for data, fostering its free flow within the European Union and across different sectors in a transparent and fair manner. Representing the next phase after the Digital Single Market (Rossi Dal Pozzo, 2020), the Strategy seeks to dismantle barriers hindering the free movement of data to enhance the competitiveness and innovation of European businesses and data economy. The governance of the digital transformation directly steers towards the concept of ‘EU digital sovereignty’, fighting for the preservation of EU core values and principles in the digital world (Casolari, Buttaboni, Floridi, 2023). The primary objective of the Strategy is to grant individuals and businesses greater control over their data and how it is used, by setting a clear, equitable and trustworthy regulatory framework for data access and use, ensuring personal data protection and fair competition (Poletti, 2022).To achieve this, the Commission intends to create a data market where data — akin to movable goods — can be exchanged, processed, and utilised, without prejudicing fundamental individual rights, particularly the right to personal data protection (Falletta, Marsano, 2024) and competition law (Amram, 2023). The European Union pursues a distinct trajectory compared to dominant global tech entities, aiming to balance the dynamism and extensive use of data with high standards of privacy, security, protection, and ethical principles, placing the individual at its core (Poletti, 2022b). The European strategy aims to facilitate and regulate this flow within the EU while maintaining high protection standards (Carvalho, Kazim, 2022). This entails creating mechanisms that enable data exchange for purposes such as scientific research, innovation, and international cooperation, ensuring such exchange occurs securely and transparently. The challenge lies in striking a balance between promoting a dynamic data economy and safeguarding fundamental individual rights. In seeking to identify this balance, the European data strategy is articulated across four pillars: i) establishing an enabling legislative framework (including various legislative initiatives on the subject); ii) investing in data, digital technologies, and skills; iii) creating common European data spaces in strategic areas; and iv) empowering European businesses and citizens (Sganga, 2022). A central element is the creation of interoperable common European data spaces in strategic economic sectors and areas of public interest. These spaces aim to overcome legal and technical obstacles to data sharing between organisations. More specifically, the strategy is directed at: 1. structuring the governance of common European spaces, founded on the principles of data Findable, Accessible, Interoperable, and Reusable and facilitating easier conditions for individuals to give consent for the use of their data (data altruism) (Ruohonen, Mickelsson, 2023); 2. identifying high-value datasets to be made publicly available for free and with easy access; 3. incentivising horizontal data sharing across sectors, both between businesses (B2B) and between businesses and public administrations (B2G), addressing issues related to usage rights for generated data, and intervening in intellectual property legislation to further enhance data access and use, with particular regard to database regulations (Sganga, 2022; Martella A., Martella C., Longo, 2025). 4. creating common European data spaces - decentralised, governed and standard-based structures enabling voluntary data sharing between participants - in the following areas: ● industry (manufacturing); ● the Green Deal (environmental issues); ● mobility; ● health; ● the financial sector; ● energy; ● agriculture; ● public administrations; ● skills; ● and the European Open Science Cloud (EOSC).
Pag. 22 These spaces will be interconnected cloud infrastructures that will overcome the legal, organisational, semantic and technical barriers to data sharing across Europe (van der Valk, Ryan, 2025). From 2020 to date, the European legislator has therefore initiated an intense legislative process aimed at implementing the data strategy and defining boundaries and rules in terms of digital spaces. This process culminated with the publication of the Data Governance Regulation and the Data Act (v. infra), considered the fundamental pillars of the strategy, and most recently with the European Health Data Space (EHDS), which represents the first regulation of a sectoral space. All these acts comprise the European Data Spaces which, by harmonising domestic legislation and establishing a unified, interconnected, and holistic framework, will enable the valorisation of data as common European knowledge. An illustration of this is the widespread adoption of the risk-based methodology, which aims to ensure a uniform framework for safeguarding data subjects by mitigating inherent risks to their fundamental rights by design, depending on the processing activity undertaken (Amram, 2023). The following table represents the result of the analysis of the whole framework adopted or in progress at EU level. Category Legal Act Summary and main contents Status and application Regulation 2022/868 (Data Governance Act - DGA)35 It facilitates data sharing by creating a framework for the reuse of sensitive public sector data, data intermediation services, and data altruism. In force since 23 June 2022, applicable from 24 September 2023 Regulation 2023/2854 (Data Act)36 It grants users the right to access and share data generated by connected products (IoT) and related services. It establishes obligations for data holders and contractual rules. Entered into force on 11 January 2024, applicable from 12 September 2025. Some provisions will apply at a later date. Vertical Legislation (Specific Sectors) Regulation 2025/327 (European Health Data Space - EHDS)37 It facilitates access to and exchange of electronic health data for primary care and secondary purposes (including research and innovation). Published on 5 March 2025. In force from 25 March 2025, with gradual application from 2027 to 2034 for various provisions. 35 Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act), O.J. L. 152, 3.6.2022. 36 Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act). O.J. L. 2023/2854. 22.12.2023. 37 Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847, O.J. L., 2025/327, 5.3.2025.
Pag. 23 Financial Sector (PSD2/3, PSR, Digital Finance Strategy) PSD2 (Directive (EU) 2015/2366)38 introduced open banking, allowing the sharing of financial data with third parties (with consent). PSD3 and PSR (mere proposals): they aim at revising PSD2 to strengthen open banking and security. Digital Finance Strategy aims to create a European financial data space. PSD2 in force from 2018. PSD3/PSR: legislative proposals, under negotiation. Energy Sector (Internal Market Directives, Reg. 2019/941) It promotes the sharing of smart meter data and access to data for final customers and energy service providers (e.g., Directive (EU) 2019/944, Directive (EU) 2024/1711 on the right to energy sharing). In force, with various transposition and application deadlines for Member states (e.g., right to energy sharing by 17 July 2026)39. Resolution 158/2024/R/COM (and previous ones such as 270/2019/R/COM) This resolution (and its updates) governs the methods for making metering data (electricity and natural gas withdrawal and injection) available to final customers and, upon their delegation, to authorised third parties (e.g., energy service providers, ESCo, aggregators). It aims to empower consumers and foster the development of new data-driven services. Resolution 87/2016/R/eel (and subsequent updates) This resolution defined the functional requirements and timelines for the implementation of 2nd generation smart metering systems. It established the technical specifications for meters and for data collection and transmission, creating the necessary infrastructure for the availability of granular data. Transport Sector (ITS Directive, Mobility Data Space Initiatives) This is the framework for the coordinated deployment of intelligent transport systems (ITS), encouraging the exchange and reuse of traffic and mobility data (e.g., Directive (EU) 2010/40 and amendments such as Directive (EU) 2023/2661). In force, with recent amendments 38 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC, O.J. L. 337, 23.12.2015. 39 Not yet implemented in Italy.
Pag. 24 strengthening data sharing40. The following section focuses on the two acts that may be directly connected to “data sovereignty”. 4.6 Focus: the Data Governance Act and the Data Act As anticipated, within the Data Strategy, two key pieces of legislation have been already put in place on data governance, access and reuse: ● Data Governance Act (DGA), which covers both personal and non-personal data and adds conditions for the re-use of certain categories of data held by public sector bodies, except for the categories of data regulated by the Open Data Directive, which fall outside of its scope; and ● Data Act (DA), which has been adopted but will apply from 12 September 2025, and seeks to enhance the interoperability of data and sharing mechanisms and services in the EU 41 . Both Acts give precedence to the GDPR, meaning data protection law should be carefully considered and coordinated. The DGA complements the ODD and it is the first act to define “data” under EU law as follows: «any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audiovisual recording». As pointed out by Resta, this definition shows that the regulation creates a system of rules that is no longer aimed at protecting assets because they are linked to a person (as in the case of the GDPR and the definition of personal data), but rather at defining rules on the circulation and use of data in relation to their formal structure (Resta 2022). The DGA also defines data sharing as «the provision of data by a data subject or a data holder to a data user for the purpose of the joint or individual use of such data, based on voluntary agreements or Union or national law, directly or through an intermediary, for example under open or commercial licences subject to a fee or free of charge» 42 . So, intermediation services will be created between data holders and those who want to use data by the EU and Member States law. In brief, this regulation provides rules for three important aspects: 1) the re-use of data held by public bodies (Chapter II); 2) the creation of the intermediation services for the data exchange (Chapter III); and 3) the creation of the possibility of allocating data for altruist purposes (Chapter IV). The re-use of data held by public sector bodies refers to certain categories of protected data, meaning information protected on grounds of commercial confidentiality, including business, professional and company 40 Directive (EU) 2010/40 was originally implemented in Italy with D.L. n. 179/2012, converted to L. 211/2012. The Directive (EU) 2023/2661 is not yet implemented. 41 Recital 5 DA. 42 Art. 2, par. 10, DGA.
Pag. 25 secrets, statistical confidentiality, of the protection of intellectual property rights of third parties or the protection of personal data (Art. 3 DGA). As anticipated, this data should fall outside the scope of ODD. Intermediation services will create a data marketplace and make data available under commercial terms between data holders and data users. It should be stressed that the data holder may not be the same entity as the data controller. When the personal data is shared by a data holder, the data controller still remains responsible for granting data subject rights. National competent authorities for data intermediation services are defined by Member States law. The DGA also introduces a new legal concept that seems particularly promising but challenging at the same time: “data altruism”. This term means «the voluntary sharing of data on the basis of the consent of data subjects to process personal data pertaining to them, or permissions of data holders to allow the use of their non-personal data without seeking or receiving a reward that goes beyond compensation related to the costs that they incur where they make their data available for objectives of general interest as provided for in national law» 43 . The data holder, who has the right to grant access to or to share certain personal data or non-personal data, releases data to the data altruism organisation for general public interest purposes. The data subject can do the same on the basis of their consent. It has been argued that data altruism is not a new phenomenon, and it is connected to ethical aspects and morality (Paseri, 2024). Bravo demonstrated how data altruism is connected with the notion of solidarity (Bravo, 2023). The concept of a voluntary consent for sharing data for general purposes should be aligned to the notion of consent in data protection law. Moreover, this notion of general public interest is not defined at the expense of legal certainty. Data altruism requires further national arrangements by Member States and the European Commission. Therefore, the risk of fragmentation arises. Resta argued that in the absence of substantive provisions that truly harmonise the DGA’s altruistic consent, the rule risks becoming a mere facade, like a “regulatory marketing device” with no impact. (Resta, 2022). The DGA is an example of a cross-sectoral governance framework for data access and reuse as well as the Data Act (Casolari et al., 2023). This section analyses this Act with particular attention since its norms will be relevant for the case study on IoT. The Data Act, formally adopted on 13 December 2023 and scheduled for full applicability from 12 September 2025, introduces a harmonised regulatory framework designed to ensure fair access to and use of data across the European Union. This legislative initiative seeks to dismantle barriers that impede consumers and businesses from accessing data generated by connected products, often referred to as the IoT devices, thereby serving as a catalyst for the burgeoning data economy and UE’s digital sovereignty. Its scope signifies a strategic evolution in EU regulation, moving beyond a singular focus on personal data protection - as embodied by the GDPR - towards a broader economic regulation of data. At the heart of this new framework are the concepts of “product data” and “related service data”, which delineate its regulatory ambit. Product data is defined as data generated through the use of a connected product that the manufacturer has designed to be retrievable 44 . Concurrently, related service data refers to data representing the digitisation of user actions or events associated with that product 45 . This is intrinsically linked to a related service, understood as a digital service whose absence would prevent the product from performing one of its main functions. Crucially, the Act applies to this data in its “raw and pre-processed” state, encompassing information on the performance, use, or environment of the connected product 46 . However, the Act’s reach is not unlimited; its application is carefully circumscribed by the principle of readily available data. The obligations apply only to data that a data holder can access without disproportionate effort. This qualification sets a practical boundary on the duty to provide access and intentionally excludes data 43 Art. 2, par. 16, DGA. 44 Art. 2, nn. 15 Data Act. 45 Art. 2, nn. 16 Data Act. 46 Recital n. 15 Data Act.
Pag. 32 under Art. 9 GDPR may be processed during the training and review phases of AI systems to correct existing biases 66 . The reformist framework aims to overcome the current regulatory dichotomy by creating two single reference texts: the GDPR for personal data and the Data Act for non-personal data. In addition, a structural change involves the absorption of cookie rules (currently in the e-Privacy Directive) into the GDPR. The new technical-legal paradigm envisages centralising consent management via browser or operating system settings. This mechanism aims to reduce user “consent fatigue” on banners and rationalise the browsing experience, overcoming the fragmentation of current cookie practices 67 . Secondly, the proposal codifies the principles expressed in CJEU Case C-413/23 (EDPS vs. SRB) regarding the definition of personal data and introduces a statutory definition of “pseudonymous data” 68 . These interventions aim to provide univocal interpretative criteria for the secure circulation of datasets, elevating jurisprudential orientations and EDPB Guidelines to legislative status. The case involved many issues including the concept of pseudonymisation under EU law (Regulation 2018/1725 and the GDPR). According to the Court, the assessment on whether data is pseudonymous or anonymous depends on the recipient’s perspective. Therefore, the interpretation is subjective: if, looking at the concrete circumstances, the entity is not reasonably able to identify the data subject, the data is not personal. When the identification effort is disproportionate in terms of time, cost, and labour, data should not be considered personal. The Proposal then takes into account this interpretation by clarifying that “information is not to be considered personal data for a given entity where that entity does not have means reasonably likely to be used to identify the natural person to whom the information relates”. As a third theme, the Omnibus formalises legitimate interest as a legal basis for AI system training, evolving the interpretative direction of EDPB Opinion 28/2024. The proposal reduces the rigidity of the balancing test, orienting the weighing of interests in favour of the controller’s innovation and research needs, while maintaining procedural guarantees for data subjects unchanged 69 . This regulatory reconfiguration aims to support industrial competitiveness, although the distributive effects between European operators and non-EU tech platforms require empirical verification. On the transparency front, a revision of Artt. 12-13 GDPR is proposed, introducing an exemption from information obligations if there are “reasonable grounds” to believe the data subject already possesses the information, provided the processing presents low risk and does not involve transfers to third parties 70 . This modification marks a shift from a clear, stable rule to a more flexible solution. It will be necessary to concretely define reasonable grounds and the methods of ascertainment by the controller, requiring more careful assessment and justification by organisations in implementation of the accountability principle. The proposal also aims for European-level harmonisation of lists of processing activities requiring or exempting a DPIA 71 . However, analogous instruments already exist, as EDPB guidelines provide criteria and examples. The introduction of further lists risks emptying the accountability principle of meaning, transforming a dynamic assessment obligation into a mere formal compliance exercise. The reform also introduces potentially relevant changes to data subject rights 72 , with possible limitations that merit careful evaluation, especially in light of the central role these rights play in the GDPR structure and the digital acquis. Regarding cybersecurity and incidents reporting, the Omnibus proposes creating a single entry point, managed by ENISA with EDPB support, for cyber incident reporting envisaged by NIS2, GDPR, DORA, eIDAS 2.0, 66 Art. 1, par. 5, of the Proposal. 67 Art. 3, par. 12 e Art. 5 of the Proposal. 68 Recital 27 and Art. 3, par. 1 of the Proposal. 69 Recital 30-31 and Art. 3, par. 15 of the Proposal. 70 Recital 36 and Art. 3, par. 5 of the Proposal. 71 Recital 40 and Art. 3, par. 9, of the Proposal. 72 Recital 35 and Art. 3, par. 4, of the Proposal.
Pag. 33 and the Cyber Resilience Act 73 . This institutionalises an integrated approach to digital compliance, simplifying organisational activities connected to reporting obligations. This modification intertwines with the extension of the deadline for notifying a data breach to the data protection authority, from the current 72 to 96 hours 74 . This change raises questions about its utility: the NIS2 Directive already mandates a pre-notification within 24 hours. By defining a single channel, this extension would effectively render a longer GDPR deadline superfluous. Furthermore, notification would only be required for breaches entailing a high risk to the data subject, prompting several critical considerations regarding the appropriateness of this amendment. The proposal intervenes on data governance by consolidating the Data Governance Act, the Data Act, the Free Flow of Non-Personal Data Regulation, and the Open Data Directive into a single regulatory act. This reorganisation aims to resolve conflicts between different regulatory clusters, ensuring legal certainty in the discipline of information access and reuse 75 . However, merging these sources exposes the system to the risk of new interpretative complexities, subordinating effective simplification to the systematic coherence of the final text. In conclusion, the reform framework highlights a potential tension between administrative efficiency objectives and the protection of the data subject’s informational sovereignty. The legislative process, now submitted to the Parliament and Council for review, will determine the final balance between the competitiveness needs of the digital market and the safeguarding of fundamental rights. It’s worth mentioning that the proposal already reveals certain critical issues that risk structurally weakening the GDPR by transforming objective definitions (such as that of “personal data”) into subjective evaluations based on the data controller’s or recipient capabilities. Furthermore, there is a tendency to favor technologies such as AI and vague commercial purposes like “innovation” to the detriment of fundamental rights, limiting crucial tools such as the right of access and reducing the obligations to notify breaches to the authorities (Noyb, 2025). At present, it is unclear how the text will proceed. Some proposed provisions seem close to an approach of deregulation. In fact, the adopted regulatory technique shows that the EU legislator aims at rationalising the number of digital-related acts. Fragmentation may be limited but the impact on the issues of digital and data sovereignty should be studied. At a first analysis, it may be argued that the new possible interpretation of the concept of personal data limits the application of the GDPR. This may impact data sovereignty. The EU has a prominent role in regulating the issues at stake. However, the importance of Member States law should not be underestimated. The following sections deal with Italian law. 5. The Italian legal framework on digital and data sovereignty The following sections focus on the Italian legal framework to understand how and how far the state is dealing with digital and data sovereignty. The implementation of the NIS2 Directive is also considered as well as the other rules adopted in the context of the Data Strategy. 5.1 The data protection framework at national level Despite its directly applicable nature, the GDPR does not exhaust the entire body of data protection law. It is embedded within a multi-layered system that also necessitates careful consideration of national domestic 73 Recital 49, Art. 6, par. 1 and Artt. 7, 8, 9 of the Proposal. 74 Art. 3, par. 8 of the Proposal. 75 Recital 21 e 22 and Art. 1 of the Proposal.
Pag. 34 legislation. Indeed, numerous GDPR provisions contain specific clauses or cross-references that empower Member States to legislate on particular or sectoral aspects. In addition, ample space is reserved to national specifications on singular issues (e.g. data concerning health, criminal and labour aspects). In Italy, this was implemented through D.lgs. n. 101/2018, which amended the pre-existing D.lgs. n. 196/2003 (the Italian Data Protection Code, hereinafter: “Codice Privacy”) to align it with the GDPR and to introde supplementary provisions in specific areas. So, the main reference to Italian data protection law is the Codice Privacy. Then, other laws should be mentioned for the specific context of processing. A notable instance is labour protection, where Art. 4 of L. 300/1970, despite its amendments and interaction with the GDPR, continues to govern electronic surveillance of employees (Turco, 2019). Moreover, D.lgs. n. 51/2018, which transposed Directive (EU) 2016/680 on the protection of individuals regarding data collected and processed by competent authorities for law enforcement purposes, regulates the processing of personal data and the data subject rights within the criminal justice context (Ricci, 2019; Galgani, 2019). Adding to this legislative complexity is the vital role of regulatory interventions by the National Supervisory Authority, the Italian Data Protection Authority, i.e. Garante per la Protezione dei Dati Personali, through its various provisions, guidelines, opinions, and the approval of codes of conduct and ethical rules. These interventions foster a consistent application GDPR (Colapietro, 2018) - including the potential intervention of the European authority (European Data Protection Board) through the consistency mechanism outlined in Art. 60 GDPR - tackling crucial arguments on complex and continually evolving issues. Examples of this regulatory function include the “Regole deontologiche” for processing personal data in journalistic activities or for scientific and statistical research (also relevant for the application of Art. 110 Codice Privacy) (Bincoletto, 2024), and more recent sectoral Codes of Conduct, such as those for telemarketing activities or the development of management software. However, the Garante’s sustained regulatory activity has also and sometimes drawn criticism, stemming from a perceived contradiction between specific requirements set out in certain measures and the principle of accountability, which should, conversely, allow data controllers to independently assess and justify the architecture of their own privacy governance (Orefice, 2024; Pelino, 2024). The following table shows the current and stratified legal framework governing personal data protection, which encompasses regulations from the European to the national level. The discipline is rooted in key European legislation that establishes the overarching principles for the collection, processing, and movement of personal data, including frameworks for law enforcement and electronic communications. This is complemented by Italian local laws that provide supplementary provisions, implementing or specifying the European rules in specific contexts like journalism, labour law, and new technological fields such as telemarketing and software development. Category Legal reference Description and Key Points EU Primary and Secondary Legislation Regulation 2016/679 (GDPR) General Data Protection Regulation. It provides the general framework for processing personal data. Directive 2016/680 Law Enforcement Directive governs the processing of personal data by law enforcement authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Directive 2002/58/EC (e-Privacy Directive) It particularly concerns cookies, electronic communications, and new technologies.
