Tag Archives: healthcare

Updated texts of the reform of the EU Regulatory Framework for Medicinal Products published: the most significant overhaul of the regulatory framework in over two decades

The institutions of the European Union have published the updated texts of the new Directive and Regulation which together constitute the reform of the EU pharmaceutical regulatory framework.

The reform represents the most significant overhaul of the European Union’s pharmaceutical regulatory framework in over two decades and introduces substantial changes across a broad range of areas governing medicinal products, from development and marketing authorisation through to market access and security of supply.

The reform addresses, inter alia, the following areas:

  • Regulatory data and market protection — the reform reshapes the rules governing the protection of data submitted in support of a marketing authorisation and the subsequent period of regulatory market protection. These forms of regulatory protection are distinct from patent protection and play a key role in product protection and lifecycle management strategies, including by affecting the timing of market entry of generic and biosimilar medicinal products.
  • Marketing authorisation procedures and the role of the EMA — the new framework seeks to streamline and increase the efficiency of assessment and authorisation procedures, including by shortening the applicable scientific assessment timelines, while strengthening patient representation within the Committee for Medicinal Products for Human Use (CHMP).
  • Orphan medicinal products — the incentive framework applicable to medicinal products for rare conditions is revised, including the criteria for orphan designation, the applicable incentives, the regime governing breakthrough orphan medicinal products and the rules concerning the duration and extension of market exclusivity.
  • Paediatric medicinal products — the provisions governing the development and authorisation of medicinal products for the paediatric population are incorporated into the new legislative framework.
  • Generic and biosimilar medicinal products — the scope of the so-called Bolar exemption is clarified and further harmonised at EU level, specifying the activities preparatory to market entry that may be carried out without infringing applicable patent rights or supplementary protection certificates.
  • Antimicrobials — new incentive mechanisms are introduced to support the research and development of antimicrobials, including specific incentives for priority antimicrobials, as part of the broader EU response to antimicrobial resistance.
  • Availability of medicinal products and management of shortages — the new framework strengthens obligations relating to the monitoring, prevention and management of shortages and provides for EU-level mechanisms concerning medicinal products identified as critical.
  • Environmental considerations — greater emphasis is placed on the environmental risk assessment of medicinal products and on the adoption of appropriate measures to prevent or mitigate the identified environmental risks.

The Directive and the Regulation must now be formally adopted and subsequently published in the Official Journal of the European Union.

Both acts will enter into force on the twentieth day following their publication. As a general rule, the Regulation will apply 24 months after its entry into force, while Member States will be required to transpose and apply the Directive within the same 24-month period, subject in each case to the specific transitional arrangements and application dates laid down in the respective acts.

Corruption in Healthcare: What ANAC’s New Catalogue Means for Life Sciences Compliance

Corruption in Healthcare. Corruption is a concrete, evolving compliance risk for life
sciences companies, not just a hypothetical risk. In my experience sitting on supervisory boards under Legislative Decree 231/2001 on corporate criminal liability, the risks in this space have grown more sophisticated and harder to detect over the years.

The numbers explain why. Italy’s National Anti-Corruption Authority (ANAC) recently noted
that roughly 25% of all public procurement spending in Italy flows to the healthcare sector, and
that 8% of whistleblowing reports concern that same sector. Those two figures alone justify
heightened scrutiny.

ANAC has been paying attention accordingly. It has adopted the “Catalogue of Corruption Risks
and Prevention Measures in the Healthcare Sector”
(Catalogo dei rischi corruttivi e delle misure
di prevenzione nel settore sanitario), approved by ANAC’s Board with Resolution No. 318 of 29
July 2026. The Catalogue is meant to support National Health Service entities in drafting the “corruption risks and transparency” sub-section of their Integrated Activity and Organization Plan (PIAO), and it is a document worth reading well beyond that immediate audience.

The idea behind it is straightforward: healthcare is complex, the stakes are high, and the web of
relationships within the system calls for extra scrutiny, especially when public health is on the
line.

What the Catalogue Covers. The Catalogue maps new risks and new prevention measures across a wide range of areas: healthcare system regulation, biomedical research, pharmaceutical and medical-device marketing and promotion, public procurement, product distribution and storage, financial resource management, human resource management, and the actual delivery of healthcare services, including relations with accredited providers, oversight and inspection activity, and private practice and waiting lists.

