Tag Archives: technology

AI Act Transparency Obligations Are Now in Force

Dear Readers,

I hope you had a great summer! While you were travelling, hiking, swimming or simply resting, article 50 of the AI Act has entered into force, which means that a number of transparency obligations are applicable.

1. YOUR ROLE. First things first: are you an AI provider or an AI deployer?

  • A provider of AI systems is a natural or legal person that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark; while
  • A deployer is a natural or legal person using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

Providers and deployers have different obligations, which are summarized below.

2. PROVIDER’S OBLIGATIONS.

  • Providers must ensure that AI systems intended to interact directly with natural persons are designed so that those persons are informed they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person.
  • Providers of AI systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable, as far as technically feasible.

Providers have started to comply and use different technical solutions. Anthropic, for example, is using a watermarking technique, while Open AI and Google are using different strategies. No single marking technique meets Article 50(2) requirements of effectiveness, interoperability, robustness and reliability, and only an appropriate combination of techniques and detection mechanisms can satisfy them. Some point to a clear “Brussels effect” where the AI Act ends up applying beyond its scope.

3. DEPLOYER’S OBLIGATIONS.

  • Deployers of emotion recognition or biometric categorization systems must inform the natural persons exposed to the system of its operation and must process personal data in accordance with the GDPR and any other applicable data protection laws.
  • Deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or analogous works, the obligation is limited to appropriate disclosure that does not hamper the display or enjoyment of the work.
  • Deployers of AI systems that generate or manipulate text published to inform the public on matters of public interest must disclose the artificial nature of the content, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

All information must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure.

The AI Office is tasked with encouraging codes of practice at Union level to facilitate the effective implementation of obligations regarding the detection and labelling of artificially generated or manipulated content. In fact, the voluntary Code of Practice on Transparency of AI-generated Content has already been signed by 190+ organizations and has been found by the EU Commission and the AI Office as an effective tool to aid compliance with article 50 of the AI Act.

In a world where AI systems have started to go rogue, perhaps the AI Act – with all its constraints to AI technology – can offer reassurance that the EU continues to pursue a human-centric, trustworthy AI.

Text and Data Mining, Copyright and M&A: Legal Risks in Acquiring AI Companies

Every time an AI model generates a text, an image or a melody, a powerful process has taken place behind the scenes: Text and Data Mining (“TDM“), any automated technique aimed at analysing large quantities of texts, sounds, images, data or metadata in digital format to generate information. Billions of web pages, photographs and musical works are ingested by algorithms, often without the authors’ knowledge. As AI companies become attractive acquisition targets, understanding the copyright risks in their training practices is essential for M&A practitioners. This article examines the Italian legal framework governing AI and copyright, from the TDM exceptions under the copyright act to the EU AI Act, and their M&A implications.

1. Regulatory Framework. Directive (EU) 2019/790 on copyright in the Digital Single Market Directive (“DSM“) was transposed into Italian law by Legislative Decree No. 177/2021, which amended Law No. 633/1941 (the “Italian Copyright Law“) by introducing two key TDM provisions: Articles 70-ter and 70-quater.

2. The TDM Exceptions. The two TDM provisions transposed into the Italian Copyright Act establish distinct regimes, each with its own scope, conditions and limitations. The distinction is critical in M&A, as it determines whether a target’s data acquisition practices are lawful and, consequently, the transaction’s risk profile:

2.1. Art. 70-ter LDA: TDM for Scientific Research (Art. 3 DSM). Art. 70-ter introduces a mandatory, non-derogable exception allowing research organisations and cultural heritage institutions to reproduce works or materials to which they have lawful access, for text and data extraction for scientific research. Copies must be stored securely and retained only for research purposes, including verification of results. Rightholders may apply proportionate security measures. Conflicting contractual terms are null and void.