Pag. 35 National Primary and Secondary Legislation D.Lgs. 30 giugno 2003, n. 196 (Codice Privacy) It initially implemented Directive 95/46/EC, now repealed by the GDPR. Subsequently, it was amended by Leg. Dec. 10 August 2018, no. 101 to comply with the GDPR. It contains supplementary provisions to this Regulation. D.Lgs. 10 agosto 2018, n. 101 It amended the Codice Privacy. D.Lgs. 18 maggio 2018, n. 51 It implements the Directive (EU) 2016/680 concerning the processing of personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. Art. 4 L. 300/1970 It governs the use of audiovisual equipment and other remote monitoring tools, limiting the use of employees’ personal data. D.Lgs. 10 agosto 2023, n. 104 (c.d. “Decreto Trasparenza”) It introduces new provisions on data and information transparency. While not strictly a data protection law, it affects the management and disclosure of information, and thus indirectly personal data, ensuring greater transparency and proper use thereof. Regole Deontologiche (ai sensi Art. 20, c. 4, D.Lgs. 101/2018); Provvedimento del Garante del 29 novembre 2018 G.U. n. 3 del 4 gennaio 2019 It regards journalistic activities and replaces the previous code. It balances the right to report and freedom of expression with the right to personal data protection. It regulates the processing of personal data (including sensitive data) by journalists, publishers, and managing editors. It provides specific rules for minors, sick individuals, victims of violence, etc. Provvedimento del Garante del 6 dicembre 2018; G.U. n. 12 del 15 gennaio 2019 It concerns defensive investigations and the protection of a right in judicial p. It replaces the previous code. It details the methods and limits for processing personal data (including judicial and sensitive data) by lawyers, authorised private investigators, and individuals conducting defensive investigations to assert or defend a right in judicial proceedings. Provvedimento del Garante del 6 dicembre 2018; G.U. n. 12 del 15 gennaio 2019 It is related to the processing for archiving purposes in the public interest or for historical research purposes. It replaces the previous code. It defines the safeguards and conditions for processing personal data (including special categories) for conservation in public and private archives of historical interest. Provvedimento del Garante del 6 dicembre 2018; G.U. n. 11 del 14 gennaio 2019 It regards the processing for statistical and scientific research purposes (Sistan context). It replaces the previous code. Outlines safeguards for processing personal data by entities
Pag. 36 and offices belonging to the National Statistical System (Sistan) for official statistical purposes or scientific research. Provvedimento del Garante del 6 dicembre 2018; G.U. n. 11 del 14 gennaio 2019 It concerns the processing for statistical and scientific research purposes (general). It replaces the previous code. It regulates the processing of personal data for statistical or scientific research purposes carried out by public or private entities outside of Sistan. It includes some rules for processing health data in the absence of consent (consistent with Art. 110-bis Codice Privacy). Codes of Conduct (under Art. 40 GDPR) Delibera n. 159 del 12 giugno 2019 It involves commercial information and credit management. updates and it replaces the previous ethical code. It regulates the methods of collection, storage, and communication of personal data by companies operating in the commercial information and credit protection sector (e.g., solvency and reputation databases). Delibera n. 80 del 15 marzo 2023 It refers to telemarketing and teleselling activities. It establishes detailed rules for commercial calls and communications (e.g., time slots, operator identification, contact limits, list management, obligation to adhere to the Public Register of Oppositions). Delibera n. 35 del 1° febbraio 2024 It is related to the development and production of management Software. Focuses on integrating data protection by design and by default into the development and provision of management software. Aims to facilitate GDPR compliance for SMEs. Within the Italian legal system, personal data protection boasts a robust tradition, deeply rooted in constitutional principles and European regulatory evolution. From the outset, with Directive 95/46/EC and the subsequent establishment of the Garante per la protezione dei dati personali, Italy has shown a steadfast commitment to safeguarding individuals’ fundamental rights regarding the processing of their data. This regulatory journey has been progressively strengthened with the introduction of increasingly effective tools and safeguards. The Codice Privacy, even with the revisions of GDPR, has consolidated and harmonized previous legislation, providing a comprehensive and detailed framework with specific features that distinguish it from other Member States. These are evident in the relationship between citizens and the public administration, in the processing of health data and the strengthening of eHealth, as well as in the protection of workers’ personal data. The relationship between privacy and labour law is particularly evident in the issue of electronic surveillance of workers, regulated by Art. 4 of Legge 300/1970. The references contained in Art. 88 GDPR and Art. 114 Codice Privacy to this law highlights the depth of protection afforded to workers, which also involves the processing of their personal data. The original purpose of the rule was to ensure the dignity and privacy of employees when they were filmed during work activities using video surveillance systems (Gaudio, 2022). This was achieved by subordinating
Pag. 37 the installation of such systems to the conclusion of a collective agreement with trade unions or with the authorisation of the Ispettorato Nazionale del Lavoro (Riccobono, 2023; Turco, 2019). However, technology and its evolution have since led to this rule being applied to all forms of remote monitoring of workers, including electronic surveillance. The tools currently used to perform work, in fact, collect a massive amount of personal data which, although important for organisational and security purposes, can lead to the monitoring of work activities. This subject has, therefore, also been the object of numerous interventions by the Garante. A clear example is the management of corporate email, for which, in its guidance document of 6 June 2024, the Authority provided several clarifications on the function, retention, and use of metadata generated from emails. In this document, it is established that the prolonged retention of such data (beyond 21 days) is an operation that can enable indirect monitoring of work activities, consequently requiring the adoption of the procedural safeguards provided for by Art. 4 L. 300/1970 (Tebano, 2024a). Despite this commendable initiative to protect workers’ privacy, this interpretation has drawn several criticisms. Both practice and legal scholarship, in fact, highlight how the Garante’s approach distorts the ratio of Art. 4, by focusing on the function of the data and no longer on the nature of the work tool. Furthermore, the 21-day time limit is considered impractical for business needs, such as defence in the event of litigation, retention under Art. 2214 of the Italian Civil Code, or the prevention of cyber-attacks (Tebano, 2024b). The enhancement of administrative transparency and personal data protection represents a central issue in public law. Transparency, understood as the full accessibility of PA data and documents, has a dual objective: to safeguard citizens’ rights and to promote their participation and widespread oversight of PA operations. The Art. 86 of the GDPR, recognises the importance of this balance. Although this is an activity that involves the processing of personal data - the legal basis for which is public interest - the GDPR allows Member States to regulate access to administrative documents. However, access to personal data contained in public documents is never indiscriminate. Italian law provides for different tools, each with its own rules: Legge n. 241/90 (administrative access) requires a direct, concrete, and current interest from the applicant; D.Lgs. n. 33/2013 (civic access and FOIA) allows for broader oversight, based on the principle of transparency. The Garante’s guidelines offer a reference framework to harmonise these two areas. The authority, in fact, emphasises the need to integrate data protection principles with those of transparency with the aim of ensuring an individual’s control over their personal data (Carloni, Falcone, 2017). The empowerment of citizens towards the PA is represented not only by the availability of data access but also by the possibility for this data to circulate between the country’s administrations. With the digitalisation of the public administration, there has been a progressive affirmation of the relevance of public information assets, which has translated into a detailed definition of the rules on data management, reuse, and their circulation between PA as stated by Art. 50 D.Lgs. 82/2005 (“CAD”) (Macrì, 2021). This has been complemented by a specific regulation for data that is elevated to a national database of interest (Art. 60, par. 1, CAD). 5.2 The cybersecurity framework at national level The Italian regulatory framework on cybersecurity has developed from a fragmented situation (Resta, 2024; Venanzoni, 2024) to a centralised governance by means of the creation of Perimetro di Sicurezza Nazionale Cibernetica (D.L. 105/2019) (Camera dei Deputati, Servizio Studi, 2024), complemented by its implementing provisions, the Strategia nazionale di cybersicurezza 2022-2026, and most notably the Agenzia per la Cybersicurezza Nazionale (ACN) through D.L. 82/2021 (ACN, 2022b; Pietrangelo, 2024a; Carotti, 2024). The ACN has taken on strategic, operational, and supervisory functions, including those stemming from the transposition of NIS2.
Pag. 38 The Perimetro di Sicurezza Nazionale Cibernetica (PSNC) marks the initial step in building a national cybersecurity and cyber resilience system (Serini, 2024). Its purpose is to safeguard the networks, information systems, and IT services of public and private entities that perform essential functions or provide essential services crucial to state interests (Calandriello, 2023). As subsequently defined by the D.P.C.M. n. 131/2020, which gave shape and substance to the Perimetro, it contributes to this reaffirmation of cyber sovereignty in several ways. First and foremost, the Perimetro is established to ensure a high level of security for the networks, information systems, and IT services of essential public administrations, national bodies, and private operators whose interruption or malfunction could cause harm to national security (Buoso, 2025). Through the PSNC, the State obtains a comprehensive mapping of the service structure and imposes obligations to minimise risks, such as preventive control over the purchase of ICT goods and services, as well as the architecture and components related to ICT assets, by the entities included in the Perimetro (Sola, 2022). Cybersecurity is viewed as an holistic concept that encompasses all aspects characterising contemporary states, with a strong focus on vulnerability prevention to strengthen national resilience (Buoso, 2025). Despite its European origins, this falls within the exclusive purview of the Presidency of the Council of Ministers, assisted by the ACN for the definition of policy guidelines (Matassa, 2025). Regarding the obligations for entities included in the PSNC, the D.P.C.M. n. 131/2020 imposes significant burdens in terms of governance and compliance. First, the Art. 7 required for a detailed mapping of IT architectures and an in-depth risk analysis shifts the burden onto entities to identify their critical assets. Furthermore, entities must describe the architecture and components of their ICT assets, transferring all information to the DIS (Dipartimento delle informazioni per la sicurezza). While this strengthens the state’s overall view on cybersecurity, it raises issues concerning the protection of trade and industrial secrets (regulated by Art. 9 D.P.C.M. n. 131/2020). The Art. 10, which provides for the protection of processed information, seeks to address this need. However, its effectiveness is contingent upon the adoption of adequate technical and organisational measures, as well as the future issuance of decrees on secrecy classification. Finally, entities are required to notify the CSIRT active in ACN significant ICT incidents. The strengthening of national cybersecurity as a strategic priority for the country is also a key theme in the National Cybersecurity Strategy 2022-2026, drafted and implemented by the ACN. This policy document aims to combine the needs of security and development to ensure digital sovereignty, adopting a whole-of-society approach that coordinates the public and private sector, the academic world, and civil society organisation (Cocchi, 2024). The Strategy is structured around three main directions. The first concerns the protection of national strategic assets, digital infrastructures, and public administration systems. A subsequent direction relates to the capacity to provide timely and effective responses to cyber incidents and crises, achieved through the integration and enhancement of national operational structures, such as HyperSOC and CSIRT Italy. A final direction involves technological and industrial development, aimed at reducing dependence on non-EU technologies and consolidating the country’s strategic autonomy in the cyber domain. In this light, the National Cybersecurity Strategy 2022-2026 is not limited to defensive measures but is configured as a long-term project designed to support the digital transition under conditions of security, resilience, and technological independence (ACN, 2022). Consistent with these strategic directions, the strengthening of national cybersecurity and cyber resilience is not exhausted by the implementation of the measures outlined in the 2022-2026 Strategy but finds further concrete expression in the bolstering of Italy’s economic and social infrastructure (Faina, Didonè, 2025). The recently introduced legal framework for cybersecurity in Italy, enshrined in D.Lgs. n. 138/2024, which transposes Directive NIS2, is designed to achieve this objective by elevating information security to a strategic function within the corporate governance framework. As mentioned, the scope of application has been significantly expanded, introducing a “size-cap rule” that automatically subjects all medium and large enterprises (pursuant to Recommendation 2003/36/EC) operating
Pag. 39 in 18 sectors, divided into 11 “highly critical sectors” (Annex I) and 7 “other critical sectors” (Annex II) (Sola, 2022). This expansion is not a mere numerical increase but a strategic re-evaluation of the concept of “criticality” in the face of the profound digitalisation of industrial value chains. This makes these chains strategic assets whose compromise can have systemic impacts on national security and economic sovereignty, on a par with traditional critical infrastructures such as energy and transport. Italy has also created a coordinated legal framework between Legislative Decree 138/2024 and the PSNC, as the entities falling within the latter are also required to comply with the new NIS2 legislation. This integration aims to avoid duplication and strengthen the country’s digital resilience, also considering entities that may not fully fall within the scope of the NIS2 but which Italy considers crucial for its national security. Secondly, the approach to compliance undergoes a transition from a model based on general principles to a prescriptive one, founded on specific controls. As outlined in Art. 24 D.Lgs. n. 138/2024, the obligation to adopt “adequate and proportionate” measures is contingent upon an overall risk assessment, as outlined in the “all-hazards approach”. This is further delineated by ACN Determinazione n. 164179/2025, which establishes a detailed catalogue of basic security measures, differentiated for “essential” and “important” entities. This regulatory system effected a fundamental transition by shifting the burden of compliance from a subjective interpretation of general principles (like that required by Art. 32 of the GDPR) to an objective and verifiable adherence to a catalogue of technical and organisational criteria (Giustozzi, 2025). This should facilitate supervision and reduce ambiguity surrounding compliance. However, it will concomitantly impose a significantly more prescriptive and onerous regulatory burden on organisations, thereby diminishing their capacity to adopt alternative measures. All the criteria provided by the ACN are directly mapped onto the National Framework for Cybersecurity and Data Protection (2025 Edition). This framework has a formally voluntary status, but in practice, it assumes a de facto binding role as a technical standard (Serini, 2024). The adoption and implementation of the controls provided by the Framework therefore become the most direct, structured, and secure path for organisations to demonstrate the adequacy of the measures required by Art. 24 D.Lgs. 138/2024 and detailed in the annexes of the Determinazione. Despite the National Framework’s pivotal function in implementing D.Lgs. n. 138/2024, its architecture permits coordination and integration with other technical regulations and international standards, including the ISO/IEC 27001 series. This coordination is of particular importance for organisations that operate internationally or have already implemented information security management systems based on such standards (Wu, Lee, Ku, 2024). In conclusion, Italy’s transposition of the NIS2 Directive has fundamentally reformed cyber risk governance through a two-tiered system orchestrated by the ACN. Initially, Legislative Decree 138/2024 provides the overarching legal framework and a basic catalogue of security areas. The second tier involves the ACN itself, which, through its Determinazione n. 164179/2025, translates these high-level principles into concrete, binding obligations. This includes a detailed catalogue of mandatory security measures and elevates a technical standard, the National Framework, into an operational guide for implementation. This approach, while challenging for businesses, is a deliberate strategic choice: to enforce a uniform, measurable, and verifiable increase in cyber resilience across the entire national critical perimeter, thereby minimising interpretive ambiguities. Proof of this is the Determinazione n. 164179 of 10 April 2025, which detailed the minimum catalogue of technical, organisational, and operational measures, notably including supply chain security, incident management, the use of encryption, and the pervasive implementation of multi-factor authentication (ACN, 2025). Moving on to the regulations that have already been approved, despite the European DORA and CRA are directly applicable, they require specific implementation in Italy to define the framework of sanctions and the competent authorities. Decreto Legislativo n. 23/2025 established the implementing regulations for the DORA, thereby delegating supervisory functions to the extant financial authorities (Banca d’Italia, CONSOB, IVASS). These authorities are required to receive notifications of any significant ICT incident and to collaborate with ACN to manage cyber threats. Finally, fines and prohibitive sanctions are defined in the event of serious or
Pag. 40 significant violations, making substantial changes to national sectorial regulations (i.e, TUB, TUF, D.Lgs. n. 209/2005, D. Lgs. n. 252/2005 and D. Lgs. n. 129/2024). This measure is expected to enhance the security of citizens, thereby ensuring the uninterrupted availability of banking and financial services, even in the event of cyber-attacks. Concurrently, for CRA, although the implementing measures are still under discussion, the main elements have already emerged: the designated authorities will be Ministero delle imprese e del made in Italy (MIMIT) and ACN. The Agenzia will lead the national implementation of the Regulation, preparing market surveillance acts in coordination with MIMIT, and serve as the technical-regulatory reference point at both national and European levels for the development and coherence of regulations on secure digital products (ACN, 2024). The last intervention to be mentioned pertains to the promulgation of Legge n. 90/2024. This act was developed in parallel with the NIS2 Directive transposition process (Senato della Repubblica - Servizio Studi, 2024), arising from the necessity to fortify the national cybersecurity ecosystem, thereby conferring new and more substantial powers upon the ACN and updating the criminal sanctions framework in response to the escalating prevalence of cybercrime (Chiara, 2024b). While NIS2 addresses a broad perimeter of economic operators, the L. n. 90/2024 imposes more stringent and specific obligations, especially for the PA. A more stringent and generalised obligation to report incidents to the ACN is introduced. This goes beyond the entities included in NIS2, as it involves PSNC’s entities, aiming to provide the Agenzia with a timely and complete awareness (Casarosa, 2024). For this reason, it is made mandatory for PAs to identify a referente per la cybersicurezza who is responsible for implementing security strategies and acting as the point of contact with the ACN (ACN, 2024). Aiming to strengthen PAs, Art. 14 of the act introduces cybersecurity criteria into procurement procedures for ICT goods and services (a reference was already present in Art. 108, par. 4, D.Lgs. n. 36/2023 (Cocchi, 2024)). This requirement will have a significant impact on the private sector, as it is expected that public spending will be directed towards Italian, European, or allied countries’ technological solutions (Nannipieri, 2024). Finally, a National Cryptography Centre is established within the ACN. Its task will be to develop and promote the adoption of national cryptographic standards, verifying the security of ICT products used by the PA. In summary, L. n. 90/2024 contributes directly to strengthening the Italian cyber sovereignty (Longo E., 2024). The establishment of the National Cryptography Centre, in conjunction with the new rules on procurement of ICT, constitutes a deliberate policy initiative aimed at mitigating technological reliance on foreign technology suppliers, especially for sensitive areas. By setting these stringent requirements for PA, the law aims to fortify the state’s digital core, protecting citizens’ data and essential services. However, the law’s implementation by local authorities may face challenges due to their limited technical, economic, and human resources, which must be further developed to meet the new obligations (ANCI, 2024). This robust institutional architecture demonstrates Italy’s commitment to the European vision. Nevertheless, this framework is not without its critical issues. On the one hand, there is the risk of an overly ‘vertical’ and technocratic approach that neglects the social and collaborative dimension of security (Pietrangelo, 2024b). On the other hand, its implementation poses significant operational challenges for public administrations, including a lack of resources and specialised technical expertise (Macrì, 2024). However, its success now hinges on the effectiveness of its implementation in addressing the significant challenges related to fostering a widespread security culture and bolstering the resilience of SMEs. This affirms the principle that cybersecurity is an indispensable foundation for national security, economic competitiveness and the protection of fundamental rights, and not merely a technical issue. The following table summarizes the cybersecurity framework at national level. Normative Act Year of Adoption/Conversion Key Aspect Introduced/Main Function
Pag. 41 D.P.C.M. 24 gennaio 2013 2013 First national directive on cybersecurity, establishing the guidelines for cyber protection and IT security, and centering the role of the Prime Minister and national security bodies in the coordination of these matters D.P.C.M. 17 febbraio 2017 2017 Upgrade of the previous institutional framework, defining the Inter-ministerial Committee for the Security of the Republic (CISR) and the DIS as key players in the governance of national cybersecurity. Decreto Legislativo n. 65/2018 (Transposition of NIS Directive) 2018 Transposition of the first NIS Directive. D.P.C.M. 8 agosto 2019 2019 Establishment of the CSIRT Italy at the DIS, serving as a single point of contact at the national and European levels for the management of cybersecurity incidents. After it has been moved at ACN. Decreto-Legge n. 105/2019 (converted in Legge n. 133/2019) – “Decreto PSNC” 2019 Establishment of the Perimetro Sicurezza Nazionale Cibernetica (PSNC) for national strategic assets. D.P.C.M. 30 luglio 2020, n. 131 2020 Defines the criteria and procedures for identifying public and private entities included in the PSNC. D.P.R. 5 febbraio 2021, n. 54 2021 Defines the notification procedure to the National Evaluation and Certification Center (CVCN) for the supply contracts of ICT goods and services intended for the PSNC. D.P.C.M. 14 aprile 2021, n. 81 2021 Defines the procedures and timelines for the notification of cybersecurity incidents by entities within the PSNC and introduces additional security measures. D.P.C.M. 15 giugno 2021 2021 Identify the categories of ICT goods, systems, and services that PSNC entities are required to notify before acquisition. Decreto-Legge n. 82/2021 (converted by Legge n. 109/2021) – “Decreto ACN” 2021 Establishment of the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authority and core of governance. Decreto legislativo n. 134/2024 2024 Transposition of Directive CER (Directive UE 2557/2022) regulating the resilience of critical entities, which—although not primarily focused on cybersecurity—has some implications for it.