For life sciences companies, the marketing and promotion chapter is the most direct point of
relevance: it is the clearest line connecting the Catalogue’s healthcare-system focus back to
industry conduct rather than treating it as a purely public-sector document.


Why This Matters. Healthcare is a perfect storm for integrity risk: high-stakes decisions, significant economic interests, constant public-private interaction, and pronounced information asymmetries. That mix can easily breed mismanagement, conflicts of interest, and outright corruption. ANAC’s own conclusion is that preventing corruption in healthcare takes a model built on transparency and impartiality, digitalization, independent controls, accountability, and the capacity to monitor the most exposed processes on an ongoing basis.

A Basis to Stress Test the Risk Map. Both public entities and private companies active in healthcare should take note of these risks and move to adopt measures that prevent them. For life sciences companies operating a Legislative Decree 231/2001 compliance model, the Catalogue is more than a general awareness exercise: it is a ready-made checklist against which to stress-test the existing risk map, refine the questions asked of management, and confirm that prevention measures keep pace with how these risks.

Italy’s New AI Law: A Boost for Healthcare Research?


Italy has recently enacted its own “Artificial Intelligence Act”, set to take effect on October 10, 2025.

You might be wondering: Did we really need another layer of AI regulation? That was our initial reaction, too. But a closer look reveals that the Italian AI Law introduces several interesting provisions, especially in the healthcare sector, that could facilitate research for both public and private entities. Here are some highlights:

1. Healthcare Data Processing as Based on Public Interest

The law explicitly recognizes that the processing of health-related personal data by:

  • Public or private non-profit entities,
  • Research hospitals (IRCCS),
  • Private entities collaborating with the above for healthcare research,

is of “substantial public interest.” This significantly expands the scope of Article 9(2)(g) of the GDPR, offering a clearer legal basis for processing sensitive data in research contexts.

2. Secondary Use of Data

The law introduces a simplified regime for the secondary use of personal data without direct identifiers. In particular:

  • No new consent required, as long as data subjects are informed (even via a website).
  • Automatic authorization unless blocked by the Data Protection Authority within 30 days of notification.

This provision applies only to the entities mentioned above so it is limited in scope, but in any case significantly strengthens the framework for nonprofit research projects.

3. Freedom to Anonymize, Pseudonymize and Synthesize

Under Article 8(4) of the AI Law, processing data for anonymization, pseudonymization, or synthesization is always permitted, provided the data subject is informed. This is a major step forward in enabling privacy-preserving AI research.

4. Guidelines and Governance

The law delegates the creation of technical guidelines to:

  • AGENAS – for anonymization and synthetic data generation.
  • Ministry of Health – for processing health data in research, including AI applications.

It also establishes a national AI platform at AGENAS, which will act as the data controller for personal data collected and generated within the platform.


Final Thoughts

While the GDPR aimed to support research, its implementation often created legal uncertainty and operational hurdles. Italy’s AI Law appears to address some of these gaps, offering a more pragmatic and enabling framework for healthcare research.

What if hospitals don’t pay?

Many of our clients encounter challenging dilemmas when public hospitals fail to reimburse the supplies they provide. Our seminar, held yesterday in our auditorium, was designed to discuss risks and potential solutions.

We regret if you were unable to attend, particularly as it was followed by an enjoyable aperitivo. However, we have included the slides presented by our attorneys, Fabrizio Sardella, Damiano Pallottino, and Francesco Clerici, who offered an analysis of the topic from a criminal, administrative, and civil law perspective.

A new decree (and new obligations) to tackle counterfeiting in the pharmaceutical sector

On January 28, 2025 the Italian government approved a legislative decree (“Decree”) implementing EU regulation 2016/161 through which the European Union has introduced specific measures aimed at fighting counterfeit medicines.

Packaging. Packaging of pharmaceutical products will have to include: (i) a two-dimensional bar code (i.e. “unique identifier”) able to guarantee the authenticity and the identification of the single individual pack of medicinal products; and (ii) an anti-tampering device.

Marketing authorization. Any new or existing marketing authorization (“MA”) requests must include information on the unique identifier and anti-tampering device when it has an impact on the primary packaging, the locking system or the label’s legibility. MA holders must update their MA to ensure full compliance with the new regulation.