2.2. Art. 70-quater LDA: TDM for Any Purpose (Art. 4 DSM). Art. 70-quater permits reproductions and extractions from works or materials to which the user has lawful access, for TDM purposes without limitation as to identity or purpose, including commercial use. However, TDM is only permitted where the use has not been expressly reserved by the relevant rightholders. Copies may only be retained as long as necessary for the TDM process, with security levels no lower than those under Art. 70-ter. This opt-out mechanism raises several concerns: (i) whether an opt-out can be enforced retroactively against prior scraping; (ii) whether rightholders may reserve only certain works or must cover their entire online corpus; (iii) the technical reliability of machine-readable reservations (robots.txt, metadata); and (iv) the unclear regime for works from physical archives or offline databases. Each open question may give rise to contingent liabilities for M&A investors.

These two TDM exceptions are particularly relevant to generative AI, as training such models typically involves mass reproduction of protected works. Art. 70-ter applies to research organisations for scientific purposes, with no opt-out. For commercial entities, Art. 70-quater applies only if rightholders have not expressly reserved their content. In M&A, identifying the applicable regime is a key question in IP due diligence.

3. AI-Generated Output and Copyright. Neither the DSM Directive nor its Italian transposition addresses the copyrightability of AI-generated output. Art. 1 of the Italian Copyright Act requires human creativity for protection; the prevailing view is that purely AI-generated works are not eligible for copyright, while the status of “AI-assisted works” remains debated. This uncertainty bears directly on M&A valuation: if a target’s core IP consists largely of AI-generated content, the enforceability and value of those assets may be materially lower than assumed.

4. Compliance with the EU AI Act. The EU AI Act (Regulation (EU) 2024/1689) requires providers of general-purpose AI models to publish a summary of training data used, including categories and sources, with particular regard to TDM compliance and any opt-out by rightholders (Art. 53(1)(d)). For M&A investors, non-compliance may expose the target to sanctions, while the required disclosures may reveal underlying IP vulnerabilities.

5. Implications on M&A Deals. The foregoing reflections raise a few red flags when a target develops or deploys AI systems. The lawfulness of the target’s data acquisition and training practices (including compliance with Articles 70-ter and 70-quater of the Italian Copyright Law, opt-out reservations, and the origin of training datasets. Equally, M&A investors should assess the enforceability of IP rights over AI-generated or AI-assisted output, given that purely AI-generated works are unlikely to qualify for copyright under the Italian Copyright Law. Overvaluation of such assets may result in a misalignment between the purchase price and the rights actually acquired. Representations, warranties and indemnities covering TDM compliance, IP ownership and AI Act obligations certainly help, but a rigorous IP due diligence remains essential to identifying risks.

Italy Moves to Regulate AI: New Rules on Civil and Criminal Liability

On 10 June 2026, the Italian Council of Ministers approved, in preliminary examination, two draft legislative decrees implementing Law No. 132/2025 and aligning the national framework with Regulation (EU) 2024/1689 (“AI Act”).

This is not the first legislative step taken by the Italian Government on AI. The two decrees follow Bill No. 1146/2024, which later became Law No. 132/2025 and set out the general national framework in the field of artificial intelligence.

The texts are not final yet: they will still be reviewed by the parliamentary committees, the State-Regions Conference and the competent authorities, including the Italian Data Protection Authority. Still, the direction is already clear. For businesses developing, placing on the market or deploying high-risk AI systems, the most relevant developments concern civil, criminal and corporate liability.

Two Decrees, in Brief

The first decree focuses on AI literacy, education and training, as well as on the national competent authorities. It regulates AI in school, university, professional and public administration training, and confirms the prohibition on purely automated decisions concerning hiring, dismissal, changes to the employment relationship and disciplinary sanctions. On governance, the framework is built around AgID, as notifying authority, and ACN, as market surveillance authority and single point of contact with the EU.

The second decree deals with more sensitive uses of AI, including policing, protection of injured parties and liability for high-risk systems. Its approach is to allow AI as a supporting tool, but within a perimeter based on human control, proportionality, traceability and protection of fundamental rights. This post focuses on its civil, criminal and corporate liability provisions.

Civil Liability: Levelling the Playing Field

The second decree strengthens the position of individuals harmed by an AI system. The main issue is informational asymmetry: a claimant will often be unable to reconstruct how the system worked or to prove the causal link between the AI output and the damage suffered.