Pag. 48 With D.L. N. 123/2023, AGCOM was designated as the Digital Services Coordinator (DSC) for Italy. It assumes general responsibility for the supervision and application of the DSA on national territory and acts as the single point of contact for the Commission and other European DSCs, in accordance with what is provided by Art. 49 of the DSA 77 . The designation of AGCOM thus appears entirely correct, considering its consolidated experience in regulating digital content and audiovisual media services, as established by the targeted law, i.e. “Testo unico dei servizi di media audiovisivi” (TUSMA). Moreover, the Authority has defined this role not as a mere bureaucratic function, but as a strategic pillar to “ensure that the digital space remains a place of rights” (AGCOM, 2025), stressing the centrality of user protection in the digital ecosystem (Ciliberti, 2024). This enhances data sovereignty from the individual point of view. To operationalise the DSA’s protective instruments, AGCOM has already acted with celerity, by adopting, following a public consultation, the Decisions 283/24/CONS and 282/24/CONS. The first decision establishes the regulation for the recognition of ‘Trusted Flaggers’, specialised and independent entities that can notify illegal content with priority, in line with Art. 22 of the DSA 78 . Analysing the text of the decision, particularly stringent requirements emerge for entities aspiring to this status, which must demonstrate not only “independence” and “competence”, but also rigorous and transparent verification procedures (AGCOM, Decision 283/24/CONS, Art. 4). The second defines the certification procedure for outof-court dispute settlement (ADR) bodies, which offer an impartial mechanism for resolving disputes between users and platforms, as provided for by Art. 21 of the DSA (Senato della Repubblica, 2025). Within this regulatory framework, the protection of minors presents one of the most complex and relevant challenges for the implementation of the DSA in Italy, constituting a fundamental testbed for the effectiveness of the national enforcement system. The DSA, in fact, moves beyond the logic of mere consent to data processing, already governed by the GDPR (which in Art. 8 sets the age threshold for digital consent, lowered to 14 in Italy in the Data Protection Code), to introduce an approach based on the assessment and mitigation of systemic risks, as outlined in Art. 34 of the Regulation. This obliges very large online platforms to identify and mitigate risks arising from the design of their systems, including negative effects on the physical and mental health of minors (Pileggi, 2024). In this context, AGCOM assumes a central role, supervising compliance with protection obligations by platforms operating in Italy. Its new responsibilities, in fact, include particular attention to the creation of age verification mechanisms, an obligation reinforced by the so-called “Caivano Decree” 79 (Pileggi, B., Minors on the internet: a constitutional problem, 2024). In implementation of D.L. N. 123/2023, the Authority approved, by decision no. 96/25/CONS 80 , the technical specifications for age verification systems for access to sites with pornographic content, based on a “double anonymity” model that guarantees user privacy by delegating verification to a certified third party (AGCOM, 2025). The issue of protecting minors, therefore, ceases to be a mere data protection problem and becomes a pillar of domestic digital sovereignty, the effectiveness of which is measured by the national apparatus’s capacity to enforce, within the harmonised DSA framework, the fundamental rights of the most vulnerable users against the risks generated by the very structure of digital services. 77 AGCOM, Decisione n. 283/24/CONS, 24/07/2024, “Regolamento di procedura per il riconoscimento della qualifica di segnalatore attendibile ai sensi dell’art. 22 del Regolamento sui servizi digitali (DSA)”: https://www.agcom.it/sites/default/files/provvedimenti/delibera/2024/Delibera%20283_24_CONS.pdf. 78 Ibidem. 79 Decreto-legge 15 settembre 2023, n. 123, recante disposizioni urgenti in materia di politiche di coesione, rilascio del codice identificativo nazionale dei contratti pubblici e altre misure urgenti di carattere finanziario, G.U. Serie Generale n. 216, 15.9.2023. 80 AGCOM, Decisione N. 96/25/CONS, 08/04/2025, Adozione delle modalità tecniche e di processo per l’accertamento della maggiore età degli utenti in attuazione della legge 13 novembre 2023, n. 159.
Pag. 49 Equally emblematic of the exercise of Italian telecommunication strategy in the enforcement phase is the action taken to combat online piracy. Thanks to the strengthening of its powers by Law no. 93/2023 81 , the “Piracy Shield” platform has become a central instrument. During the reference period, the platform was used to block 28,041 fully qualified domain names (FQDNs) and 6,104 IP addresses that were illicitly disseminating live sporting events. Furthermore, disabling and de-indexing orders were issued to large global operators such as Cloudflare and Microsoft (AGCOM, 2025). Finally, it is pertinent to note the repeal of Artt. 14-17 of D.lgs. 70/2003, pertaining to the liability regime for internet service providers, affected by D.lgs. 50/2024. This legislative action constitutes a necessary measure, mandated to ensure alignment between the national legal order and the new European regulatory framework established by the DSA. Indeed, Artt. 4, 5, 6, and 8 of the aforementioned Regulation have superseded the corresponding provisions previously contained within the Directive 2000/31/EC (which had been transposed into Italian law precisely through D.lgs. 70/2003), introducing updated stipulations concerning the liability of these online operators. Consequently, Art. 3, par. 4, of D.lgs. 50/2024 has formally expunged from the Italian legal system those provisions rendered obsolete following the entry into force of the new intermediary liability regime governed by DSA. For the application of the DMA, the focus of which is competition, the supporting role has instead been entrusted to the AGCM. This assignment is not coincidental; rather, it builds upon a path of analysis of digital markets that the Authority has long pursued, as demonstrated by the fundamental joint fact-finding investigation on Big Data (AGCM, AGCOM, Garante Privacy, 2020). This investigation had already mapped the competition-related criticalities arising from data collection and use well before the European regulatory framework. Although the primary enforcement of the DMA is centralised at the Commission, the AGCM acts as the national supporting authority, exercising investigative powers in cooperation with Brussels, as provided for by Art. 38 of the Regulation, which authorises national authorities to conduct investigations on their own initiative into possible cases of non-compliance by gatekeepers (Rocca, 2024). This division, however, creates a complex regulatory mosaic, raising the risk, already highlighted by legal scholars, of overlaps and friction between the authorities’ competences, to which is added the cross-cutting role of the Garante on privacy issues (Ciliberti, 2024). In parallel, a crucial strategic aspect lies in the AGCM’s dual operational capacity. As stressed by the Authority itself in its Annual Report, the entry into force of the DMA does not exhaust the instruments for protecting competition. The AGCM indeed asserts the full applicability of national legislation, particularly concerning the abuse of economic dependence, and of Art. 102 TFEU for cases not covered by the European Regulation (AGCM, 2025). Through its internal regulation implementing the 2022 Competition Law 82 , the Authority, while supporting the Commission on the DMA, reserves the right to initiate autonomous investigations should evidence emerge of a breach of national competition law or, in particular, of an abuse of economic dependence. This setting ensures that Italy maintains a strong and autonomous instrument of regulatory pressure, avoiding relegation to the role of a mere data-gathering agency (Rocca, 2024). An example of this proactive approach is the investigation launched against Apple in 2023 for an alleged abuse of a dominant position in the app store market, an action taken on the basis of national law 83 but which fits 81 Legge 14 luglio 2023, n. 93, di conversione in legge, con modificazioni, del decreto-legge 15 maggio 2023, n. 48, recante misure urgenti per l’inclusione sociale e l’accesso al mondo del lavoro, G.U. Serie Generale n. 186, 10.8.2023. 82 AGCOM, Delibera n. 31295, 23/07/2024, “Regolamento sulle forme di collaborazione e cooperazione ai sensi dell’articolo 18 della Legge 30 dicembre 2023, n. 214, recante misure per l’attuazione del Regolamento (UE) 2022/1925 del Parlamento europeo e del Consiglio del 14 settembre 2022”. 83 Art. 102 TFUE.
Pag. 50 squarely within the logic of monitoring digital markets promoted by the DMA 84 . Similarly, the investigation opened into Meta in 2024 concerning its platform's terms of use, to verify a possible exploitation of users’ economic dependence, demonstrates the Authority’s will to act autonomously to protect the market, even in areas complementary to those covered by the DMA 85 . Despite this proactive stance, the Italian regulatory strategy presents the serious critical issue of the risk of “gold plating”. This term describes the phenomenon whereby a Member State, in transposing a directive or applying a European regulation, introduces regulatory, procedural, or substantive obligations that are more onerous and stringent than those strictly required by the Union’s act (CFA Society Poland, 2024). Although it may stem from the intention to guarantee a higher level of protection, gold plating directly undermines the objective of maximum harmonisation of the Digital Single Market, creating regulatory barriers, increasing compliance costs for businesses operating transnationally, and generating legal uncertainty. In the context of the AGCM’s autonomous action, gold plating represents a fundamental contraindication: should its investigations impose obligations on gatekeepers not provided for by the DMA or in conflict with it, the Authority’s decisions could be challenged and potentially annulled by the CGUE for breaching the principle of the primacy of EU law and the direct applicability of regulations. This would not only weaken the effectiveness of national enforcement but also create a dangerous precedent, discouraging future autonomous actions and de facto reducing the very digital sovereignty it intends to affirm. A recent and significant judgment by the TAR Lazio 86 referred a question for a preliminary ruling to the CGUE on this very issue. The TAR questioned the lawfulness of an AGCOM decision 87 concerning copyright, arguing that the negotiation and mandatory arbitration obligations imposed on service providers exceeded what was established by Art. 15 of the EUCD Directive, explicitly breaching the prohibition on gold plating (Segretariato generale della giustizia amministrativa, 2024). This legal precedent serves as a warning bell, because if the same tendency towards regulatory zeal were to be replicated in the implementing regulations for the DSA - for example, by defining disproportionate requirements for the certification of ADRs or, as already analysed, imposing overly onerous criteria for the qualification of Trusted Flaggers 88 - the new decisions could be challenged on the same basis, creating a conflict between the objective of reinforced protection and the coherence of the Digital Single Market. In conclusion, Italy has acted rapidly in defining its institutional framework, but a fundamental strategic criticism emerges: institutional fragmentation, which necessitates inter-authority coordination that has not yet been formalised in primary law. To complete this framework, the adoption of a legislative act establishing binding cooperation protocols between AGCOM, AGCM, and the Garante Privacy is recommended. The effectiveness of national digital sovereignty lies not in the isolated action of a single authority, but in the capacity to create a cohesive and synergistic institutional front. It is crucial that the competences regarding content (AGCOM), competition 84 AGCM, Decisione n. 30833 (Caso A549), 11/11/2021, “Abuso di posizione dominante da parte di Apple nel mercato delle piattaforme di distribuzione di applicazioni per dispositivi iOS”. Available at: https://www.agcm.it/media/comunicati-stampa/2021/11/A549. 85 AGCM, Decisione n. A559, 04/04/2023, “Avviata istruttoria nei confronti di Meta Platforms Inc. per presunto abuso di dipendenza economica nei confronti della SIAE ai sensi dell’articolo 9 della legge 18 giugno 1998, n. 192”. Available at: https://www.agcm.it/media/comunicati-stampa/2023/4/A559. 86 TAR Lazio, Sez. IV, Sentenza n. 18790 del 12 dicembre 2023 (in DeJure). 87 AGCOM, Decisione n. 3/23/CONS, 12/01/2023, “Regolamento per l’individuazione dei criteri di riferimento per la determinazione dell’equo compenso per l’utilizzo online delle pubblicazioni di carattere giornalistico, ai sensi dell’articolo 43-bis della legge 22 aprile 1941, n. 633”. 88 AGCOM, Decisione n. 283/24/CONS, 24/07/2024, “Regolamento di procedura per il riconoscimento della qualifica di segnalatore attendibile ai sensi dell’art. 22 del Regolamento sui servizi digitali (DSA)”: https://www.agcom.it/sites/default/files/provvedimenti/delibera/2024/Delibera%20283_24_CONS.pdf.
Pag. 51 (AGCM), and data protection (Garante Privacy) are in constant dialogue to avoid contradictory decisions and to address the complex challenges posed by digital platforms holistically. The national strategy must, therefore, balance vigorous enforcement with loyal adherence to EU harmonisation, as only an effective, coordinated, and legally unassailable application will permit Italy to fully utilise the DSA and DMA as effective instruments of digital sovereignty within the European context. Legislative act Main legal purpose Key articles Directive 2000/31/EC E-commerce Directive (previous framework) Artt. 12-15 repeal by Artt. Artt. 4, 5, 6, and 8 of DSA D.L. 15 settembre 2023, n. 123 (“Caivano Decree”) Designation of AGCOM as Digital Services Coordinator (DSC). Reinforcement of obligations for age verification mechanism AGCOM Decisione N. 283/24/CONS Regulation for the recognition of 'Trusted Flaggers' under the DSA Art. 4, Art. 22 (DSA) AGCOM Decisione N. 282/24/CONS Certification procedure for out-of-court dispute settlement (ADR) bodies Art. 21 (DSA) AGCOM Decisione N. 96/25/CONS Approval of technical specifications for age verification systems Legge N. 93/2023 Strengthening of AGCOM's powers against online piracy (“Piracy Shield”) AGCM Regulation (implementing Law 214/2023) Regulation on forms of collaboration and cooperation for AGCM Art. 18 (Law 214/2023)
Pag. 52 AGCM Decisione N. 30833 Case A549: Investigation into Apple for abuse of dominant position Art. 102 TFEU AGCM Case A559 Investigation into Meta for alleged abuse of economic dependence TAR Lazio, Section IV, No. 18790/2023 Judgment referring a question to the CJEU regarding 'gold plating' AGCOM Decisione N.. 3/23/CONS Decision on copyright (challenged by TAR Lazio 18790/2023) D.Lgs. 25 marzo 2024, n. 50 Repeal of italian provision of Internet Service Provider liability in Artt. 14-17 of D.lgs. 70/2003 Art. 3, par. 4 5.6. The impact of the PNRR in the Italian legislation The “Piano Nazionale di Ripresa e Resilienza” (PNRR) acts as a driver of regulatory transformation, aimed at revitalising Italy after the pandemic crisis through an unprecedented acceleration of modernisation processes. This intervention is not limited to economic support but mandates a profound overhaul of the regulatory framework, particularly in the fields of digitalisation, cybersecurity, data governance, and data protection. The PNRR promotes the adoption of emerging technologies such as cloud computing and artificial intelligence, strengthening the national data strategy in coherence with European law, and adapts the system to new cybersecurity directives, such as NIS2 (Gastaldi, 2025). At the same time, the regulatory innovations introduced raise complex issues, requiring a careful balance between technological innovation, administrative efficiency, and the protection of fundamental rights. The three strategic axes underpinning the Plan are digitalisation and innovation, ecological transition, and social inclusion. These are the pillars on which the six Missions foreseen by the PNRR are based, which are the six main thematic areas, in turn articulated into sixteen Components—more specific intervention areas comprising Investments and Reforms: ● Digitalisation, innovation, and competitiveness of the productive system: this involves the promotion of the country’s digital transformation and the innovation of the productive system, alongside investments in the tourism and culture sectors. A cornerstone of this modernisation is the creation and implementation of the Piattaforma Digitale Nazionale Dati, designed to ensure the interoperability of public data and realise the “once-only” principle, i.e., the single provision of data by citizens and businesses to the public administration (Governo italiano, 2025; Sorrentino, Spagnuolo, 2023; Graditi, 2023);
Pag. 53 ● Green revolution and ecological transition: it aims to achieve the green and ecological transition of society and the economy with interventions for sustainable agriculture, for research into renewable energies, for the development of the hydrogen supply chain, and for sustainable mobility; ● Sustainable mobility: this action aims to modernise and enhance the national railway network, especially in the South, digitalise air transport, and ensure the interoperability of logistic procedures for the port network, but also infrastructures for mobility; ● Education, training, research, and culture: it intends to address all problems encountered in educational institutions, from nurseries to universities, strengthening research systems and offering new tools for technology transfer; ● Social, gender, and territorial equity: this task invests in social infrastructures to support active labour policies; ● Health: it focuses on improving healthcare services through the digitalisation of the National Health Service. Relevant to this topic are the definition of the Italian version of the Electronic Health Record, meaning the Fascicolo Sanitario Elettronico (“FSE”), now called “FSE 2.0”, and the Ecosistema dei Dati Sanitari, which have a fundamental connection with the European Health Data Space (EHDS). The PNRR, with its vast scope, stringent European conditionalities, and transversal impact on laws, is effectively defining the fundamental principles and directions of Italy’s digital transition for the next decade (Piperata, 2022). Despite not being a law in a formal sense, its influence on the political and legislative agenda is such that it can be considered a kind of costituzione materiale — a concept describing the set of political forces and fundamental aims that determine a state’s effective direction beyond the formal text of its constitutional charter. This perspective stems from the PNRR’s nature not just as a funding allocation, but as a strategic document driving structural legislative change through its medium to long-term reform agenda and “enabling reforms”. Its funding mechanisms, tied to the achievement of legislative or regulatory milestones and quantitative targets, actively necessitate national legal adjustments. Furthermore, the PNRR’s digital agenda is intrinsically linked to the broader EU digital regulatory framework, positioning the plan as a national vehicle for implementing European principles and directives. The reforms and investments envisaged are creating a new regulatory and infrastructural ecosystem that will inevitably shape the country’s future digital policies. Understanding the PNRR and its regulatory impact is, therefore, essential not only for evaluating the ongoing economic and social recovery but also for grasping the foundations upon which the digital Italy of the future will be built. To provide a more granular detail of the legislative and regulatory framework that the PNRR is shaping and influencing in the digital sphere, a synoptic table listing the main normative and strategic interventions of reference will be presented below. Dominio Main regulatory initiative/reform Primary impact/objective Key laws/Policy instruments and link to PNRR Public Administration Digitalisation Polo Strategico Nazionale (PSN) The goal is to create a safe harbour for the state’s information assets. This aims to migrate PA data and applications to an infrastructure that guarantees the highest standards of security, resilience, and, most importantly, legal independence. Investments under PNRR Mission 1; specific PNRR investment lines for PSN and cloud migration of local public administrations.
Pag. 54 Data hosted on the PSN is subject exclusively to Italian and European jurisdiction, neutralising the extraterritoriality of laws such as the CLOUD Act (USA) or Data Security Law (China). Public Administration Digitalisation Strategia Cloud Italia Modernise PA IT infrastructure, improve data security and management, and achieve 75% PA cloud migration by 2026. Ensuring maximum control over data that is vital to the nation, while also allowing the flexibility to use the best market technologies for less sensitive services. This is all done within a framework of rules and qualifications defined at the national level. PA/Citizen Digitalisation Reform of the Codice dei Contratti pubblici To digitalise the entire lifecycle of public contracts, increasing transparency and efficiency in public procurement. D.Lgs. 31 March 2023, n. 36; PNRR emphasis on administrative simplification and efficiency. Furthermore, Art. 108 emphasises cybersecurity requirement for ICT procurement PA/Citizen Digitalisation Enhancement of Digital Identity (SPID, CIE) and transition towards European Digital Identity (eIDAS 2.0) National Objective (PNRR): to promote the adoption and use of national digital identity systems (SPID and CIE), to improve interaction between citizens and the State and provide secure and efficient means to access a wide range of online public services. Once national platforms are consolidated, the aim is to evolve them into the new European Digital Identity Wallet. This transition aims to ensure full cross-border interoperability and give citizens direct and granular control over the sharing of their personal data. Objectives under PNRR Mission 1: Strengthening existing platforms for a better user experience. The relevant regulatory framework is Regulation (EU) 2024/118389. eHealth Enhancement of the Electronic Health Record (FSE 2.0) To transform the FSE from a document archive into a service ecosystem, modernising the healthcare PA Falling under Component 1 of PNRR Mission 6, the intervention on FSE aims to make its use uniform and 89 See Sect. 4.4 of this report.