Timeline.  The Decree should come into force on February 9, 2025, but its publication in the official Gazette is still awaited. However, the Decree has provided for a transition period between February 9, 2025, to February 8, 2027, where it will be possible to continue using the old “Bollino” system without incurring penalties.

Sanctions.  The manufacturer who does not apply and activate the unique identifier may be sanctioned with an administrative fine ranging from Euro 10,000 up to 60,000 for each batch. An MA holder may be sanctioned with a fine, ranging from Euro 10,000 up to 60,000 for each batch, for trading a medical product lacking an anti-tampering device. Manufacturers, wholesalers, and suppliers of medicines to the public who do not notify immediately to the competent authorities of any case of tampering or counterfeiting may be sanctioned with a fine starting from Euro 20,000 up to Euro 80,000 for each batch.

Happy GDPR-compliant Xmas and a prosperous new year!

Winter recess is about to start. While we’ll all be resting, GDPR will not!

While we will all be recharging our batteries to tackle the challenges for the upcoming 2025, GDPR will not go on vacation, and will thus never be out-of-office!

Check out the following tips that the Italian Data Protection Authority has recently issued in order to avoid threats to your privacy rights during the upcoming vacations:

  • Are you receiving plenty of virtual greetings and commercial offers? Be careful about them, even if apparently sent by a friend or parent: they may contain viruses, obscure links or may hide tentative of phishing. Not all presents may be welcome.
  • Have you taken good family pictures that you wish to share on your social network? Don’t forget to ask consent of all depicted individuals. Is your grandpa going to provide his consent as well?
  • Have you filmed your children’s Christmas pageant? Keep it for yourself! You’d need consent from all depicted individuals for publishing (including from their parents in case of minors).
  • Are you wishing to download any specific Christmas-related app on your smartphone? Choose them carefully, check their issuer and the reviews. You may inadvertently be downloading the Grinch’s one!
  • Are you going away for a trip? Don’t share too much information and pictures on your social media about your time off, your house and your vehicles, as it may attract thieves. Only Santa Claus shall be allowed to break in without your consent!
  • Are you connecting with your hotel’s or restaurant’s Wi-Fi? Ask the staff about its security: they may not be protected enough.
  • Have you bought any “smart” presents for your little nephews? Check whether they may collect any personal data from their users. In the affirmative, make sure that they will not harm them in any way possible.

Our own additional tips: rest, enjoy good food, spend time with your loved ones, and get ready for 2025! We wish you happy holidays and a healthy and successful new year.

Gitti and Partners Life Sciences Team

Don’t Miss our European Biotech Week 2024 Webinars

Hungry for content? The life sciences practice of Gitti and Partners has an interesting program of webinars/seminars in store for you within the framework of the EUROPEAN BIOTECH WEEK 2024:

See you soon!

Processing Health Data: the Most Recent Amendment to Italian Privacy Code

The Italian “Privacy Code” (Legislative Decree No. 196/2003), which governs data protection in Italy together with the European GDPR, has recently been amended.

Law No. 56/2024, further implementing the National Recovery and Resilience Plan, intervened on section 110 of the Privacy Code, which deals with the processing of health-related data for the purposes of medical, biomedical or epidemiological scientific research.

Section 110 provides that consent of the data subject for the processing of health-related data for the purpose of medical, biomedical or epidemiological scientific research is not required when:

  • the research is carried out on the basis of legal provisions or European Union law, when processing is necessary for scientific research or statistical purposes, provided that an impact assessment is carried out pursuant to sections 35 and 36 of the GDPR; or
  • informing the data subject is impossible or involves a disproportionate effort, or would render impossible or seriously jeopardise the attainment of the purposes of the research.

In such cases – before the latest amendment – the data controller had to:

1) take appropriate measures to protect the rights, freedoms and interests of the data subject;

2) obtain a favorable opinion of the competent ethics committee; and

3) consult the Italian Data Protection Authority prior to processing.

The obligation to consult the Italian Data Protection Authority has now been repealed. Thus, there is no need to apply for the Authority’s clearance prior to processing health-related data (in those cases where consent of the data subject is not required under section 110 of the Privacy Code). 

This amendment may have a significant impact especially on retrospective studies for which informing data subjects is particularly burdensome. The data controller will, in fact, be able to proceed without the Authority’s permission. Nonetheless, the data controller will still have to comply with specific guarantees and ethical rules issued by the Authority – as specified by the amended section 110.