The proposed response is mainly procedural. It includes access to the system’s technical documentation, a presumption of causation, an alternative venue close to the injured individual’s residence, and the possibility of acting directly against the insurer. Rather than introducing a broad new set of substantive obligations for businesses, the decree appears aimed at making compensation claims more effective, while leaving existing rules on data protection and product liability in place.

Criminal Liability: The New Article 437-bis

On the criminal side, the decree introduces a new Article 437-bis of the Criminal Code, concerning the failure to adopt security measures in high-risk AI systems and their unlawful alteration.

This offence does not punish the use of artificial intelligence as such. It targets human and organisational conduct that makes high-risk AI systems concretely dangerous. In particular, it covers omissions or alterations which, in the design, placing into service or use of such systems, create a concrete danger to primary interests such as life, public safety or State security.

Criminal liability is limited to the most serious cases. Not every technical error or malfunction would be criminally relevant: the conduct must be capable of generating a concrete danger. For the negligent form of the offence, gross negligence is required, which suggests an attempt to avoid over-criminalising technological innovation.

Corporate Liability Under Legislative Decree 231/2001

A further important point concerns the potential extension of liability to entities under Legislative Decree No. 231/2001. The available materials indicate that the new Article 437-bis may also have consequences under the 231 framework, so that liability would not fall only on individuals, but could also involve the organisation benefiting from the development, placing into service or use of a high-risk AI system.

This point should be verified against the final text, particularly as to whether and how Article 437-bis will be included among the predicate offences under Legislative Decree No. 231/2001. In any event, for companies operating with high-risk AI systems, the direction is significant: existing 231 models and internal protocols may need to be reviewed in light of AI-related risks.

In practice, this would mean assessing whether the organisation has adequate safeguards around system security, traceability, human oversight, risk management, incident escalation and controls across the AI lifecycle. As in other areas of 231 liability, the adequacy and effective implementation of the compliance model would be central to mitigating the entity’s exposure.

Why It Matters

The texts may still change before final approval, but the signal for companies is already clear. Businesses should start mapping where high-risk AI systems are developed or deployed, assessing whether existing compliance frameworks adequately cover AI-related risks, and strengthening documentation, oversight and risk management mechanisms.

These steps will be important not only to mitigate potential criminal and corporate liability, but also to respond effectively to civil claims arising from the use of AI systems.

Contributed by Francesco Stagno D’Alcontres

Disclosure Day: Drones in the EU – What’s Flying Above Us (and No, It’s Not Aliens)


With the recent wave of U.S. government declassifications of UFO files – officially referred to as UAPs (Unidentified Aerial Phenomena) – and a new Spielberg film tapping into our fascination with the unknown, the skies have never felt more mysterious. Yet, before looking up in wonder, a more grounded reality emerges: most of what we see overhead is far more explainable. Drones, for instance, are quietly reshaping our airspace – and the European Union has already put in place a comprehensive regulatory framework to govern them.

The Regulatory Framework: Two Regulations, One Clear Sky

Since 2019, two EU regulations have governed the production and operation of Unmanned Aircraft Systems (UAS) across all Member States, ending years of fragmented national rules.

Regulation (EU) 2019/945 – Manufacturing and Market Requirements

This regulation sets out the technical requirements for drones placed on the EU market, introducing a classification system based on maximum take-off mass (MTOM) and operational characteristics:

  1. Class C0 – under 250g; minimal requirements, no Remote ID required
  2. Class C1 – 250g to 900g; Remote ID mandatory, restrictions near populated areas
  3. Class C2 – 900g to 4kg; Remote ID, low-speed mode, geofencing capability required
  4. Class C3 / C4 – up to 25kg; reserved for “Specific” category operations
  5. Class C5 / C6 – designed for advanced operations, including drone swarms and controlled BVLOS flights

All drones must carry CE marking confirming conformity with their class requirements. From Class C1 upwards, every drone must be equipped with Remote ID, i.e. a real-time digital identification system that continuously broadcasts the drone’s unique identifier, position, altitude, speed and the operator’s location. Think of it as a number plate for the sky.

Manufacturers not established in the EU must designate an authorised representative within the Union to ensure compliance.