Pag. 55 and optimising the delivery of essential services to citizens and businesses. widespread across the national territory, serving as a single point of access to online healthcare services. The collection, storage, and provision of data-driven services for care and prevention purposes should lead to the creation of the Ecosistema Dati Sanitari. eHealth Development and standardisation of Telemedicine Improve territorial healthcare through innovative digital solutions, enhancing the quality and accessibility of public services for citizens. Also under the same Component, telemedicine projects aim to strengthen care pathways to improve the management of acute and chronic diseases, favouring dehospitalisation and improving the quality of proximity care. All of this must occur with uniform application of clinical workflows and care best practices via the National Telemedicine Platform (PNT), which will govern and validate regional solutions to ensure interoperability. Industry and R&D Microelectronic The initiative aims to reduce Italy’s strategic dependence on Asia and the USA. It seeks to strengthen the national production system’s competitiveness and integrate it into strategic European value chains, thereby making it less vulnerable to geopolitical shocks. Mission 4, Component 2 (M4C2), Investment 2.1: This PNRR investment line is explicitly dedicated to funding Italian participation in IPCEIs. National Data Strategy High-Performance Computing Create a world-class, distributed, and cross-cutting research infrastructure. This infrastructure is designed to support both cutting-edge scientific research and technology transfer to the productive sector, thus securing a leading role for Italy in the European supercomputing landscape (EuroHPC Joint Undertaking). Mission 4, Component 2 (M4C2), Investment 1.4: “Strengthening research structures and creating ‘national champions’ of R&D in certain Key Enabling Technologies.” Private Sector Digitalisation Transition 4.0 & Transition 5.0 To incentivise private investments in advanced PNRR funding lines (MIMIT allocations for Transition 4.0:
Pag. 56 digital and green technologies (AI, IoT, cloud), R&D, and skills. €13.381 billion PNRR + €5.08 billion PNC; Transition 5.0: €6.3 billion PNRR). National Data Strategy Strategic Programme for Artificial Intelligence To strengthen the Italian AI ecosystem, promote skills, research, and technology transfer, making Italy a competitive AI hub. The regulatory framework is defined by the national AI Bill, which integrates with the European Regulation (AI Act). The strategy is based on the Strategic Programme for AI (which outlines 24 specific policies for development) and alignment with the European AI Strategy, finding support in PNRR investments. National Data Strategy Valorisation of Public Information Assets & Interoperability Improve data governance, enable data sharing, and leverage public data for innovation and policies. Three-Year Plan for IT in Public Administration; AgID guidelines on interoperability; PNRR investments in data platforms. In this context, the PNRR serves as the main strategic and financial tool for bridging Italy’s digital divide. With Measure 1.3.1, the PNRR allocates significant resources to the creation of digital infrastructures and the interoperability of information systems, laying the groundwork for a profound and systemic (Dipartimento per la trasformazione digitale, 2022). The Piattaforma Digitale Nazionale Dati (“PDND”) fits into this framework as a fundamental technological infrastructure, regulated by Art. 50-ter CAD. Its main purpose is to promote the interoperability of public information systems and databases, facilitating the secure and efficient exchange of information between PAs (Gorgerino, 2022). The objective is twofold: on the one hand, to foster knowledge and use of the vast state information assets, transforming data from a burden into a strategic resource; on the other hand, to realise the “once only” principle, according to which the PA should not request data from citizens and businesses that it already possesses (Laus, 2021; Dipartimento per la trasformazione digitale, 2025). This coordination eliminates duplication and significantly simplifies information flows. This transition from a fragmented, siloed PA to an interconnected, citizen-oriented model is a direct expression of Italy’s digital sovereignty (Alberti, 2022), aiming to reduce dependence on external solutions that may not comply with its regulations and to guarantee sovereign control over its critical data flows (these objectives are the same ones that are tailored by “Strategia Cloud Italia”). This positioning is consistent with broader European digital strategies, including the EU Data Act, promoting a coordinated approach to data governance at a continental level. Momentum for this infrastructure is provided by the PDND and the new AgID Guidelines on the technological infrastructure of the Piattaforma Digitale Nazionale Dati, with an attached positive opinion from the Garante for the specific data protection aspects. The analysis of the right of access has shown how the regulation of public data is a driver of oversight and participation. The principle of informational self-determination manifests with even greater intensity in the healthcare sector, where access to one’s own clinical information represents the foundation for genuine patient empowerment. The Italian healthcare system’s digitalisation, promoted by the PNRR, aims to modernise and streamline healthcare services. At the same time, it raises the crucial need to balance system efficiency with the protection of personal data (Lombardi, 2021). The processing of health data is subject to rigorous regulation founded on the specific condition of Art. 9 GDPR and national rules established particularly in the Artt. 75-93 the Codice Privacy.
Pag. 57 The main legal basis for the processing of health data is for care purposes: Art. 9, par. 2, lett. h) of the GDPR states that processing is lawful if it is necessary for the purposes of preventive or occupational medicine, for medical diagnosis, the provision of health or social care, or the management of health systems. With the GDPR, healthcare professionals are no longer obliged to request specific consent for processing that is strictly necessary for the healthcare service requested by the patient. However, a distinct legal basis is required for processing not directly necessary for care, such as for administrative purposes. In addition to the conditions and measures established by the GDPR, the Italian Legislator has maintained prior specificities, establishing further conditions and safeguards for processing in the healthcare sector, linked both to the Codice Privacy (Bolognini, Marmorato, 2024) and to the predominant intervention of the Garante. This regulation is accompanied by the normative revision which, in recent years, has concerned the Fascicolo Sanitario Elettronico 2.0 and telemedicine, aiming to strengthen the healthcare empowerment of citizens. The new FSE 2.0 has enhanced the technological infrastructure and defined homogeneous national standards. Although the EHR is now automatically populated (without any request for explicit consent for new data) (Corso, 2024), the data subject maintains a high level of control over the possibility of obscuring their data, making specific data and documents (s.c. “dati a maggior tutela”) not visible to third parties. Furthermore, the segmentation of data access by healthcare professionals for care or prevention purposes is subject to the patient’s consent. Pointing in the same direction as the FSE 2.0 is the Ecosistema dei Dati Sanitari which, fed directly by the EHR, is an information coordination tool aimed at developing a centralised system for the collection and analysis of health data. This enables the provision of services for care, prevention, and international prophylaxis, as well as for governance and scientific research (Filippi, 2024). Telemedicine also contributes to patient empowerment, offering services that reduce geographical divides and improve access to care (AGENAS, 2022). Telemedicine platforms are designed to integrate with the FSE 2.0, allowing patients to monitor their own health and share data in a controlled manner, thereby promoting a more conscious management of their care pathway (Napoli, 2025; Atella, Ganna, Lombardi, 2025). The digitalisation of the healthcare system has made a large amount of data available which, in addition to being used for care, has enormous potential for reuse for scientific research purposes. The secondary use of this data for scientific research is not incompatible with the GDPR; indeed, it is incentivised by Art. 9, par. 2, lett. j) GDPR, provided that appropriate national measures are adopted to guarantee the protection of data subjects (Di Somma, 2022). The PNRR and the recent European Health Data Space represent key interventions in strengthening the secondary use of health data, making it now crucial for regulatory purposes, for the definition of health strategies, for scientific research, for health technology assessment, and for clinical applications as stated by recitals 53 and 61 (Legido-Quigley, Wewer Albrechtsen, Bæk Blond, 2025; EIT Health, 2024). Following this impetus, Art. 110 Codice Privacy, relating to the criteria for medical research studies (and particularly retrospective ones), was modified by D.L. n. 19/2024, converted into L. n. 56/2024. While in the past research without consent was very burdensome (requiring opinions from the Garante and the competent Ethical Committee) (Elmi, 2023), the new wording simplifies the process. It is now possible to conduct research without the data subject’s consent when: it is impossible to inform them; informing them would involve a disproportionate effort; or the information would seriously prejudice the purpose of the research (Bincoletto, 2024). However, a favourable opinion from the Ethical Committee is always required, as is compliance with safeguards established by the Garante through the new ethical rules that will be developed. At present, a preliminary communication of the Garante of 9 May 2024 indicated that it is necessary to carry out a DPIA, publish it and communicate it to the authority before the beginning of the scientific project. The amendment of Art. 110 represents a balance between the need to promote scientific research and the necessity to protect the rights of data subjects, simplifying the reuse of data while maintaining rigorous ethical and security controls (Aurucci, Di Tano, 2024). In summary, the recent Italian regulatory framework transcends the mere implementation of a technical framework. Instead, it aims to safeguard national sovereignty over its own information assets (as mentioned for the Strategia Cloud Italia). This takes concrete form in the delineation of a digital perimeter that also
Pag. 64 authenticity of data (with strong interconnections with eIDAS 2.0), and favours data minimisation. In essence, CRA transforms technical resilience from a mere product feature into a prerequisite for the effective exercise of individual autonomy in the digital sphere. Similarly, the DMA counters the power of designated gatekeepers by reinforcing the right to portability. Beyond introducing specific rules for these entities, the DMA extends portability to data generated by user activity - such as metadata, interaction histories, preferences, and behaviour - within the context of core platform services. It mandates real-time and continuous data portability, thereby preventing anti-competitive practices that would otherwise limit user autonomy (Rosa Lazarotto, 2024). Within the scope of the DSA, the crucial juncture lies in the rules on user profiling and Art. 22 GDPR. Requiring platforms to offer opt-out mechanisms from profiled recommendation systems inevitably entails strengthening information obligations to guarantee conscious choice (EDPB, 2025). However, the gap between the availability of information and its actual usability remains critical. For the purposes of informational selfdetermination, transparency and explainability are not merely accessory features but constitutive elements: without accessible understanding, the protection of fundamental rights risks remaining ineffective. This package of regulatory measures is undoubtedly inspired by noble principles and aims to define the legal framework within which it is possible to create a genuine single market for the circulation and reuse of data. However, it presents some significant critical issues. Firstly, the wording of the various provisions appears particularly complex and difficult to understand, making it extremely difficult to apply them in practice. Furthermore, the interaction and integration between these instruments is not entirely clear, leading to situations of overlap or apparent regulatory conflict that need to be resolved. Finally, coordination with the provisions of the GDPR, to which all the aforementioned regulatory texts refer, appears to be anything but straightforward. Overregulating may also be a risk because it can hinder innovation and create a competitive disadvantage for companies operating in the EU. As an example, EU limits on data sharing may restrict businesses based on data, which will prefer to operate out of the EAA. However, it should be stressed that the restrictions are based on the need to safeguard fundamental rights, liberties and values. The EU regulation is human-centered. Besides, in many cases legal requirements are vague and to some extent open, leading to a need for clarification and implementation at national level. Fragmentation between Member States is a major risk for the vision of digital and data sovereignty. The common European data spaces cannot be achieved without coordination. One issue concerns the coordination of all the pieces of legislation in the context of EMDAS objectives. This necessity of alignment refers both to legislation and implementation policies, including the harmonisation level in Member State’ law. The interplay between the already well-implemented GDPR and the recent data law will only become clear in a few years’ time, when all the new legislation has been implemented and businesses have had to adapt with new policies and measures. The recent regulations also require a coordinated implementation effort: guidelines and technical standards (by the Commission but also by Member states), the creation of and cooperation between the new data intermediaries (under the DGA and the EHDS), transparent governance at every level with uniform interpretation of the EU rules. Data spaces may be able to foster data sovereignty, while promoting innovation but fragmented implementation puts the EU at risk of missing out the potentiality of the reforms. The EU regulatory approach is oriented towards the rights and values of good data governance. Its efficacy will depend largely on the ability of the new rules to offer effective protection to individuals as citizens, and consumers, but also small businesses against abuses of digital power. Regarding the themes highlighted, it becomes clear that the complexity of digital compliance is not linked exclusively to the inherent difficulty of the subject matter itself. Rather, there are structural burdens that exacerbate the problem.
Pag. 65 The European digital acquis is characterised by a multiplicity of multi-layered composite procedures involving public bodies, national and European agencies, and forms of co-regulation and audited self-regulation. This generates regulatory duplication and complex networks of obligations that are difficult to manage (Hofmann, 2025). For SMEs, these difficulties are aggravated by limited organisational structures and economic power. Together, these factors make it difficult to adapt even to sectoral standards, given their often limited resources and difficulties in interpreting complex requirements such as those of the Data Act and the AI Act. Ultimately, the search for simple and rapid compliance solutions remains hindered by persistent technical and regulatory complexity. In this context, GRC (governance, risk, compliance) tools act as essential facilitators for process automation and transparency, though their effectiveness remains contingent upon prudent planning and strategic deployment. However, tools alone are insufficient: the establishment of a truly sound digital compliance ecosystem depends fundamentally on heightened awareness across both the political and industrial spectrums. After this general analysis the research has been devoted to highlight the implications of the spread of digital technologies and data management and their data protection and cybersecurity issues in the following key contexts: ● Internet of Things (IoT), in this deliverable; ● Smart agriculture, in a specific presentation; ● Smart energy, in a specific deliverable. The following sections refer to the first context. 7. Digital and Data sovereignty in the context of the Internet of Things: legal requirements and good practices to guarantee data protection and cybersecurity This part of the report will analyse the peculiarities of the IoT and investigate the impact of the presented legal framework. The work aims at proposing guidelines that balance data protection and cybersecurity with transparency requirements, both in the public and private sector, in light of achieving digital and data sovereignty. In particular, these guidelines will include measures which can “by design” protect individuals’ rights and enhance cybersecurity and transparency. The Internet of Things (IoT) devices can be essentially defined as an ecosystem of physical objects equipped with sensors, capable of collecting data about their surroundings, and internet connectivity, to enable them to communicate with each other or with centralised data collection platforms (Lele, 2018). This pervasive interconnection and capacity for real-world perception, intertwining hardware and software components (Asemani, Abdollahei, Jabbari, 2019; Rayers, Salam, 2019) - whose scope is evolving towards the concept of the “Internet of Everything” (Gaeta, 2018) - generates a vast and continuous amount of data that can be harnessed for the benefit of human existence. IoT stands at the crossroads of the contemporary regulatory debate, requiring a reconsideration of the paradigms for the protection (and circulation) of personal data and for cybersecurity. In this context, the IoT assumes a central and, at the same time, paradoxical role in the European Union’s vision for the “2030 Digital Decade”. On the one hand, it is designated as the technological engine for innovation and economic growth, promising to optimise industrial processes and transform citizen services. On the other hand, its uncontrolled proliferation, with billions of interconnected devices, generates an unprecedented cyber-attack surface, exposing critical infrastructures, privacy, and fundamental rights to systemic risks.
Pag. 66 To govern this duality, the EU has developed a comprehensive regulatory framework. Through key legislative acts such as the GDPR, the Cyber Resilience Act, the NIS2 Directive, and the Data Act, the European strategy aims not only to mitigate risks but also to transform security, trust, and transparency into a competitive advantage. A common feature of all the initiatives on the EU data strategy is the risk-based approach. This requires main actors to analyse how a data-driven activity could affect the fundamental rights of target groups and, therefore, which safeguards must be put in place in order to avoid harm in the given application scenario(s). These standards were initially introduced for privacy-preserving techniques and have since been extended to a general concept of an ethical-legal assessment for the protection of fundamental rights. The current European regulatory framework for the IoT cannot be interpreted as a mere set of technical rules; rather, it represents a fundamental instrument for the realisation of a precise strategic vision: the achievement of digital sovereignty (AmCham EU, 2021). This ambition, outlined in the “2030 Digital Compass” programme (Consolari, et al., 2023), is the European Union’s response to growing global technological competition and the need to reduce its strategic dependencies (Makowska, 2021). As already analysed, the strategy is structured around four interconnected pillars (Novelli, 2023): the strengthening of digital skills; the development of secure and autonomous infrastructures (from 5G to semiconductors) (European Commission, 2021); the acceleration of the digital transformation of businesses; and the complete digitalisation of public services. At the heart of this vision is the valorisation of data as a strategic resource. The free and secure circulation of information, particularly the enormous volume of data generated by the IoT, is considered an imperative for competitiveness and innovation (European Commission, 2023). The EU’s strategy for capitalising on this potential entails extending the foundational principles of its single market to the digital domain (Ferri, 2022), with the final aim of forging a Single Market for Data. This nascent market is being constructed upon the bedrock principles of trust, security, and the stringent protection of fundamental rights, including that of personal data (Camera dei Deputati, 2022; Caggiano, 2020). Consequently, any rigorous analysis of the specific regulations applicable to the IoT must be situated within this overarching politico-economic framework, as they are the primary instruments for realising this strategic ambition. The pervasive impact of the IoT is not limited to revolutionising the economic-industrial fabric; it also raises systemic challenges for the social and legal order. Alongside its undeniable benefits, critical implications emerge that affect the privacy and security of data, the protection of intellectual property, and consumer protection (Vinuesa, Azizpour, Leite, Balaam, Dignum, Domisch, 2020). This technological acceleration highlights the structural limitations of existing regulatory frameworks. The law, conceived for more static contexts, struggles to govern such complexities, making it essential to develop new regulatory approaches capable of adapting to the volatile characteristics of emerging technologies (Akpobome, 2024). The proliferation of technologies like the IoT creates a profound discontinuity in traditional data protection paradigms. The ubiquity of devices, evolving towards an Internet of Everything, generates a vast production of data and a potential global private-public surveillance network that erodes the traditional boundaries of the private sphere. This phenomenon raises systemic issues that call into question the effectiveness of the protection offered by the GDPR. The main challenges relate, firstly, to the quantity and type of data collected, which include not only information actively provided but also inferential data deduced from user behaviour. Secondly, the complex architecture and limited interfaces of the devices undermine informational self-determination, making it arduous for the data subject to provide valid consent. This is compounded by the ambiguity in the attribution of roles and responsibilities among manufacturers, platform providers, and third parties, creating uncertainty as to who holds effective control over the data (Sicari, Rizzardi, et. al., 2015a). Finally, the proliferation of
Pag. 67 connected sensors exponentially increases the attack surface for malicious actors, inextricably intertwining data protection profiles with those of cybersecurity (Perera, Rizzardi, et. al., 2014). In this context, as it will be analysed in greater detail later, the GDPR stands as the benchmark regulatory framework, but its application requires an evolutionary interpretation to govern the complex dynamics of the IoT ecosystem (Poletti, 2022a). The interaction between consumers and the IoT introduces a paradigm that facilitates manipulative commercial practices. The granular collection of data on lifestyles and habits allows for the adoption of predatory commercial strategies, compromising the user’s decisional autonomy. There is therefore the need to broaden the concept of the “vulnerable consumer” to include the induced manipulability of the IoT which, by acting through opaque algorithms and predictive analytics, can affect the average consumer indiscriminately (Noto La Diega, 2023). This imbalance is aggravated by a “contractual quagmire”, in which the consumer faces overlapping legal regimes, inadequate pre-contractual information, and practices such as bricking - the remote disabling of a device’s smart functionalities by the provider (Noto La Diega, 2023). These complexities reverberate upon the product liability regime. Directive 85/374/EEC, as amended by Directive (EU) 2024/2853 96 , reveals its inadequacy in the face of new types of defects that emerge in IoT objects, resulting, for example, from software updates, sensor malfunctions, or security vulnerabilities. The high degree of automation in IoT systems makes it difficult to trace damage back to human fault, necessitating a radical revision of the very concept of a “product”. The latter must now be understood as an inseparable amalgam of hardware, software, data, and services, in order to ensure a clear attribution of liability in a constantly evolving ecosystem (Sicari, Rizzardi, et. al., 2015b). 7.1 Data protection in the context of IoT devices As previously mentioned, IoT devices produce a vast amount of data, and the profound physical-digital surveillance of the data subject risks eroding the boundaries of privacy. In this context, the GDPR stands as the primary regulatory instrument for restoring users’ control over their data. However, despite its technological neutrality, its application to the IoT is complex due to the intrinsic characteristics of this technological environment, such as sensor fusion and limited interfaces, which make it difficult to implement fundamental principles like informed consent and purpose limitation. Data processing in the IoT is therefore pervasive, as it can easily include personal data, even when it is not apparent (Bolognini, Bistolfi, Zigler, 2019). The widespread proliferation of IoT devices means that even the collection of non-personal data can lead to the indirect identification of an individual by combining information from various sources. This risk is acknowledged by recital 26 GDPR, which establishes that identifiability must be assessed based on all “reasonably available” means, considering factors like cost, time, and technology. As technology evolves, this dynamic threshold for identification lowers, consequently classifying more data as personal. A well-calibrated sensor able to report the precise level of gravity force, which varies from one place to another, can reveal information on the location of the data subject (Pacheco Huamani, Zigler, 2019). These numerous digital traces generated by IoT devices, even if not directly personal, can be combined (socalled “linkage” or “sensor fusion”) not only to identify the individual but also to increase the exposure surface 96 Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC.
