Privacy notices

Privacy notices have always been one of the most significant and debated obligations under data protection law.

In 1997, with the entry into force of Law No. 675/96, the innovative nature of this obligation clearly emerged: not merely a form of “general” transparency (typical of administrative acts), but an individualized communication addressed directly to the individual data subject.

The BNL case

The historic case of BNL in May 1997 was emblematic. It was the subject of the first formal decision of the Data Protection Authority, established only a few months earlier by Law No. 675/1996. The case arose from complaints by consumer associations (Adusbef, Movimento Difesa del Cittadino, Codacons), which reported that the privacy notice sent by the bank to its customers did not comply with the requirements of the new legislation.

With its decision of 28 May 1997 (press release, doc. web no. 49373), which also led to the adoption of a policy guidance measure identifying general criteria for credit institutions (doc. web no. 40425), the Authority—among other findings—held that the notice sent by the bank failed to distinguish between data collected directly from the customer and data collected from third parties.

The Authority therefore ordered the bank to completely redraft the privacy notice, deeming the one already sent invalid. This was a massive compliance operation, the cost of which at the time was estimated at around 5 billion lire to reprint and resend the notice to millions of customers. It marked a turning point in large organizations’ perception of compliance costs.

There is a common thread linking the burdensome compliance operation carried out by BNL in 1997 to the recent judgment of the Court of Justice concerning bodycams.

From 1997 to 2025: CJEU case C-422/24

If at the time the challenge was understanding that the privacy notice had to be an individualized communication, today the Court reaffirms the same principle of immediacy and direct contact.

The attempt by the Swedish company to rely on Article 14 of the GDPR—arguing that video recording constitutes an “indirect” or passive collection of data in order to avoid the contemporaneous information obligations under Article 13—clashes with the same logic established thirty years ago: when the source of the data is the natural person themselves, technological complexity cannot serve as an alibi to delay transparency or, worse, to turn data collection into a form of covert surveillance.

Privacy notices

From the outset, while maintaining the central role of transparency, the legal framework highlighted the existence of two distinct regimes:

  • Article 13, applicable where data are “collected from the data subject,” requires that the information notice be provided immediately, at the time of collection.
  • Article 14, applicable where data “have not been obtained from the data subject” (i.e., from third-party sources), allows the information to be provided within a reasonable period (no later than one month).

The distinction is crucial: applying the wrong article exposes the controller to sanctions for failure to provide information or for delayed transparency.

The difference hinges on the correct interpretation of the concept of collecting personal data “from the data subject,” as this determines which transparency regime applies and prevents the risk of covert surveillance.

Condividi

Post Recenti

Workshop – Come realizzare una FRIA

Beyond the Algorithm: Safeguarding the Human in the Age of Artificial Intelligence

Energy Telemarketing: Law 49/2026 Changes the Rules of the Game – 2