Regulation (EU) 2019/947 – Operational Rules for Pilots and Operators

This regulation, developed by EASA (the European Union Aviation Safety Agency), governs how drones are actually flown, organising all operations into three categories based on risk level:

Open Category – low-risk flights requiring no prior authorisation. Operations must remain within visual line of sight (VLOS), below 120 metres, and away from gatherings of people. This category is further divided into three subcategories (A1, A2, A3) depending on the drone’s class and its proximity to uninvolved persons. Subcategory A2, for instance, requires pilots to pass a theoretical examination before operating a Class C2 drone near people.

Specific Category – medium-risk operations that generally require either an authorisation from the national competent authority or compliance with a pre-defined Standard Scenario (STS). Authorisations are based on the SORA methodology (Specific Operations Risk Assessment), which helps assess the level of risk involved and determine what safety measures are needed. Two Standard Scenarios are currently available – STS-01 (visual line of sight flights in populated areas) and STS-02 (beyond visual line of sight flights in unpopulated areas). Operators meeting all the conditions of an STS can fly under a simple declaration, without needing individual authorisation.

This category is also where BVLOS operations (Beyond Visual Line of Sight) come in – flights where the drone operates beyond the pilot’s direct visual contact. BVLOS is key to unlocking use cases like long-range infrastructure inspection, medical delivery, and large-scale surveying. These flights typically require either a SORA-based authorisation or compliance with STS-02, and the drone must be equipped with detect-and-avoid capabilities to ensure safe separation from other aircraft.

Certified Category – high-risk operations equivalent in complexity to conventional aviation. Requires full EASA certification of the drone, a formal operator approval, and a licensed pilot. Reserved for operations where a system failure could have catastrophic consequences.

Cross-Cutting Obligations

Regardless of category, all operators must:

  1. Register with their national competent authority (mandatory for drones over 250g or equipped with a camera)
  2. Respect UAS geographical zones defined by each Member State, covering restricted, prohibited, and conditional airspace
  3. Maintain flight logs for all Specific and Certified category operations
  4. Ensure adequate pilot training appropriate to the subcategory or category of operation

The U-Space: Managing the New Low-Altitude Frontier

The two regulations sit within a broader framework that includes the U-Space system, established by Regulation (EU) 2021/664. U-Space is the EU’s digital infrastructure for managing low-altitude air traffic in real time – essentially an air traffic management system for drones. It enables flight authorisation, conflict detection, real-time traffic monitoring and information sharing between operators, authorities, and conventional airspace managers.

U-Space is the critical enabler for large-scale BVLOS operations, and its progressive rollout across Member States is expected to unlock entirely new categories of drone deployment in the coming years.

Why It Matters

Together, these regulations created a single European drone market: harmonised, scalable, and built around safety. For anyone operating drones professionally in Europe, compliance is not optional – it is the foundation of lawful and sustainable operations.

So while the debate on UAPs continues across the Atlantic, Europe has already answered its own version of the question: what’s flying up there, and who’s in charge of it?

The answer, refreshingly, involves neither little green men nor government cover-ups – just well-drafted regulations and a lot of paperwork.

The future of GDPR? Focus on Automated Decisions

The Digital Omnibus Proposal.  The so called “Digital Omnibus” regulation proposal promises to lighten the burden of compliance with data protection legislation. Its aim is “to ensure that the rules continue to be fit for supporting innovation and growth”. Europe is not giving up on privacy, but it is willing to simplify it.

EDPB and EDPS Chime In.  The proposal, published in November 2025, has recently been the subject matter of a joint opinion by the European Data Protection Board and the European Data Protection Supervisor. While these two bodies are apparently in favor of facilitating GDPR compliance and strengthening consistency in its application, they express significant concerns regarding the impact of the changes on the fundamental rights and freedoms of individuals. They also fear that the proposal will create additional legal uncertainties.

The GDPR of the Future.  Gitti and Partners is embarking in a series of blog posts to explain what the GDPR may look like if the Digital Omnibus proposal becomes law. Today we focus on changes to the provision on automated decisions.

Automated Decisions: from Right to Prohibition.  Article 22 of the current GDPR regulates automated individual decision-making. The current language of the provision frames the rule as a “right”: a data subject is entitled not to be subject to a decision based solely on automated processing, unless certain conditions apply. The new proposal, instead, shapes a similar rule as a prohibition.