Pag. 68 of personal data, facilitating profiling and the granular tracking of the data subject’s habits and activities, often passively (Zigler, Crettaz, et. al., 2019). The value of data in the IoT, therefore, lies not in the raw data itself, but in the inferences that companies are able to derive from it, allowing them to track habits, preferences, and behaviours (Guarda, Bincoletto, 2023). Although one might mistakenly think that inferential data is not personal, case law has sometimes confirmed its inclusion within the definition of personal data, thereby applying the GDPR. Although inferential data may not be directly attributable to an individual, it may fall within the definition of personal data, as it may be capable of revealing their identity. This extensive interpretation, oriented towards the protection of the data subject, implies the application of the GDPR and its related data protection principles, rights and obligations, despite the practical complexities that obviously arise. This data, although not directly personal, may possess individual characteristics that can lead to profiling processes and subsequent decisions on the data subject, reinforcing its identification as personal data 97 . Marketing choices can be based on this data, which then represent an asset for the entity controlling it. The traditional dichotomy between personal and non-personal data risks proving inadequate today for resolving questions regarding the application or non-application of the GDPR in the IoT context. The rapid pace of technological development has created a crisis for methodological approaches anchored to static legislative definitions. The distinction between personal and anonymous data tends to blur in practice, making clear the need for a regulatory approach based on case-by-case analysis and the application of guiding principles in rapidly evolving contexts like the IoT. To distinguish personal from anonymous data, the GDPR states that it is necessary to assess the identifiability of the data subject. This involves evaluating the potential for linking the information to a specific natural person (Irti, 2019). As clarified by Recital 26 (Finck, Pallas, 2020) and the case law of the CJEU since the landmark Breyer case, assessing identifiability requires consideration of all the means reasonably likely to be used by the data controller or a third party (Irti, 2019). The reasonableness of such means depends on some factors such as the cost and time required for identification, the technologies available at the time of processing, and their foreseeable developments. These factors seem objective. However, identifiability is not an absolute concept but a dynamic risk. Although it is possible to mitigate it, a residual risk of re-identification almost always remains. From the perspective of the GDPR’s risk-based approach, the controller has the responsibility to constantly monitor this risk, adopting suitable technical and organisational measures to prevent re-identification (Irti, 2019; Finck, Pallas, 2020). On this point, a certain interpretive heterogeneity has been noted among national supervisory authorities. The Italian Garante Privacy, in line with WP29’s Opinion 05/2014, has adopted a strict interpretation, according to which any technique that allows a risk of singling-out the data subject to persist leads to pseudonymisation, not anonymisation (and then the applicability of the data protection framework). Similar positions have been expressed by the French CNIL. The Irish DPC appears to hold a different view, considering data to be anonymous if the unlikelihood of re-identification can be demonstrated according to the criteria of Recital 26 (Lodie, Lauradoux, 2024). It should be noted that the EDPB has also adopted a rather strict interpretation regarding pseudonymisation, drawing criticism from industry operators (EDPB, 2025; IAB Europe, 2025). Facing this heterogeneity, the CJEU’s case law has historically adopted a “relative approach” to the concept of identifiability, a position that has been further solidified in recent rulings (Rupp, Von Grafenstein, 2020). In the Scania (C-319/22), OLAF (C-479/22), and IAB Europe (C-604/22) judgments, the Court reiterated that the analysis must consider the means reasonably available not only to the controller but also to third parties, such as recipients, and that the mere legal possibility of lawfully obtaining additional information for 97 CJUE, C-582/14, Judgment of 19/10/2016, P. Breyer c. Bundesrepublik Deutschland; ECoHR, Benedik v. Slovenia, application no. 62357/14, 24/04/2018.
Pag. 69 identification is sufficient to classify the data as personal (Roßnagel, 2024) 98 . Of particular significance is the most recent EDPS v. SRB case of 2025 (T-557/20, now C-413/23), which ruled that the perspective of the data recipient is decisive: pseudonymous data can be considered anonymous for a party that does not have reasonable means to re-identify it. In summary, data can only be considered anonymous if re-identification is “reasonably unlikely” in the specific context and with respect to a given actor in terms of time, cost and labour (Lodie, Lauradoux, 2024). This approach seems more subjective than before. To address this complexity, assessment tools such as the Anonymity Assessment have been proposed. This is an interdisciplinary methodology aimed at measuring the degree of anonymisation (or pseudonymisation) of a dataset, combining an objective analysis of the re-identification risk (based on statistical metrics like kanonymity, l-diversity, t-closeness) with a subjective evaluation that considers the perspective and capabilities of the data controller or recipient. Such a tool, configured as a practical application of the data protection by design principle, can support operators in choosing the most appropriate techniques (Kolain, Grafenauer, Ebers, 2022). Nevertheless, the IoT presents additional challenges. The data flows generated by sensors are often so rich with information that they may render anonymisation ineffective (Poletti, 2022). Furthermore, personal and non-personal data can be so intrinsically linked that their separation is impossible. The continuous evolution of re-identification techniques requires constant monitoring of the measures adopted (Irti, 2022). Since complete anonymisation may constitute a concrete technical utopia in some cases and re-identification capabilities are constantly improving, the focus of legislators and operators should arguably shift. Rather than pursuing the unattainable goal of eliminating all risk of de-anonymisation, it would be more pragmatic to concentrate on the effective management of the residual risks associated with de-identified data, whether they be pseudonymous or imperfectly anonymised (Finck, Pallas, 2020). Tools like the Anonymity Assessment already offer a methodology to do this in a structured way (Kolain, Grafenauer, Ebers, 2022). This would imply an even greater emphasis on robust security measures, transparency regarding residual risks, and, hopefully, a regulatory framework that acknowledges this reality more pragmatically, definitively formalising the risk-based approach (IAB Europe, 2017). Therefore, open source solutions should be promoted to offer free, or at least expensive, tools for data controllers, for SMEs especially. Moreover, one of the most complex issues regarding the application of the GDPR to IoT devices concerns the identification of a suitable legal basis to legitimise the many processing activities. Although the data subject’s consent is often the preferred basis, its strict conditions for validity - i.e. that it must be free, specific, informed, unambiguous, and granular (EPDB, 2020; Belisario, Riccio Giovanni, Scorza, 2023) - are difficult to reconcile with the intrinsic complexity of IoT devices. The challenges arise from the conditionality of consent (or “bundling”) (WP29, 2014), the collection of data for multiple purposes (“function creep”) (Bolognini, Baldoni, 2019), and the aforementioned sensor fusion, making it almost impossible to provide clear and precise information to obtain fully informed consent or, conversely, to manage its withdrawal when the data subject makes this choice (Guarda, Bincoletto, 2023). The capacity to provide information represents a particularly difficult problem. Hardware limitations (small or no screens) (Gaeta, 2018), difficulties in identifying the device (and consequently in understanding the processing carried out) (Noto Dalla Diega, 2022; W.K. Han et al., 2016; Edwards, 2018), and the inability to identify third parties with whom information is shared, undermine the data subject’s ability to be aware of the processing (WP29, 2014). Added to this are subjective factors, such as the user’s lack of interest in knowing the details of the processing and their inability to understand its content due to the legal and technical jargon that characterises the device (Esposito, 2024). 98 CJUE, C-413/23, Judgment of 04/09/2025, EDPS v. SRB.
Pag. 70 To overcome these obstacles, it appears necessary to develop a regulatory framework at the European level - through the intervention of the EDPB or the approval of certifications and codes of conduct (Lachaud, 2020) - that governs in greater detail the methods for expressing consent in the IoT (Gaeta, 2018). Besides consent, other legal bases can also legitimise the processing of personal data by IoT devices. For instance, processing may be lawful if it is necessary to safeguard the vital interests of the data subject, such as in an emergency situation (Gaeta, 2018; ICO, 2025). It may apply in the context of IoT and medical devices but also other systems (e.g. fire identification system) used in a smart home. Another valid legal basis for the processing of personal data is the performance of a contract, applicable in many contexts such as the sale of a vehicle or entering into an insurance policy. As it will be explained later, the contract is an important source of rules in the IoT context. The legitimate interest of the data controller may also justify the processing of data. According to Art. 6, par. 1, lett. f) GDPR, this occurs when the processing is necessary for the purposes of a prevailing legitimate interest pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject. A clear example of this arises when the manufacturer (the data controller) has a legitimate interest in fulfilling product safety obligations, such as those imposed by Regulation (EU) 2023/988 - Cyber Resilience Act, which have been mentioned in the preceding sections. The legitimate interests basis is even used for the activities of improving the functionality and efficiency of the systems. Since this legal ground is rather subjective, it may be subject to abuse. Therefore, criteria could be provided by the authorities to guide the interpreter. In addition to the applicability and the issues related to the legal grounds, the architecture of IoT systems, characterised by the simultaneous involvement of numerous actors, generates significant ambiguity in the assignment of roles under the GDPR. The operational context is pivotal, as the qualifications of controller and processor do not derive from a formal designation but from a functional analysis of the activities actually performed (EDPB, 2021). The controller determines the means (including technical instruments and functionalities) and purposes of the data processing, while the processor carries out activities on its behalf and based on defined instructions. This approach is at odds with the dynamic nature of the “processing chain” that is characteristic of the IoT (Mäkinen, 2015). This chain involves a plurality of actors who can, depending on the circumstances, assume the role of controller (or maybe join-controller in some cases). These actors include device manufacturers, who define the operating system’s functionalities and data collection methods, and platform managers, who determine the purposes of the processing. In addition to these, third-party application developers often act as independent controllers for the data they access while providing some services necessary for the functionality of the connected systems. Moreover, other third parties, such as insurance companies or other intermediaries, reuse this information for further purposes (Poletti 2022a; Guarda, Bincoletto, 2023). They may receive the information on the basis of contracts with the original controllers. The presence of all these actors can generate a series of variable scenarios based on their actual involvement in the data processing (Poletti, 2022a). This complex web of interests creates a “relational black box”, making it arduous for the end-user to identify the actual data controller subject to the main obligations (Noto La Diega, 2023). An enterprise that uses IoT devices may be qualified as a controller or, in the case of joint decisions, as a joint controller (De Conca, 2020). This makes a “case-by-case” analysis indispensable for correctly allocating roles and responsibilities (EDPB, 2021). The uncertainty related to the roles exacerbates the user’s potential loss of control. This may have a negative impact on the concept of individual sovereignty in the IoT context. To mitigate this risk, all stakeholders should adopt rigorous data protection by design and by policies. The measures cannot be fully suggested because a case-by-case analysis should be performed. Anyway, these should certainly include limiting the volume of outbound data from devices and prioritising the processing and aggregation of raw data directly on-device before any export to third parties (WP29, 2014).
Pag. 71 A similar analysis is required for the role of the processor. This entity is limited to processing data “on behalf of” the controller, defining only the operational means of processing and physically handling the IoT data. Therefore, it will act as a processor only if it exercises no autonomous decision-making power. It is crucial, then, to draft clear and robust data processing agreements between controllers and processors (Art. 28 GDPR) that allow these entities to precisely define their respective obligations and responsibilities (Bolognini, Baldoni, 2019). Including the application of data protection by design and by default measures by the processor is equally important. This enforces the reference already made in Recital 78 GDPR on producers of products and providers of services. 7.2 Adopting data protection by design & by default to achieve data sovereignty in the Iot context The principles of DPbD and bu default (Art. 25 GDPR) are cornerstones of the data protection regime. As explained in the previous sections, the former requires the integration of safeguards right from the design phase (ex ante) of the processing, while the latter requires that, by default, only the data strictly necessary for each specific purpose be processed. Although the application of these principles is essential for mitigating risks, their strict implementation in the IoT can create tension with interoperability and even innovation (Di Ruggiero, 2021; Pinto, Donta, et. al., 2024). A system designed to be highly adaptive, as is typical in the IoT, is not easily reconciled with rigid rules of data minimisation or purpose limitation, which could stifle its functionality or future evolution. The application of these principles, therefore, raises a fundamental dilemma: how can the maximisation of technological utility be reconciled with the guarantee of adequate data protection required under Art. 25 GDPR and by extent its all obligations? To answer this key question, several indispensable strategies emerge. First of all, it can be suggested the adoption of a conscious design plan: this translates into the systematic integration of security and privacy principles from the initial stages of the ICT systems’ development lifecycle, guiding the actions of data controllers and processors (Rodriguez, A. Q., Ziegler, S., Hemmens, C., et. al., 2019; O’Connor, et al., 2017). Carefully mapping of the data flows is pivotal. Identifying the nature, scope, context and purpose of the processing is relevant. Then, the assessment of the risks involved by the processing is key. A compliance budget should be estimated and allocated. Moreover, it should be stressed the importance of the concrete application of technical and organisational measures: the use of Privacy-Enhancing Technologies (PETs) (Li, Palanisamy, 2018) is crucial for safeguarding data (Del-Real, De Busser, van den Berg, 2025) and must be corroborated by effective organisational management that clearly defines roles and responsibilities (e.g., through a privacy organisation chart) and provides for in-depth risk assessment, with particular attention to high-risk processing 99 . In this case, Art. 35 GDPR mandates a DPIA for processing resulting in “high risk” to the rights and freedoms of individuals, particularly when new technologies are employed. IoT applications frequently fall into this category due to their significant privacy impact on private life, the systematic nature of their data processing, and their potential for automated decision-making. Consequently, a DPIA is an almost invariably mandatory tool for IoT projects, functioning proactively to identify and mitigate risks, thereby operationalising the core principle of accountability for the data controller (WP29, 2014; Poletti, 2022a). The state of the art of technologies should be evaluated and applicable certification mechanisms should be promoted. Contracts should be stipulated among parties and eventually agreements between joint controllers. In addition to the DPIA, a record of the processing (Art. 30) may be useful to map the activities. Other useful measures will be highlighted in the final section. 99 GPDP (2018). Allegato 1 al Provvedimento n. 467 dell’11 ottobre 2018 [doc. web n. 9058979]. Gazzetta Ufficiale, n. 269 del 19 novembre 2018; AEPD (2019). Listas de tipos de tratamientos de datos que requieren evaluación de impacto relativa a protección de datos (Art. 35.4).
Pag. 72 Guaranteeing user control in the IoT context is particularly important: it is necessary to provide users with granular control over their data, facilitating the exercise of their rights and providing intuitive options (e.g., ‘do not collect’) to quickly deactivate sensors and limit the collection of information (Bolognini, Balboni, 2019). This is in line with the improvement of data sovereignty. The establishment of an IoT environment that is oriented towards data protection by design is not merely a possibility, but rather an imperative to ensure user trust. This necessitates a concerted and proactive effort from all relevant stakeholders, including developers, manufacturers, supervisory authorities, and even legislators, to promote tech development that is mindful of the interests and rights of data subjects (Aljeraisy, et. al, 2021; Perera, et. al., 2016). 7.3 Security and cybersecurity in the IoT context The very architecture that gives the IoT its intrinsic power is also the source of its most severe vulnerabilities. Market dynamics, geared towards low-cost production and rapid commercialisation, have historically marginalised security practices, generating an intrinsically fragile and high-risk digital ecosystem. The main cybersecurity issues for the IoT include vulnerabilities in device authentication, data integrity, confidentiality, and network security, largely due to the vast number of interconnected and often low-cost devices with limited security features (Meneghello et al., 2019; Dritsas, Trigka, 2025; Tariq et al., 2023). Common threats involve unauthorized access, data breaches, denial-of-service (DoS) attacks, and the exploitation of weak communication protocols, which can compromise the confidentiality, integrity, and availability of IoT systems (Meneghello et al., 2019; Tariq et al., 2023; Lone et al., 2023). The lack of standardized security specifications and the diversity of IoT devices make it difficult to implement consistent and robust security measures across different platforms and applications (Tariq et al., 2023; Schiller et al., 2022; Xu, 2019). Additional challenges arise from the integration of IoT with cloud services and 5G networks, which introduce new attack vectors and complicate threat detection and response (Singh et al., 2024; Narciandi-Rodriguez et al., 2024). Many IoT devices are deployed without adequate security considerations, making them easy targets for attackers and potentially turning them into entry points for larger network attacks (e.g., botnets) (Meneghello et al., 2019; Schiller et al., 2022). Added to this are the growing risks concealed within the software supply chain: as highlighted by ENISA, a vulnerability in a third-party component can compromise the security of the entire final product, often without the manufacturer’s knowledge (ENISA, 2024). Such vulnerabilities are not isolated incidents but rather a symptom of a systemic market failure, in which security has long been treated as an optional cost, thereby undermining consumer trust in digital products. Addressing these issues requires a holistic approach involving secure device design, improved management protocols, and ongoing research into advanced security solutions tailored for the evolving IoT landscape (Tariq et al., 2023; Schiller et al., 2022; Lone et al., 2023). The Cyber Resilience Act represents the foundational pillar of the European regulatory architecture for the IoT and cybersecurity context. As mentioned, it is a horizontal piece of legislation, the first of its kind in the world, which establishes mandatory cybersecurity requirements for products (divided into normal, important, and critical categories) with digital elements placed on the Union market (Zirnstein, 2024) 100 . The primary purpose of CRA is to enact a paradigm shift: transferring the responsibility for security from the end-user, who often lacks technical expertise, to the manufacturer, who controls the product’s design and 100 Art. 2 CRA.
Pag. 73 development. In essence, cybersecurity becomes a non-negotiable condition for access to the EU Single market through the institutionalisation of the security by design and by default (SbDD) principle 101 . Security by design means that it integrates security measures into the development process of digital technologies from the outset. This ensures that security is a foundational aspect of the system’s architecture and lifecycle, rather than an afterthought (Del-Real et al., 2025; Del-Real et al., 2024). Instead, security by default means that the settings of a connected device and service are secure as a basic setting (ANEC, BEUC, 2018; Ruohonen, et. al., 2025). This approach is closely related to, and inspired by, the data protection by design and by default principles. Although SbDD and PbDD share similar foundational principles and aim to proactively address risks (because also CRA adopt a risk-based methodology), SbDD is still evolving and tends to focus more on technical aspects such as the development of ICT products, services or processes 102 . SbDD can be seen as an extension of the GDPR philosophy, broadening the focus from data protection to encompass all aspects of security. Both methodologies advocate for early and continuous integration of their respective protections throughout the technology lifecycle to build trust and resilience in digital systems (DelReal et al., 2025; Del-Real et al., 2024; Gedeon et al., 2020). The SbDD principle is built on a set of foundational components that guide the integration of security into every stage of software and system development. Key components include (Ebad, 2022; Soundararajan, 2019; Beach et al., 2019): ● least privilege, i.e. restricting access rights for users and processes to the minimum necessary; ● defense in depth, i.e. layering multiple security controls; ● fail-safe defaults, i.e. defaulting to secure settings; ● economy of mechanism, i.e. keeping designs simple and small; ● complete mediation ensuring all access to resources is checked; ● open design, meaning security does not depend on secrecy of design; ● separation of privileges, which requires multiple conditions for access; ● least common mechanism, which equals to minimizing shared resources; ● psychological acceptability, i.e. making security mechanisms easy to use ● and finally, sound authentication and input validation. Modern frameworks, such as those from NIST 103 or ENISA 104 , expand these principles to include prevention/proactiveness, embeddedness (security built into the system, not added later), user-centricity, and transparency (Del-Real et al., 2025; Beach et al., 2019). SbDD also emphasizes threat modeling, secure coding practices, and continuous security testing throughout the software lifecycle (Mudavatu, 2025; Murat et al., 2024; Soundararajan, 2019). These components work together to proactively identify and mitigate vulnerabilities, tackling the problem of “weakness by default” at its root and protecting the consumer from cyber threats. The CRA also introduces other key requirements: ● vulnerability assessment and management: it seeks to resolve the issue of insufficient patching. The CRA makes the continuous management of post-sale vulnerabilities binding. Manufacturers must implement processes to identify and remedy vulnerabilities “without delay” and provide automatic security updates for the entire support period of the product (Ruohonen, et. al., 2025). This support 101 Recital nn. 32, 64; Art. 13; Annex I - essential cybersecurity requirements CRA. 102 Recital n. 12 CRA. 103 NIST. (2022). Special Publication NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems. Available at: https://doi.org/10.6028/NIST.SP.800-160v1r1. 104 ENISA (2019), Good Practices for Security of IoT - Secure Software Development Lifecycle, in ENISA Report. Available at: https://www.enisa.europa.eu/publications/good-practices-for-security-of-iot-1.