On the one hand, the amended section 110 seems to favor accountability and to soften the procedural requirements in processing health data for research purposes, making the overall procedure quicker. When it comes to “secondary use” of health data, the accountability approach should be considered strong enough to protect data and favorably welcomed, as it moves in the same direction of the European Health Data Space – which intends to provide a reliable and efficient system for the re-use of health data in areas as research and innovation.

On the other hand, though, the Italian Data Protection Authority has already issued some interim guarantees, specifying that data controllers – when processing health data related to deceased or non-contact subjects – must carry out and publish an impact assessment, pursuant to section 35 of the GDPR, notifying it to the Authority. It remains to be seen how the amendment will be handled by the Authority in practice: the effects of the simplification provided by the new version of section 110 may be diminished if the guarantees set forth by the Authority generate equally articulate procedures.      

Processing of personal and health data through apps and online platforms aimed at connecting HCPs and patients: the new digest of the Italian DPA

On March 2024, the Italian Data Protection Authority (“Italian DPA”) has issued a new digest (“Digest”) relating to the processing of personal data, whether or not concerning health data pursuant to section 9 of the GDPR, carried out through the utilization of platforms, accessible through apps or web pages (“Platforms”), that aim to facilitate connection between healthcare professionals (“HCPs”) and patients.

The use of such Platforms poses high risks to the protection and security of patients’ personal data, and in particular health-related data, given that the latter are subject to an enhanced protection regime set forth by section 9 of the GDPR. 

The Digest seeks to summarize the applicable data protection rules that may be followed, and defines the roles of the parties, as well as the legal bases, applicable to (i) the processing of personal data of the users by Platform’s owners; (ii) the processing of HCP’s personal data by Platform’s owners; and (iii) the processing of health data of the patients by the Platform’s owner and by the HCPs.

Additional guidance is provided as to:

  • The necessity for the Platform’s owner to carry out (and periodically update) a data protection impact assessment (DPIA) pursuant to section 35 GDPR, since the use of Platforms determine a “high risk” processing of personal data, as such kind of treatment automatically meets the criteria issued by the European Data Protection Board for the identification of the list of data processing that may be deemed subject to the duty to perform a DPIA;
  • Which information notices should be provided, by who and to whom, as well as the contents that such information notices should have in each case, according to sections 13 and 14 GDPR;
  • The specific rules applicable to cross-border data transfers and data transfer to third countries.

Lastly, the Digest includes a list of the most common measures that are taken by the data controllers to ensure an appropriate level of technical and organizational measures to meet the GDPR requirements, such as encryption, verification of the qualification of the HCPs that seek to enroll within the Platform; strengthened authentication systems, monitoring systems aimed at preventing unauthorized access or loss of data.

The Digest should be very welcomed by the Platform’s owners, as it now gives a reliable and complete legal frame that may be followed in order to set up a Platform in a way which is compliant with the GDPR principles.

The Italian Government Fund for the Governance of Medical Devices

With Ministerial Decree dated December 29, 2023, the Italian Ministry of Health has established criteria and methods for feeding the fund dedicated to the governance of medical devices, the so-called “Fondo per il governo dei dispositivi medici” (Fund for medical devices governance, “Fund”).

Key Features

  • Annual payment obligation.  Companies manufacturing or distributing medical devices, large medical equipment and in vitro diagnostic medical devices must pay a sum equal to 0.75% of the company’s previous year turnover from the sale of such devices to the National Health Service, net of VAT.
  • Annual Declaration Requirement.  Companies must submit an annual statement to the Ministry of Health regarding:
    • The estimated amount of 0.75% of the above-mentioned turnover.
    • The company’s previous year turnover to the National Health Service, net of VAT;
  • Use of the Fund. The Fund will be used for various activities related to Health Technology Assessment and governance of medical devices (including the management of the National Price Observatory, the vigilance system and the market surveillance system).
  • Deadlines and next steps. The first deadline for compliance with the fund regulations is set for December 31, 2024.

Companies are currently assessing whether the Fund can be challenged in court with arguments that may be similar to those raised in the so called “payback” litigation, which will see its day in Court (namely, the Italian Constitutional Court) on May 22, 2024.