Conditions for Automated Decisions.  The new proposal reads (new language highlighted in yellow): “1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision: (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means. […]”

While – as before – the automated decision is legitimate if necessary to enter into or perform a contract with the data subject, the novelty is that the necessity of the automated decision can be assessed “regardless of whether the decision could be taken otherwise than by solely automated means”. Therefore:

  • An automated decision that does not produce any legal effects is fine.
  • An automated decision producing legal effects may be based on automated processing only if the decision is necessary to enter into or perform a contract with the data subject.
  • No automated decision is allowed unless it is necessary to enter or perform a contract with the data subject.
  • In order to add certainty to the interpretation of the requirement of “necessity”, the proposal clarifies that the decision may be regarded as necessary also if the decision could be made by a human. In the words of the EDPB/EDPS opinion, “the requirement of necessity does not mean that the mere fact that a decision could theoretically also be taken by a human should prevent the controller from taking the decision by solely automated means”.
  • In short, “The fact that the decision could also be taken by a human does not prevent the controller from taking the decision by solely automated processing” (recital (38) of the Digital Omnibus proposal).

Bottom line: the data controller may choose a human decision process or an automated decision process so long as they are necessary to enter into or perform a contract with the data subject.

In conclusion, as shown in the “AI First” policy, the EU is now worried that AI may not be fully exploited. The above changes are supposed to encourage automated decisions even if such decisions could be taken by a human being.

Stay tuned for more angles of the Digital Omnibus.

A More Volatile World: The Digital Omnibus

On November 19, 2025, the European Commission unveiled a landmark proposal: the Digital Omnibus Regulation. This initiative is not just another legislative tweak – it signals a philosophical shift in how Europe approaches digital regulation. In a world increasingly defined by volatility, complexity, and rapid technological change, the Commission seems to be saying: “We’ve heard you – let’s regulate, but let’s make it easier to comply.”

Why Now? The Context Behind the ‘Digital Omnibus’

The proposal comes against a backdrop of mounting pressure on Europe’s competitiveness. In his now-famous “Please, do something” speech to the European Parliament, Mario Draghi urged EU institutions to act decisively to restore Europe’s ability to innovate and compete globally. Could the Digital Omnibus be seen as a response to this heartfelt appeal?

For years, the EU has been a global pioneer in digital regulation – think GDPR, AI Act, Data Act, Digital Services Act (DSA), Digital Markets Act (DMA), NIS2, and more. But this success has come at a cost: fragmentation, complexity, and heavy compliance burdens. Businesses have struggled to navigate overlapping obligations. The Digital Omnibus is designed to change that. In the “explanatory memorandum” to the Digital Omnibus, the Commission emblematically acknowledges, for instance, that “some entities, especially smaller companies and associations with a low number of non-intensive, often low-risk data processing operations, expressed concerns regarding the application of some obligations of the GDPR”.

The ‘Digital Omnibus’ Proposal

The proposal introduces technical amendments and structural simplifications across a wide range of legislation, including:

  • General Data Protection Regulation (GDPR)
  • AI Act
  • Data Act
  • ePrivacy Directive
  • NIS2 Directive
  • Data Governance Act
  • Free Flow of Non-Personal Data Regulation
  • Platform-to-Business (P2B) Regulation (to be repealed

Key Highlights

  • GDPR Simplification:
    • Clarifies the definition of personal data
    • Supports controllers with respect to the criteria and means to determine whether data resulting from pseudonymization does not constitute personal data
    • Introduces flexibility for AI development: processing personal data for AI training under “legitimate interest,” with safeguards.
    • Modernizes cookie consent rules – centralized browser settings to end “cookie fatigue.”
  • AI Act Adjustments:
    • Expands regulatory sandboxes and simplifies compliance for SMEs and mid-cap companies.
    • Clarifies the interplay between the AI Act and other EU legislation
    • Introduces an obligation on the Commission and Member States to foster AI literacy
  • Incident Reporting:
    • Creates a single-entry point for incident notifications under GDPR, NIS2, DORA, and CER – ending duplicative reporting.

A New Philosophy?