Pag. 80 EHDS, the IoMT manufacturer must register its datasets with the HDAB and, upon the latter’s instruction, transfer or grant access to the data for an authorised user. Another similarity lies in the intent to ensure fairness and transparency in the relationship between data holders and data recipients. This is achieved through the prohibition of unfair contractual clauses in Art. 13 DA and through the intervention of the HDAB in the EHDS to ensure that access is balanced and does not prejudice the interests of the data subject. Furthermore, building on the interoperability principles of the Data Act, the EHDS raises the standardisation requirements by explicitly focusing on semantic and technical interoperability at a European level for electronic health record systems. As noted, the regulation mandates the use of the EEHRxF for key clinical data types (Lianos, 2024). Currently, data from wearable or IoMT devices do not appear to fit neatly into the semantic categories of this standard. However, given the growing importance of such data, it would be prudent for the Commission to add new data classes in the future via delegated acts, specifically including IoMT data 132 . In the interim, IoMT manufacturers can proactively adapt their systems to support these formats if they wish for their device data to be integrated into the EEHRxF semantic categories. Despite these converging goals, the divergences between the DA and the EHDS are marked. The primary difference lies in the purpose of data reuse. In the DA, access to IoT data is not tied to predetermined purposes; any user (e.g., a hospital or an individual) can request data from an IoMT device, with the sole requirement that the data processing has a valid legal basis under the GDPR. The EHDS, conversely, circumscribes the permissible purposes for secondary use to those linked to scientific research, development of health innovations, public health protection, and health policy planning (Art. 53 EHDS) (Casarosa, Gennari, 2025). A second key difference resides in the procedural access mechanism. The Data Act favours a decentralised and autonomous private-led model, where access to IoMT data occurs through direct contractual agreements or immediately operative obligations between private parties. This bottom-up approach is, in principle, more flexible as it does not require prior public authorisation, though it necessitates the management of trilateral relationships (user, manufacturer, and third party). The EHDS, by contrast, adopts a centralised, top-down approach with a strong public oversight component. Access to data is filtered through an authority (the HDAB), which acts as a single point of contact at national level. This guarantees a higher level of uniformity and rigour but may introduce procedural delays due to the involvement of an intermediary (Casarosa, Gennari, 2025). A third point of differentiation concerns the range of entities authorised to access IoMT data. In the Data Act, the initiative lies with the device user. If the user does not act - by either requesting data or authorising a third party - the data remains with the manufacturer (barring any voluntary sharing by the latter) 133 . Under the EHDS, access can be requested by entities potentially extraneous to the original device-user-patient relationship, such as universities, research centres, pharmaceutical companies, and medtech start-ups, which may have no direct contact with the data subject (Casarosa, Gennari, 2025). To sum up, the Data Act and the EHDS can be viewed as complementary mechanisms. The former provides a flexible, private-law model for sharing IoMT data that is immediately applicable even without centralised infrastructures. The latter establishes a structured, public-law model designed to leverage health data on a large scale for research and innovation. The coexistence of both frameworks offers IoMT manufacturers and users multiple options for valorising data, ensuring its circulation through the implementation of open formats and interoperability mechanisms. 132 Recital nn. 26 e 56 and Art. 14, par. 2, EHDS. 133 Recital n. 15 and Art. 4 Data Act.
Pag. 81 Both Regulations foster interoperability, access and sharing in a way that promotes data sovereignty at EU and national levels. 7.7 Conclusions: policies for the IoT context The analysis of the IoT context tried to highlight that a distinctive feature of digital regulation is that vertical legislation is not the sole entry point for mandatory security and data flow requirements; instead, it is strictly complemented by contractual arrangements. In fact, these agreements are becoming the primary vehicle for ensuring regulatory compliance with all new EU frameworks throughout the supply chain. Consequently, the imposing European regulatory architecture does not operate in a vacuum; rather, it mandates a profound and necessary contractual overhaul to translate these legal principles into operational obligations. In this context, the contract ceases to be a mere transactional instrument and assumes the role of a cornerstone for compliance. The analysis of this contractual revolution unfolds on two main fronts: the supply chain (upstream relationships with suppliers) and the relationship with the end-user (downstream relationships with customers). The new regulatory framework renders these two axes legally interdependent, as the guarantees regarding security, maintenance, and data access that a manufacturer is obliged to provide to its customers (under the CRA and the Data Act) depend directly on its ability to impose and verify equivalent obligations upon its suppliers (under NIS2). The contract thus becomes the instrument managing this “cascading” liability throughout the entire value chain. Contractual governance should redefine relationships with suppliers, specifically to safeguard the security and resilience of the supply chain. The risk-based approach - as demonstrated in this deliverable, a cardinal principle of the entire EU strategy - mandates a due diligence process that finds its necessary implementation within the contractual framework. Organisations are obliged to conduct a rigorous risk assessment of suppliers, which must not be limited solely to their organisational resilience (which may impact the resilience of a NIS2scope organisation itself), but must necessarily extend to the intrinsic security of the product supplied, which must in turn comply with the “by design” requirements of the CRA and the data protection framework. Entities should therefore ensure that their service providers adhere to these stringent (and dual) security standards (Slapničar et al., 2025) and data protection rules. As a result it may be argued that a comprehensive update of contractual frameworks is necessary to include specific clauses, such as clear incident notification procedures, vulnerability management obligations, auditing and continuous monitoring requirements, as well as adherence to recognized standards (such as ISO/IEC 27001 or IEC 62443 for industrial systems) as a tool for verifiable assurance (Michota, Polemi, 2022; Song, Wang, et al., 2024). This need is further accentuated by the introduction, via NIS2, of direct personal liability for management in cases of non-compliance, compelling leadership to demand reinforced guarantees in value chain management. Targeted contractual subject matter, the definition of precise SLAs, together with the inclusion of liquidated damages clauses resulting from a cybersecurity incident, thus constitute the essential elements to incentivise supplier performance. Moreover, the contractual rules should redesign relationships with customers and end-users to clearly delineate rights and opportunities within the connected IoT ecosystem. This transcends the traditional product liability regime and addresses two key aspects: ● maintaining security: the CRA imposes direct liability on the manufacturer, obliging them to integrate cybersecurity from the design stage and by default. This is no longer a mere contractual option, but a legal requirement for obtaining the CE marking. Consequently, customer contracts should be transparent not only regarding initial compliance but also regarding the manufacturer’s binding
Pag. 82 obligation to provide maintenance and security patches for the product’s entire lifecycle (Shaffique, 2024). This liability extends to integrated components, open-source software, and third-party APIs, making transparency not merely a factor relevant to the principle of good faith, but a fundamental legal burden; ● access and data sharing: in line with the Data Act, contracts can no longer rely on ambiguous wording; it is necessary to specify “data sharing modalities” transparently and granularly to make such rights concretely exercisable. Although manufacturers (as data holders) physically hold the data and continue to exploit it for their own purposes, they lose the capacity to do so unilaterally and opaquely. For any use of non-personal data generated by the product (going beyond the mere provision and maintenance of the service), they must now enter into an explicit agreement with the user, who in turn obtains nonwaivable rights of access and sharing with third parties (Eckardt, Kerber, 2024; Kerber, 2022). The synergy between the regulatory frameworks is evident: NIS2 (demand) drives entities to contractually demand the security of their supply chain; the CRA (supply) compels manufacturers to provide secure products, consequently increasing the resilience of the purchasing entity. For both legal regimes, the contract represents the venue where parties can concretely strengthen their position and security. Furthermore, contractual management is also called upon to mediate the tensions between these security requirements (e.g., CRA product integrity obligations) and Data Act access rights; security measures cannot be used as a pretext to unjustifiably restrict data access (Chiara, 2025). Likewise, the contract must govern the tension between mandatory data access and the protection of trade secrets. Although a company cannot refuse access by generically appealing to trade secrecy, it can and must contractually demand adequate and rigorous guarantees (i.e., TPMs/DRM, NDAs, enforcement rights) (De Noyette, Stähler, et al., 2025). Contractual management has become so central that the European legislator has intervened directly to rebalance bargaining power. New information and good faith obligations have been introduced, accompanied by protections against unfair terms. Art. 13 of the Data Act is the most glaring example, prohibiting unilaterally imposed B2B clauses deemed abusive. Moreover, precisely for the Data Act, the EU Commission has recently published standard contractual clauses for B2B data sharing and cloud computing contracts. The use of these models would represent a favorable option for SMEs, which could avoid additional indirect costs linked to drafting contracts based on soft law and unaccredited best practices. It is hoped that the Commission might extend these initiatives to the cybersecurity front as well, defining unitary methodologies to guide entities in managing their supply chain. From data protection by design, security and open/access by design, the European legislator’s strategy is to embed the legal requirements of digital regulations directly within production processes. Across the various promulgated regulations and directives, one frequently observes the demand for products or services to be defined in a manner that already incorporates all requisite safeguards for the proactive protection of the data subject (or the user of said product/service, even considered consumer) in all respects. Indeed, the singular principle devoted to protecting data subject’s personal data ab initio (data protection by design and by default) has now been augmented with elements that are ancillary, yet simultaneously fundamental. Regarding security by design, it must be emphasised that the security (and cybersecurity) of IT devices (and indeed all connected devices) is essential for the secure management, and consequent protection, of the data subject’s data. In this respect, the principle - though transposed from its original domain - remains unchanged: it demands that the manufacturer undertakes a far-sighted governance of the device’s security throughout its entire lifecycle in a proactive way. This security is precisely what is embodied in the legal requirements and obligations of the Cyber Resilience Act. Likewise, in the context of the Data Act, IoT devices are required to be accessible by default. This permits the user to perform extraction - even automated - of the data generated therein, thereby reinforcing their empowerment. These “by design” principles share more than a methodological approach; they are, in fact, inextricably linked. Data protection, access, and sharing cannot come at the detriment of device security - which could be targeted
Pag. 83 during this very process (particularly if requested by a legal entity). Concurrently, security by default cannot be so rigid as to inhibit access, nor so lax as to render it susceptible to attack and thus fail to protect personal data. Data protection by design, however, stands as the inviolable cornerstone of this triptych, demanding robust balancing in its application. This interplay does not represent a mere technical challenge; it ascends to a legal and ethical imperative that redefines innovation within the European context. The horizontal expansion of the “by design” principle - from data protection to security and access - marks the definitive supersession of a siloed approach to compliance, demanding a proactive, ex-ante synthesis from economic operators. The ultimate objective of this horizontal strategy is to ensure that every new technology or service placed on the Digital Single Market is, by its very architecture and default configuration, a vector for the protection - and not the potential erosion - of the individual’s freedoms and digital and data sovereignty. Data management within the IoT ecosystem is dominated by a structural tension between openness and proprietary control. The economic utility of such datasets often lies in their reuse for analytical purposes not originally envisaged at the time of collection, effectively defining business models initially unforeseen by digital regulation. Data governance now transcends the boundaries of mere data protection to extend into cybersecurity, accuracy, accessibility and availability, especially for AI systems. For the latter, IoT data constitutes the essential foundation for training, validation, and development. In this scenario, mere formal compliance is no longer sufficient. Instead, a holistic approach is required, placing a compliance by design strategy at the core of every industrial project. Under the principle of accountability, organisations must conduct preventive assessments that intersect various regulations, such as combining DPIA and FRIA evaluations (Thomaidou, Limniotis, 2025). Consequently, the management of IoT data can no longer be conceived as an isolated process within a single organisation. It must be oriented towards sharing and value creation. While the Data Act and DGA mandate a paradigm shift towards such openness, this transition raises two substantial operational and economic challenges. The first major hurdle involves technical accessibility. The question arises as to how the manufacturer, or data holder, can make data accessible and interoperable for third parties efficiently. Although semantic standards exist (e.g. ETSI NGSI-LD or ISO/IEC 21823), their implementation involves significant management and infrastructure costs. Prior to the Data Act, these transaction costs could be contractually shifted to the party requesting access. The new framework partially reverses this burden by obliging manufacturers to design products for access by default. This forces them to bear the initial data structuring costs, with the possibility of financial recovery limited to direct costs and only on a deferred basis (Kerber, 2023). The second challenge lies in the intrinsic regulatory complexity of IoT datasets. Connected devices generate hybrid databases intertwining technical non-personal data with personal and behavioural inferential data. Since the latter fall fully under GDPR obligations, they necessitate robust pseudonymisation or anonymisation to mitigate re-identification risks. This creates an economic dilemma because applying PETs, such as differential privacy or homomorphic encryption, is computationally expensive and skill-intensive. Furthermore, robust application often degrades data quality to the point of hindering the original analytical purposes, forcing companies to choose between compliance and business value (NIST, 2016; ENISA, 2023). This situation prompts a critical reflection. While data availability and openness are laudable goals, they are extremely costly processes requiring careful planning. Paradoxically, the current European framework risks raising entry barriers. The high cost and complexity of compliance threaten to crystallise the market power of Big Tech, as only these players possess the financial and technological resources to amortise the adaptation costs, e.g. for the Data Act and AI Act. This dynamic threatens to transform regulation into an involuntary competitive moat to the detriment of SMEs and innovative startups (Crémer, et al., 2019).
Pag. 84 To attempt to rebalance this structural asymmetry, the EU legislator introduced data intermediation services via the DGA and the EHDS Regulation. These neutral third parties act as fiduciary facilitators connecting data holders and users. By reducing transaction costs and overcoming mistrust between competitors, they allow for secure data aggregation and standardisation, thereby bypassing the technical and organisational obstacles that hinder direct portability (Fabianek, et al., 2024; Schweihoff, et al., 2024). However, these entities will be appointed at national level; therefore, risks of fragmentation of concrete policies arise. Moving to the policies, the following conclusive table contains measures aimed at balancing cybersecurity and data protection with transparency requirements. They may be applicable both in the public and private sector in light of achieving digital and data sovereignty. The description of the measures is limited to those that can “by design” protect individuals’ rights and enhance cybersecurity and transparency. Measure Description Rule / Principle / Source CYBERSECURITY Map data flows in the concrete context A clear data flow ensures allocation of resources and liabilities. Accountability (GDPR) No universal default passwords IoT devices must not use immutable, universal passwords. Each device must have a unique password or require the user to define one upon initialization. ETSI EN 303 645 (Prov. 5.1); Cyber Resilience Act (Ess. Req. Annex I) Threat modeling & risk assessment Conduct structured threat modeling to identify, analyze, and rank security and privacy risks; document mitigation strategies. ETSI EN 303 645 (Preamble & Annex B); Cyber Resilience Act (article 8-10); NIST Threat Modeling Framework Vulnerability disclosure policy Manufacturers must provide a public point of contact for security researchers to report vulnerabilities and must publish a policy on how they handle these reports. ETSI EN 303 645 (Prov. 5.2); ENISA Guidelines on VP; Cyber Resilience Act (Art. 11)
Pag. 85 Software update mechanism Devices must have a secure, automated (or easily manageable) mechanism for software updates. Updates must be verified (signed) to prevent malicious code injection. ETSI EN 303 645 (Prov. 5.3); Radio Equipment Directive (RED) DA Art. 3(3); EN 180311 Firmware Security Defined support period Manufacturers must explicitly state the minimum period during which the device will receive security updates. Cyber Resilience Act (Transparency Req.); Directive (EU) 2019/771 (Sale of Goods) Secure storage of particular (sensitive) data Credentials and keys must be stored securely within the device (e.g., using a Trusted Platform Module - TPM or Secure Element) and not hard-coded in the source code. ETSI EN 303 645 (Prov. 5.4); ISO/IEC 27402 Secure communication protocols and End-to-End encryption IoT devices must use industry best-practice cryptography for all communications; encryption for both data in transit and machineto-machine communication; encryption for sensitive data in rest. ETSI EN 303 645 (Prov. 5.5); EN 18031-2 Security Requirements; ENISA Guidelines on IoT Security; TLS/SSL Best Practices (IETF RFC 8446) Software bill of materials (SBOM) Manufacturers must maintain a record of all software components (including thirdparty libraries) used in the device to facilitate rapid vulnerability management. Cyber Resilience Act (Art. 11, Annex I); EN 18031-1 ( Documentation Requirements) Attack surface minimization Unused network interfaces (e.g., debug ports, Telnet) and services must be disabled by default. The principle of “least privilege” applies to processes. ETSI EN 303 645 (Prov. 5.6); NIST IR 8259A Supply chain security assessment Evaluate third-party suppliers for security and privacy controls; maintain documented assessment of supply chain risks ENISA Guidelines for Securing IoT Supply Chain (2020); ISO 27002 A.1 Supplier Assessment; NIST SP 800-161 rev. 1 (Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations)
Pag. 86 Back-up and recovery mechanisms, intrusion control system, audit and log systems Implementation of these technical mechanisms for data at rest Integrity, confidentiality, accountability, transparency Stipulate contracts with clauses on cybersecurity and conditions for liability The contractual level is key to allocate liability and responsibility for compliance. Accountability DATA PROTECTION Data protection by design & default Devices must be configured to the most privacy-friendly setting by default. Data collection should be disabled unless necessary for the core function. To do so, it is necessary to identify the nature, scope, context and purposes of the data processing, and evaluate the risks for the data subjects considering varying likelihood and severity. GDPR (Art. 25); EDPB Guidelines 4/2019 (Art. 25); ETSI EN 303 645 Recommendation Perform a gap analysis on the applicable rules Both the EU and national rules should be analysed to point out the applicable legal requirements and translate them as functional requirements. Lawfulness (GDPR) and accountability Define legal grounds in a granular and modular way Many grounds should be defined according to the specific data processing activities. Lawfulness (GDPR)
Pag. 87 Define specific measures for data portability Access and data portability is required in every phase. GDPR and Data Act Data minimization The device should only collect data strictly necessary for the requested service. Raw data should be processed locally where possible, sending only aggregates to the cloud. GDPR (Art. 5.1.c); EDPB Opinion 8/2014 (Recent dev. in IoT); ETSI EN 303 645 Provision 5.8 Pseudonymization & anonymization Replace identifiable personal data with pseudonyms or anonymize data where feasible to reduce identification risk and protect personal data. ISO/IEC 27002 A.2.1 Data Protection Impact Assessment and record of the processing activities The DPIA and the record are useful tools to evaluate the context and then ensure compliance Accountability Stipulate contracts with clauses on data protection and transparent policies for the users The contractual level is key to allocate liability and responsibility for compliance. The policies for the users should be transparent and written in an accessible and clear language. Accountability DATA ACCESS Access control and identity management systems, authentication system and related policies Controllers and processors should define efficient and appropriate mechanisms for access and authorisation. Integrity and confidentiality, data minimisation
Pag. 88 User access to generated data Users (owners/renters of the device) have the legal right to access the data generated by their use of the IoT product in a readable format, free of charge, and to transfer the data directly to a third-party. EU Data Act (Artt. 4-8); ETSI EN 303 645 Recommendation; NIST SP 800-204 (Security Strategies for Microservices based Application Systems) Interoperability and switching specifications Common standards and open interfaces must be used to allow data to flow between different IoT ecosystems (avoiding vendor lock-in), facilitating switching providers. EU Data Act (Chapter VIII); ISO/IEC 21823 (IoT Interoperability); EN ISO/IEC 19944 (Cloud computing and distributed platforms ─ Data flow, data categories and data use) Entities should estimate and define the compliance costs and allocate resources to implement the measures. Certification and codes of conduct should be considered as important tools for compliance. Data control and openness must evolve into a sustainable equilibrium towards digital and data sovereignty. Real openness is impossible without granular control - managed multilaterally between manufacturer, user, and intermediary - nor can there be control generating economic value without openness. The challenge for legislators and industry is to transform compliance burdens from mere costs into levers for transparent and, hopefully, fairer data governance.
Pag. 89 References Agencies and supervisory authorities ACN (2022). Relazione annuale al Parlamento 2022, 8-22. Available at: https://www.acn.gov.it/portale/documents/20119/99437/ACN_Relazione_2022.pdf. ACN (2022). Strategia Nazionale di Cybersicurezza 2022-2026. Available at: https://www.acn.gov.it/strategia-nazionale-di-cybersicurezza. ACN (2024). Allegato II al Piano triennale di prevenzione della corruzione e della trasparenza 2024-2026, 56. Available at: https://www.acn.gov.it/portale/piano-triennale-di-prevenzione-della-corruzione-e-dellatrasparenza-2024-2026. ACN (2024). Linee guida per il rafforzamento della resilienza dei soggetti di cui all’articolo 1, comma 1, della Legge 28 giugno 2024, n. 90. Available at: https://www.acn.gov.it/portale/linee-guida-rafforzamentoresilienza. ACN (2025). Determinazione del 10 aprile 2025, recante disposizioni per l’attuazione della disciplina in materia di sicurezza delle reti e dei sistemi informativi ai sensi del D.Lgs. 4 settembre 2024, n. 138, e relativi allegati tecnici. AGCM (2020), (congiuntamente ad AGCOM e Garante per la protezione dei dati personali). Indagine conoscitiva sui Big Data. Available at: https://www.agcm.it. AGCM (2021). Caso A549 – Apple, abuso di posizione dominante nel mercato delle piattaforme di distribuzione di applicazioni. Decisione n. 30833. Available at: https://www.agcm.it. AGCM (2023). Regolamento sulle forme di collaborazione e cooperazione ai sensi dell’articolo 18 della Legge 30 dicembre 2023, n. 214. Provvedimento n. 31295. Available at: https://www.agcm.it/dotcmsdoc/normativa/concorrenza/p31295_Regolamento_collaborazione_cooperazione _art_18_l_214_2023.pdf. AGCOM (2025), Relazione annuale 2025 sull’attività svolta e sui programmi di lavoro, 16/07/2025. Available at: https://www.agcom.it/sites/default/files/documenti/relazione_annuale/RELAZIONE%20ANNUALE%20202 5_0.pdf AGENAS (2022). Approfondimento: piano nazionale di ripresa e resilienza. In Monitor - Elementi di analisi e osservazione del sistema salute, n. 45, 79. Available at: https://www.agenas.gov.it/archivio-monitor2021/1918-nuovo-monitor-45. AgID (2023). Linee guida recanti regole tecniche per l’apertura dei dati e il riutilizzo dell’informazione del settore pubblico, Capitolo 8.3. Dipartimento per la trasformazione digitale (2022). Misura 1.3.1 Piattaforma Digitale Nazionale Dati (PDND) - Avvisi per Comuni e Regioni (Casi d’uso). Available at: https://assets.innovazione.gov.it/1675333598misura-131_pdnd_avvisi-comuni_regioni_casi-d-uso.pdf. Dipartimento per la trasformazione digitale (2025). Piano Triennale per l’informatica nella Pubblica Amministrazione 2024-2026 - Aggiornamento 2025, 46–47. Available at: https://www.agid.gov.it/sites/agid/files/2025-01/Piano_Triennale_per_l_informatica_nella_PA_20242026_Aggiornamento_2025.pdf. EDPB (2017). Guidelines on Data Protection Impact Assessment (DPIA). Available at: https://ec.europa.eu/newsroom/article29/items/611236.
Pag. 96 Dalla Preda, M., Egelman, S., Mandalari, A. M., Stocker, V., Tapiador, J., Vallina-Rodriguez, N. (2025). EU Cyber Resilience Act: Socio-Technical and Research Challenges. Dagstuhl Reports, 14(3), 61-66. Available at: https://doi.org/10.4230/DagRep.14.3.52. De Conca, S. (2020). Between a rock and a hard place: owners of smart speakers and joint control. SCRIPTed, 17(2), 262-263. Available at: https://script-ed.org/?p=3884. De Gregorio, G. (2021) The rise of digital constitutionalism in the European Union, in International Journal of Constitutional Law, 19(1), 41-70. De Gregorio, G., & Radu, R. (2022). Digital constitutionalism in the new era of Internet governance. International Journal of Law and Information Technology, 30(1), 68–87. De Hert, P. & Hajduk, P. (2024). EU cross-regime enforcement, redundancy and interdependence : Addressing overlap of enforcement structures in the digital sphere after Meta. In Technology and Regulation, vol. 2024, 291-308. Available at: https://doi.org/10.71265/fydwsg59. De Minico, G. (2025). La governance della cybersicurezza dopo la direttiva NIS 2: un’analisi comparata del principio di accountability. Rivista Italiana di Diritto Pubblico Comunitario, 1, 101–125. De Noyette, E., Stähler, L., Margoni, T. (2025). Data Secrets: The Data Act’s New Trade Secrets Framework. In IIC - International Review of Intellectual Property and Competition Law. Available at: https://doi.org/10.1007/s40319-025-01601-9. Del-Real, C., De Busser, E., van den Berg, B. (2025). A systematic literature review of security and privacy by design principles, norms, and strategies for digital technologies. International Review of Law, Computers & Technology. 25-28. Available at: https://doi.org/10.1080/13600869.2025.2457227. Di Ruggiero, C. (2021). Dispositivi indossabili: rischi per la privacy. Che fine fanno le informazioni raccolte? [Intervista a Pasquale Stanzione]. Corriere Salute Di Somma, C. (2022). Ricerca scientifica, storica e per finalità statistiche. In E. Belisario, G. M. Riccio, G. Scorza (eds.), GDPR e Normativa privacy - commentario, 884-885. Ipsoa. ECHR (2024). Cracò v. Italy (30782/18), 13 June. Available at: https://hudoc.echr.coe.int/eng?i=001-234137. Eckardt, M., Kerber, W. (2024). Property rights theory, bundles of rights on IoT data, and the EU Data Act. In European Journal of Law and Economics, 1-31. Available at: https://doi.org/10.1007/s10657-023-09791-8. Edwards, L. (2018). Privacy, security and data protection in smart cities: A critical EU law perspective. European Journal of Law and Technology, 9(1), 28 ss. Available at: http://www.ejlt.org/index.php/ejlt/article/view/100. Eifert, M., Metzger, A., Schweitzer, H., Wagner, G. (2021), Taming the giants: The DMA/DSA package, in Common Market Law Review, 58(4). EIT Health (2024). Implementing the European Health Data Space Across Europe, Think Tank Report. Available at: https://eithealth.eu/think-tank-topic/implementing-the-european-health-data-space/. Elmi, G. T. (2023). Art. 110 - Ricerca medica, biomedica ed epidemiologica. In R. Sciaudone (ed.), Commentario al codice della privacy, 333-337. Pisa University Press. Esposito, M. S. (2024). Smart Tourism Destinations e GDPR: un’analisi sulla protezione dei dati nell’era del turismo digitale. Il Diritto dell’Informazione e dell’Informatica, 40(6), 890.
Pag. 97 Fabianek, C., Krenn, S., Loruenser, T., Siska, V. (2024). Secure Computation and Trustless Data Intermediaries in Data Spaces. Available at: https://doi.org/10.48550/arxiv.2410.16442. Faina, E., Didonè, C. (2025). NIS2-Ready? L’applicazione della direttiva NIS 2 nelle imprese italiane. Tempistiche e nodi da sciogliere. In S. Ungaro (ed.), NIS 2 e Cybersecurity, Rivista elettronica di Diritto, Economia, Management, 1, 109-121. Falletta, P., & Marsano, A. (2024). Intelligenza artificiale e protezione dei dati personali: il rapporto tra Regolamento europeo sull’intelligenza artificiale e GDPR. Rivista italiana di informatica e diritto, 6(1), 120. Falletti, E. (2025, Sovranità digitale, tutela della sicurezza nazionale e libertà di manifestazione del pensiero: i faticosi equilibri della sentenza TikTok v. Garland. In Diritto dell'Informazione e dell'Informatica (Il), 1, 81101. Fasan, M. (2024). Intelligenza artificiale e costituzionalismo contemporaneo, Collana deflla Facoltà di Giurisprudenze, Trento. Ferrarese, M. R. (2022), Poteri nuovi. Privati, penetranti, opachi, Il Mulino, Bologna. Ferri, F. (2022). Il bilanciamento dei diritti fondamentali nel mercato unico digitale, 29-41. Giappichelli. Filippi, C. (2024). L’impatto della digitalizzazione del SSN sulla protezione dei dati personali. In G. Cerrina Feroni (ed.), Le nuove frontiere della medicina, Il Mulino, 149. Finck, M., Pallas, F. (2020). They who must not be identified—distinguishing personal from non-personal data under the GDPR. International Data Privacy Law, 10(1), 13-35. Finocchiaro, G. (2022). La sovranità digitale. Diritto pubblico, 3, 809-827. Floridi, L (2020). The Fight for Digital Sovereignty: What It Is, and Why It Matters, Especially for the EU. Phil. & Tech., 369-378. Frank, C., von Imhoff, J. (2024). Data Access under the Data Act — A practical guidance to more clarity and compliance demonstrated in three practice-oriented scenarios. Computer Law Review International, 25(6), 165-171. Gabrielli, S., Krenn, S., Pellegrino, D., Pérez Baún, J. C., Pérez Berganza, P., Ramacher, S., Vandevelde, W. (2022). KRAKEN: A Secure, Trusted, Regulatory-Compliant, and Privacy-Preserving Data Sharing Platform. In E. Curry, S. Scerri, T. Tuikka (eds.), Data Spaces (pp. 235-257). Springer. Gaeta, M. C. (2018). La protezione dei dati personali nell’internet of things: l’esempio dei veicoli autonomi. Il Diritto dell’Informazione e dell’Informatica, 34(1), 147-179. Galgani, B. (2019). Giudizio penale, habeas data e garanzie fondamentali. In Archivio Penale, n. 1, 8-19. Gastaldi, L. (2021). PNRR: cosa prevede il Piano Nazionale di Ripresa e Resilienza. Osservatori.net. Gatelli, E. (2024). Dark pattern e personalizzazione manipolativa: fit check del panorama legislativo europeo. In MediaLaws Rivista di diritto dei media, Vol. 3, 280-289. Gaudio, G. (2022). Algorithmic management, sindacato e tutela giurisdizionale. In Diritto delle relazioni industriali, 35(1), 33. Geiregat, S. (2022). The Data Act: Start of a New Era for Data Ownership?. SSRN Electronic Journal. Available at: https://doi.org/10.2139/ssrn.4214704. Giustozzi, C. (2025). Direttiva NIS 2: genesi, attuazione, impatti. In S. Ungaro (ed.), NIS 2 e Cybersecurity, Rivista elettronica di Diritto, Economia, Management, n. 1, 80-97.
Pag. 98 Gobbato, S. (2020). Verso l’attuazione della direttiva (UE) 2019/1024 sul riutilizzo degli open data della PA: nuove opportunità per le imprese. In Medialaws Rivista di diritto dei media, n. 2, 247-261. Gorgerino, F. (2022). Legal Basis and Regulatory Applications of the Once-Only Principle: The Italian Case. In M. Wimmer, H. O. (eds.), The Once-Only Principle, Springer, 119. Available at: https://link.springer.com/content/pdf/10.1007/978-3-030-79851-2_6.pdf. Governo Italiano (2025). Digitalizzazione, innovazione, competitività, cultura e turismo. Available at: https://www.italiadomani.gov.it/it/il-piano/missioni-pnrr/digitalizzazione-e-innovazione.html. Graditi, G. (2023). Innovazione e PNRR, la sfida della transizione ecologica e digitale. In Energia, ambiente e innovazione, 2. Available at: https://www.eai.enea.it/archivio/innovatori-e-innovazione/innovazione-e-pnrrla-sfida-della-transizione-ecologica-e-digitale.html. Graux, H., Garstka, K., Murali, N., Cave, N., Botterman, M. (2025). Interplay between the AI Act and the EU digital legislative framework, publication for the Parliament's Committee on Industry, Research and Energy (ITRE), Policy Department for Transformation, Innovation and Health, European Parliament, Luxembourg. Guarda, P. (2019). I dati sanitari. In V. Cuffaro, R. D’Orazio, V. Ricciuto (eds.), I dati personali nel diritto europeo (pp. 591 ss.). Giappichelli. Guarda, P., Bincoletto, G. (2021). Diritto comparato della privacy e della protezione dei dati personali. Milano, Ledizioni. Guarda, P., Bincoletto, G. (2023). Diritto comparato della privacy e della protezione dei dati personali. Le edizioni, 291-291. Heidebrecht, S. (2024)), From market liberalism to public intervention: Digital sovereignty and changing European union digital single market governance, in JCMS: Journal of Common Market Studies, 62(1), 205223. Hofmann, H. (2025). New Regulatory Approaches under the EU’s Legislation on Digitalisation:Introduction to the Special Edition of the EJRR “Charting the Landscape of Automation of Regulatory Decision-Making”. In European Journal of Risk Regulation. Available at: https://doi.org/10.1017/err.2024.86. Hon, W. K., et al. (2016). Twenty Legal Considerations for Clouds of Thing (Legal Studies Research Paper No. 216/2016), 23 ss. Queen Mary University of London. https://noyb.eu/en/digital-omnibus-first-analysis-select-gdpr-and-eprivacy-proposals-commission Hulkó, G., Kálmán, J., & Lapsánszky, A. (2025). The politics of digital sovereignty and the European Union’s legislation: navigating crises. In Frontiers in Political Science. Available at: https://doi.org/10.3389/fpos.2025.1548562. IAB Europe (2017). Opinion of IAB Europe on the Proposal for a Regulation on Privacy and Electronic Communications (ePrivacy Regulation), 2. IAB Europe (2025). IAB Europe’s response to the EDPB public consultation on Guidelines 1/2025 on Pseudonymisation. Available at: https://iabeurope.eu/wp-content/uploads/IAB-Europes-response-to-theEDPB-public-consultation-on-draft-Guidelines-1_2025-on-Pseudonymisation-2.pdf. Information Commissioner’s Office (2025). Guidance for consumer Internet of Things products and services. Available at: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-dataprotection-regulation-gdpr/internet-of-things-iot-guidance/consumer-iot-products-and-services-guidance/. Irti, C. (2022). Personal Data, Non-personal Data, Anonymised Data, Pseudonymised Data, De-identified Data. In R. Senigaglia, C. Irti, A. Bernes (eds.), Privacy and Data Protection in Software Services, 49-59. Springer. Available at: https://doi.org/10.1007/978-981-16-3049-1.
Pag. 99 Jara, A., Martínez, I., Sanchez, J. (2024). CyberSecurity Resilience Act (CRA) in Practice for IoT Devices: Getting Ready for the NIS2. In 2024 IEEE Smart Cities Futures Summit (SCFC), 56-60. Available at: https://doi.org/10.1109/SCFC62024.2024.10698057. Junklewitz, H., et al. (2023). Guiding principles to address the cybersecurity requirement for high-risk AI systems, Luxembourg: Publications Office of the European Union. Kerber, W. (2022). Governance of IoT Data: Why the EU Data Act will not fulfill its objectives. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4080436. Kolain, M., Grafenauer, C., Ebers, M. (2022). Anonymity Assessment – A Universal Tool for Measuring Anonymity of Data Sets under the GDPR with a Special Focus on Smart Robotics. Rutgers Computer and Technology Law Journal, 48(2), 28-29. Available at: https://ssrn.com/abstract=3971139. Kuner, C., L.A. Bygrave, C. Docksey, C. (eds.) (2020). The EU General Data Protection Regulation (GDPR): a commentary. Oxford University Press, Oxford. Laus, F. (2021). Preparedness e once only nella digitalizzazione della PA: focus sul settore sanitario. In European Review of Digital Administration & Law - Erdal, Vol. 2, n. 2, 164-167. Legido-Quigley, C., Wewer Albrechtsen, N. J., Bæk Blond, M., et. al. (2025). Data sharing restrictions are hampering precision health in the European Union. In Nature Medicine, 31(2), 360-361. Available at: https://doi.org/10.1038/s41591-024-03437-1. Lele, A. (2018). Internet of Things (IoT). In Disruptive Technologies for the Militaries and Security. Smart Innovation, Systems and Technologies, 132, 187-195. Springer. Available at: https://doi.org/10.1007/978-98113-3384-2_11. Lepore, C. (2024). Self-sovereign identity: The revolution in digital identity. Opinio Juris in Comcotione, (Special Issue 2024), 59-71. Li, C., Palanisamy, B. (2018). Privacy in Internet of Things: from Principles to Technologies, 3-14. Available at: https://arxiv.org/abs/1808.08443. Lianos, I. (2024). Access to Health Data: Competition and Regulatory Alternatives-Three Dimensions of Fairness. in Centre for Law, Economics and Society. Research Paper Series: 5/2024. Available at: https://ssrn.com/abstract=4962599. Lodie, A., Lauradoux, C. (2024). Is it Personal data? Solving the gordian knot of anonymisation. Privacy Symposium 2024. Available at: https://hal.science/hal-04609238. Lombardi, A. (2023), Disciplina della tutela dei dati personali e regolazione dell’intelligenza artificiale: rapporti, analogie e differenze tra GDPR e AI Act, 2 EJPLT, 240-252. Lombardi, P. (2021). Sicurezza dei dati in ambito sanitario ed evoluzione tecnologica tra passato, presente e futuro. In Il diritto dell’economia, n. 3, 49-82. Longo, E. (2024). Audizione informale per il disegno di legge in materia di «Disposizioni in materia di rafforzamento della cybersicurezza nazionale e di reati informatici» (AC 1717): Camera dei Deputati, Commissioni riunite I e II - Roma, 28 marzo 2024. In Rivista Italiana Di Informatica E Diritto, 6(1), 65-70. Available at: https://doi.org/10.32091/RIID0136. Lopez, L. (2025). AI at the core of digital wallets: Revolutionizing instant payments through adaptive gateways. Available at: https://www.researchgate.net/publication/392979716_AI_at_the_Core_of_Digital_Wallets_Revolutionizing_ Instant_Payments_Through_Adaptive_Gateways.
Pag. 100 Lorè, F. (2025). Il trattamento dei dati personali nella pubblica amministrazione tra Open data, Big Data e privacy. In Ratio Iuris. Available at: https://ratioiuris.it/il-trattamento-dei-dati-personali-nella-pubblicaamministrazione-tra-open-data-big-data-e-privacy/. Ludvigsen, K., Nagaraja, S. (2022). The Opportunity to Regulate Cybersecurity in the EU (and the World): Recommendations for the Cybersecurity Resilience Act. Available at: https://doi.org/10.48550/arXiv.2205.13196. Lynskey, O. (2020). Chapter III Rights of the Data Subject (Articles 12–23). Article 20. Right to data portability”. In: The EU General Data Protection Regulation (GDPR): A Commentary. Oxford University Press, 2020, pp. 497–507. ISBN: 9780198826491, 499-500 Macrì, I. (2021). I dati delle Pubbliche Amministrazioni per la ripresa del Paese. In Azienditalia, n. 10, 16321635. Macrì, I. (2024). Strategie e modelli operativi per la sicurezza delle pubbliche amministrazioni al tempo del PNRR, In Rivista Italiana di Informatica e Diritto, 93-114. Madiega, T. (2020). Digital sovereignty for Europe. European Parliamentary Research Service, available at https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/651992/EPRS_BRI(2020)651992_EN.pdf. Magli, L. (2025). La sovranità sui dati: l’abbandono del criterio territoriale. In Punti di Vista sulla sovranità digitale, Osservatorio sullo Stato digitale. Available at: https://www.irpa.eu/punti-di-vista-sulla-sovranitadigitale-la-sovranita-sui-dati-labbandono-del-criterio-territoriale/. Mäkinen, J. (2015). Data quality, sensitive data and joint controllership as examples of grey areas in the existing data protection framework for the Internet of Things. Information & Communications Technology Law, 24(3), 241-272. Makowska, M. (2021). The EU’s Digital Decade: Goals and Challenges. In PISM. Available at: https://pism.pl/publications/The_EUs_Digital_Decade_Goals_and_Challenges. Mangiameli, S (2023). La sovranità digitale. Diritti fondamentali.it, 3, 279-297. Mantelero, A. (2024). The Fundamental Rights Impact Assessment (FRIA) in the AI Act: Roots, Legal Obligations and Key Elements for a Model Template. Comput. Law Secur. Rev., 54, 106020. Markopoulou, D., Papakonstantinou, V., & de Hert, P. (2019). The new EU cybersecurity framework: The NIS Directive, ENISA’s role and the General Data Protection Regulation. In Computer Law & Security Review, Vol. 35. Martella, A., Martella, C., & Longo, A. (2025). Designing Data Spaces: navigating the European initiatives along technical specifications. Paper presented at ITADATA2025: The 3rd Italian Conference on Big Data and Data Science. Matassa, M. (2025). Sicurezza cibernetica e nazionale nell’ordinamento multilivello: quale possibile convivenza?. Teoria E Critica Della Regolazione Sociale, 1(30). 73-85. Available at: https://doi.org/10.7413/197054760161. Michota, A., Polemi, N. (2022). A Supply Chain Service Cybersecurity Certification Scheme based on the Cybersecurity Act. In 2022 IEEE International Conference on Cyber Security and Resilience (CSR), 382-387. Available at: https://doi.org/10.1109/csr54599.2022.9850323. Moerel, E.M.L., Timmers, P. (2021). Reflections on Digital Sovereignty. EU Cyber Direct, Research in Focus series 2021, Available at SSRN: https://ssrn.com/abstract=3772777
Pag. 101 Morgan, A. (2025). Digital Transformation in the European Union: Opportunities, Challenges, and Policy Implications. In SSRN Electronic Journal. Available at: https://doi.org/10.2139/ssrn.5077868. Mursia, M., & Trovato, C.A. (2021). The commodification of our digital identity: limits on monetizing personal data in the European context. Medialaws, 2, 165–189. Nannipieri, L. (2024). Cybersicurezza e appalti. Interventi legislativi e prime criticità. In Rivista italiana di informatica e diritto, 6 (2), 71-79. Napieralski, A. (2024). Between the Data Act and the GDPR: Attributing Responsibility for Data Sharing. Yearbook of Antitrust and Regulatory Studies, 17(29), 127-145. https://doi.org/10.7172/16899024.YARS.2024.17.29.4 Napoli, A. G. V. (2025). Il Sistema Sanitario Nazionale e il panorama dell’eHealth in Italia: Un sistema multilivello di servizi sanitari e di salute digitale, 10-11. Available at: https://doi.org/10.22541/au.174733791.19227772/v1. NIS Cooperation Group, European Commission (2024). 2024 Report on the State of Cybersecurity in the Union, December 2024. Available at: https://www.enisa.europa.eu/publications/2024-report-on-the-state-ofthe-cybersecurity-in-the-union. Noto La Diega, G. (2023). Internet of Things and the Law. In Legal Strategies for Consumer-Centric Smart Technologies (pp. 16-17, 74-83 e 68-69). Routledge. Available at: https://ssrn.com/abstract=4617016. Novelli C. et al. (2023), Taking AI risks seriously: a new assessment model for the AI Act, in AI & Society, 1-5. Novelli C. et al. (2024), Generative AI in EU law: Liability, privacy, intellectual property, and cybersecurity, in Computer Law & Security Review, 55, 106066. Novelli, V. (2023). Trasformazione digitale per il raggiungimento della sostenibilità: Kuza case study. Politecnico di Torino, 38-41. Available at: https://webthesis.biblio.polito.it/27445/ Noyb (2025), Digital Omnibus - fisrt legal analysis, available at https://noyb.eu/en/digital-omnibus-first-legalanalysis. O’Connor, Y., et al. (2017). Privacy by Design: Informed Consent and Internet of Things for Smart Health, in Procedia Computer Science, 113, 653-658. Available at: https://doi.org/10.1016/j.procs.2017.08.329. Opara-Martins, J., Sahandi, R., Tian, F. (2016). Critical analysis of vendor lock-in and its impact on cloud computing migration: a business perspective. Journal of Cloud Computing, 5, 1-18. Available at: https://doi.org/10.1186/s13677-016-0054-z. Orefice, M. (2016). I big data. Regole e concorrenza. In Politica del diritto, 4, 713-717. Available at: https://doi.org/10.1437/85478. Orefice, M. (2024). Garante per la protezione dei dati personali (1/2024), in Osservatoriosullefonti.it. Available at: https://www.osservatoriosullefonti.it/archivi/archivio-rubriche/archivio-rubriche-2024/577agcm-agcom-anac-garante-privacy/4577-osf-1-2024-garante. Pacheco Huamani, A. M., Ziegler, S. (2019). GDPR Compliance Tools for Internet of Things Deployments. In S. Ziegler (ed.), Internet of Things Security and Data Protection, 123-124. Springer. Paseri, L. (2024). The ethical and legal challenges of data altruism for the scientific research sector. In AriasOliva, M. et al. (eds). The leading role of smart ethics in the digital world, 189-200.
Pag. 102 Pelino, E. (2024). Privacy e metadati di posta elettronica dei dipendenti – Le principali novità. In Ictsecuritymagazine. Available at: https://www.ictsecuritymagazine.com/articoli/privacy-e-metadati-di-postaelettronica-dei-dipendenti-le-principali-novita/. Perera, C., McCormick, C., Bandara, A. K., Price, B. A., Nuseibeh, B. (2016). Privacy-by-Design Framework for Assessing Internet of Things Applications and Platforms. Available at: https://arxiv.org/pdf/1609.04060. Perera, C., Zaslavsky, A., Christen, P., Georgakopoulos, D. (2014). Context-aware computing for the internet of things: A survey. IEEE Communications Surveys & Tutorials, 16(1), 414-454. doi:10.1109/SURV.2013.042313.00197. Available at: https://doi.org/10.1109/SURV.2013.042313.00197. Pierucci, F. (2025). Sovereignty in the Digital Era: Rethinking Territoriality and Governance in Cyberspace. Digit. Soc. 4, 27. https://doi-org.ezp.biblio.unitn.it/10.1007/s44206-025-00189-4. Pietrangelo, M. (2024a). Lo Stato insicuro. Sicurezza e sorveglianza nella cybersocietà. In Rivista Italiana di Informatica e Diritto, 14-22. Pietrangelo, M. (2024b). Per un modello nazionale di cybersicurezza cooperativa e resilienza collaborativa. Rivista italiana di informatica e diritto, 1. Pileggi, B. (2024). I minori su internet: un problema costituzionale. BIOLAW JOURNAL – Rivista di BioDiritto, Special Issue 1, 361–374. Pinto, G. P., Donta, P. K., Dustdar, S., Prazeres, C. (2024). A systematic review on privacy-aware IoT personal data stores. Sensors, 24(7), 2197, 2-3. Available at: https://doi.org/10.3390/s24072197 Piperata, G. (2022). PNRR e pubblica amministrazione: attuazione, riforme, cambiamenti. In Istituzioni del Federalismo. Pizzetti F. (2018). La protezione dei dati personali e la sfida dell’Intelligenza Artificiale, in ID. (a cura di), Intelligenza artificiale, protezione dei dati personali e regolazione, Torino, 5-189. Pohle, J., Thiel, T. (2020). Digital sovereignty. Internet Policy Review, 9(4). https://doi.org/10.14763/2020.4.1532 Poletti, D. (2022a). Gli intermediari dei dati. in EJPLT, 1, 48. Poletti, D. (2022b). IoT and Privacy. In R. Senigaglia, C. Irti, A. Bernes (eds.), Privacy and Data Protection in Software Services, 178. Springer. Quarta, A., & Smorto. G. (2024). Diritto privato dei mercati digitali. Le Monnier, Milano. Radan, S. (2023). NIS 2 Directive - Implications for System and Infrastructure Security. Interdisciplinary Description of Complex Systems, 21(3), 248–257. Rayes, A., Salam, S. (2019). Internet of Things. From Hype to Reality. The road to Digitization, 3-4. Springer. Resta, F. (2024). Cybersicurezza e protezione dati: un rapporto ambivalente. Rivista italiana di informatica e diritto, 2. Resta, G. (2022). Pubblico, privato e collettivo nel sistema europeo di governo dei dati. Rivista Trimestrale Di Diritto Pubblico (4), 971-996. Resta, G., Simonetti, F. (2022). La c.d. sovranità digitale e il progetto Gaia-X. Contratto e impresa Europa, 3, 479-489. Ricci, S. (2019). Il trattamento dei dati personali a fini di prevenzione, indagine, accertamento e perseguimento di reati o esecuzione di sanzioni penali. In V. Cuffaro, R. D’Orazio, & V. Ricciuto (eds.), I dati personali nel diritto europeo, Giappichelli, 1135–1146.
Pag. 103 Ricciuto, V. (2019). La patrimonializzazione dei dati personali. Contratto e mercato nella ricostruzione del fenomeno. In V. Cuffaro, R. D’Orazio, & V. Ricciuto (eds.), I dati personali nel diritto europeo, Giappichelli, 23–58. Riccobono, A. (2023). Nuove tecnologie e controlli difensivi tra diritto positivo e creazionismo giudiziario. Rivista Italiana di Diritto del Lavoro, 42(4), 507-529. Roberts, H. (2024). Digital sovereignty and artificial intelligence: a normative approach. Ethics Inf Technol 26, 70. https://doi-org.ezp.biblio.unitn.it/10.1007/s10676-024-09810-5 Robles-Carrillo, M. (2024). Digital identity: an approach to its nature, concept, and functionalities. International Journal of Law and Information Technology, 32, eaae019. Rocca, V. (2024). Digital Markets Act: il regolamento AGCM sull’esercizio dei poteri d’indagine. In Diritto Bancario. Available at: https://www.dirittobancario.it/art/digital-markets-act-il-regolamento-agcmsullesercizio-dei-poteri-dindagine/. Rodriguez, A. Q., Ziegler, S., Hemmens, C., et. al. (2019). End-User Engagement, Protection and Education. In S. Ziegler (ed.), Internet of Things Security and Data Protection, 183-184. Springer. Rossi Dal Pozzo, F. (2020). Qualche considerazione d’insieme sul mercato unico dei dati e la loro tutela nell’Unione europea. In Id. (eds.), Mercato Unico Digitale, dati personali e diritti fondamentali, Rivista Eurojus, 10. Rossi Dal Pozzo, F. (2020). Qualche considerazione d’insieme sul mercato unico dei dati e la loro tutela nell’Unione europea. In Id. (eds.), Mercato Unico Digitale, dati personali e diritti fondamentali, Rivista Eurojus, Fascicolo Speciale, 7–10. Roßnagel, A. (2024). Anonymisierung personenbezogener Daten und Nutzung anonymer Daten. Datenschutz Datensich, 48, 516-517. Available at: https://doi.org/10.1007/s11623-024-1968-0. Ruohonen, J., & Mickelsson, S. (2023). Reflections on the Data Governance Act. DISO, 4–6. Available at: https://doi.org/10.1007/s44206-023-00041-7. Ruohonen, J., Hjerppe, K., Kang, E. (2025). A Mapping Analysis of Requirements Between the CRA and the GDPR. Available at: https://arxiv.org/abs/2503.01816v1. Rupp, V., von Grafenstein, M. (2025). Clarifying "personal data" and the role of anonymisation in data protection law: Including and excluding data from the scope of the GDPR (more clearly) through refining the concept of data protection. In Gda journal, n. 4, 5. Ryan, M., Gürtler, P., Bogucki, A. (2024). Will the real data sovereign please stand up? An EU policy response to sovereignty in data spaces. International Journal of Law and Information Technology, 32(1), eaae006. Santaniello, M. (2021), La regolazione delle piattaforme e il principio della sovranità digitale, in Rivista di Digital Politics, 3, 579-600. Scherenberg, F. v., Hellmeier, M., Otto, B. (2024). Data Sovereignty in Information Systems. In Electronic Markets, 34(15), 15. Available at: https://doi.org/10.1007/s12525-024-00693-4. Schip, M. (2024). The Regulation of Supply Chain Cybersecurity in the NIS2 Directive in the Context of the Internet of Things. European Journal of Law and Technology, 15(1). Schmitz-Berndt, S. (2023). Defining the reporting threshold for a cybersecurity incident under the NIS Directive and the NIS 2 Directive. Journal of Cybersecurity, 9. Schwalm, S. (2023). The possible impacts of the eIDAS 2.0 digital identity approach in Germany and Europe. In Open Identity Summit 2023. Available at: https://doi.org/10.18420/OID2023_09.
Pag. 104 Schweihoff, J., Lipovetskaja, A., Jussen-Lengersdorf, I., Möller, F. (2024). Stuck in the middle with you: Conceptualizing data intermediaries and data intermediation services. In Electronic Markets, 34:48. Available at: https://doi.org/10.1007/s12525-024-00729-9. Sciacchitano, F. (2018). Disciplina e utilizzo degli Open Data in Italia. In Medialaws, n. 1, 281-314. Available at: https://www.medialaws.eu/wp-content/uploads/2019/05/20.-Sciacchitano.pdf. Segretariato generale della giustizia amministrativa (2024). News n. 19 del 15 febbraio 2024 a cura dell’Ufficio del Massimario. In Giustizia Amministrativa, 2024. Available at: https://www.giustiziaamministrativa.it/documents/20142/54775532/News+n.+19+del+15+febbraio+2024.pdf/190659d8-db79f6b9-2707-fa0be43e39ce?t=1707986716283. Senato della Repubblica - Servizi Studi. (2025). Disposizioni e delega al Governo in materia di intelligenza artificiale, 14-21. Senato della Repubblica (2025). Relazione sulle procedure di risoluzione delle controversie tra utenti e fornitori di servizi di media audiovisivi, nonché tra utenti e fornitori di piattaforme per la condivisione di video. Available at: https://www.senato.it/service/PDF/PDFServer/BGT/1461551.pdf. Senato della Repubblica, Servizio Studi (2024). Dossier, N. 257/2, Disposizioni in materia di rafforzamento della cybersicurezza nazionale e di reati informatici - A.S. n. 1143. Available at: http://www.senato.it/showdoc?leg=19&tipodoc=DOSSIER&id=1418663&idoggetto=0&part=dossier_dossier1&rif=0. Serini, F. (2024). Una proposta di studio dei concetti di cybersicurezza e cyberresilienza in senso giuridico tra ordinamento europeo e italiano. In Rivista italiana di informatica e diritto, 6 (2), 115-136. Sganga, C. (2022). Ventisei anni di direttiva database alla prova della nuova strategia europea per i dati: evoluzioni giurisprudenziali e percorsi di riforma. Il Diritto dell’informazione e dell’informatica, 3, 696. Shaffique, M. (2024). Cyber Resilience Act 2022: A silver bullet for cybersecurity of IoT devices or a shot in the dark?. In Comput. Law Secur. Rev., 54, 106009. Available at: https://doi.org/10.1016/j.clsr.2024.106009. Sicari, S., Rizzardi, A., Grieco, L., Coen-Porisini, A. (2015a). Sicurezza, privacy e fiducia nell’Internet delle cose: la strada da percorrere. Reti informatiche, 76, 146-164. Available at: https://doi.org/10.1016/j.comnet.2014.11.008. Sicari, S., Rizzardi, A., Grieco, L.A. and Coen-Porisini, A. (2015b) Security, Privacy and Trust in Internet of Things: The Road Ahead. Computer Networks, 76, 150-160. Simoncini, A. (2017). Sovranità e potere nell’era digitale. In T.E. Frosini, O. Pollicino, E. Apa, M. Bassini (eds). Diritti e libertà in Internet, Milano, 2017. Slapničar, S., Vidmar, T., Tsen, E. (2025). Process Theory of Supplier Cyber Risk Assessment. In Australas. J. Inf. Syst., 29. Available at: https://doi.org/10.3127/ajis.v29.5323. Smorto, G. (2023). Il ruolo della comparazione giuridica nella contesa per la sovranità digitale. DPCE Online, 57(1), 339-369. Sola, A. (2022). Economie dei dati, nuovi poteri ed autorità amministrative: il caso dell’Agenzia per la cybersicurezza nazionale. In Rivista di diritto dei media - Medialaws, 3, 386-404. Song, J., Wang, T., Yen, J., Chen, Y. (2024). Does cybersecurity maturity level assurance improve cybersecurity risk management in supply chains?. In Int. J. Account. Inf. Syst., 54, 100695. Available at: https://doi.org/10.1016/j.accinf.2024.100695.
Pag. 105 Sorrentino, E. & Spagnuolo, A.F. (2023). Le sfide degli enti locali: tra PNRR e gap digitali. In Federalismi, 163–166. Stirone, G. (2023). La nuova direttiva NIS2: l’evoluzione della normativa europea in materia di cybersecurity. Cybersecurity&Law Review, 1, 15–34. Strazza, G. (2022). I dati aperti in Italia: un focus sull’openness digitale dei Comuni. In Federalismi, n. 34, 152-179. Available at: https://www.federalismi.it/nv14/articolo-documento.cfm?Artid=48199. Streinz, T. (2021). The Evolution of European Data Law. In P. Craig & G. de Búrca (eds.), The Evolution of EU Law, 3rd ed., Oxford University Press, 902–936. Tafani, D. (2024). GDPR could protect us from the AI Act. That’s why it’s under attack. Bollettino telematico di filosofia politica. https://commentbfp.sp.unipi.it/gdpr-could-protect-us-from-the-ai-act-thats-why-itsunder-attack/, . Tawalbeh, L., Muheidat, F., Tawalbeh, M., Quwaider, M. (2020). IoT Privacy and Security: Challenges and Solutions. Applied Sciences, 10(12), 4-5. Available at: https://doi.org/10.3390/app10124102. Tebano, L. (2024). Ancora sulla gestione della posta elettronica nel contesto lavorativo: conservazione dei metadati e natura dello strumento. in Rivista Italiana di Diritto del Lavoro, 2, 294-297. Tebano, L. (2024). La gestione della posta elettronica nel contesto lavorativo: una questione ancora aperta, ma sospesa. In Rivista Italiana di Diritto del Lavoro, 1, 75-95. Thomaidou, A., & Limniotis, K. (2025). Navigating through human rights in AI: Exploring the interplay between GDPR and fundamental rights impact assessment. Journal of Cybersecurity and Privacy, 5(1), 7. https://doi.org/10.3390/jcp5010007 Thomaidou, A., Limniotis, K. (2025). Navigating Through Human Rights in AI: Exploring the Interplay Between GDPR and Fundamental Rights Impact Assessment. In J. Cybersecur. Priv., 5 (7). Available at: https://doi.org/10.3390/jcp5010007 Turco, V. (2019). Il trattamento dei dati personali nell’ambito del rapporto di lavoro. In V. Cuffaro, R. D’Orazio, & V. Ricciuto (eds.), I dati personali nel diritto europeo, Giappichelli, 522–544. van der Valk OMC, Ryan M. (2025). Data for the common good in the common European data space. In Data & Policy, e32, 2-3. Available at: https://doi.org/10.1017/dap.2025.5. Vandezande, N. (2024). Cybersecurity in the EU: How the NIS2-directive stacks up against its predecessor. In Comput. Law Secur. Rev., 52, 105890. Available at: https://doi.org/10.1016/j.clsr.2023.105890. Vardanian, R. (2025). La certificazione ai sensi del GDPR: uno strumento di accountability per lo sviluppo della data protection. Aracne, 10–22. Venanzoni, A. (2024). L’ordine costituzionale della cybersecurity. Forum di Quaderni Costituzionali, 4, 69– 75. Villani, S. (2025). The Cyber Solidarity Act: Framework and Perspectives for the New EU-Wide Cybersecurity Solidarity Mechanism Under the EU Legal System. European Journal of Risk Regulation, 1, 1–13. Vinuesa, R., Azizpour, H., Leite, I., Balaam, M., Dignum, V., Domisch, S., Felländer, A., Langhans, S. D., Tegmark, M., Fuso Nerini, F. (2020). The role of artificial intelligence in achieving the sustainable development goals. Nature Communications, 11(1), 233. Available at: https://doi.org/10.1038/s41467-01914108-y.