There are strong indications that the “Digital Omnibus” is more than a mere technical adjustment and may represents a strategic shift in EU “digital law”. The proposals will now proceed to the European Parliament and the Council for deliberation. It remains to be seen whether words will be turned into action.

Italy’s New AI Law: A Boost for Healthcare Research?


Italy has recently enacted its own “Artificial Intelligence Act”, set to take effect on October 10, 2025.

You might be wondering: Did we really need another layer of AI regulation? That was our initial reaction, too. But a closer look reveals that the Italian AI Law introduces several interesting provisions, especially in the healthcare sector, that could facilitate research for both public and private entities. Here are some highlights:

1. Healthcare Data Processing as Based on Public Interest

The law explicitly recognizes that the processing of health-related personal data by:

  • Public or private non-profit entities,
  • Research hospitals (IRCCS),
  • Private entities collaborating with the above for healthcare research,

is of “substantial public interest.” This significantly expands the scope of Article 9(2)(g) of the GDPR, offering a clearer legal basis for processing sensitive data in research contexts.

2. Secondary Use of Data

The law introduces a simplified regime for the secondary use of personal data without direct identifiers. In particular:

  • No new consent required, as long as data subjects are informed (even via a website).
  • Automatic authorization unless blocked by the Data Protection Authority within 30 days of notification.

This provision applies only to the entities mentioned above so it is limited in scope, but in any case significantly strengthens the framework for nonprofit research projects.

3. Freedom to Anonymize, Pseudonymize and Synthesize

Under Article 8(4) of the AI Law, processing data for anonymization, pseudonymization, or synthesization is always permitted, provided the data subject is informed. This is a major step forward in enabling privacy-preserving AI research.

4. Guidelines and Governance

The law delegates the creation of technical guidelines to:

  • AGENAS – for anonymization and synthetic data generation.
  • Ministry of Health – for processing health data in research, including AI applications.

It also establishes a national AI platform at AGENAS, which will act as the data controller for personal data collected and generated within the platform.


Final Thoughts

While the GDPR aimed to support research, its implementation often created legal uncertainty and operational hurdles. Italy’s AI Law appears to address some of these gaps, offering a more pragmatic and enabling framework for healthcare research.

Your Face at the Airport: the EDPB Weighs in on Face Boarding

As you wander around an airport waiting to travel for the summer, you may notice that your image is captured by various devices. This process, known as facial recognition or “face boarding”, has recently been the subject matter of an opinion by the EDPB https://www.edpb.europa.eu/edpb_it, which issued an opinion (no. 11/2024, https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-112024-use-facial-recognition-streamline_en, pursuant to article 64 of the GDPR) – on the processing of data obtained in airports using facial recognition to streamline airport passenger’s flow.

The EDPB assessed the compatibility of such data processing with:

  • article 5(1)(e) and (f) of the GDPR on storage limitation and integrity and confidentiality;
  • article 25 of the GDPR on privacy by default and privacy by design;
  • article 32 of the GDPR on security of processing.

The opinion takes into account four different scenarios:

  • Scenario 1: Storage of an enrolled biometric template – which is a set of biometric features stored in a database for future authentication purposes – only in the hands of the passenger.

Enrolment consists in recording – by each passenger who has consented to such processing – the biometric template and ID necessary for the processing, on the passenger’s device. Neither the passengers’ ID, nor their biometric data are retained by the airport operator after the enrolment process.

The passenger is authenticated when going through specific checkpoints at the airport (equipped with QR scanners and cameras), through the use of a QR code produced by the passenger’s device, where the biometric template is stored.

The EDPB opinion concludes that such processing could be considered in principle compatible with article 5(1)(f), 25 and 32 of the GDPR (nonetheless, appropriate safeguards must be implemented, including an impact assessment).

  • Scenario 2: centralized storage of an enrolled biometric template in an encrypted form, stored in a database within the airport premises and with a key solely in the passenger’s hands.

The enrolment is controlled by the airport operator and consists in generating ID and biometric data that is encrypted with a key/ secret. The database is stored within the airport premises, under the control of the airport operator. Individual-specific encryption keys/ secrets are stored only on the individual’s device

Passengers are authenticated when going through specific checkpoints, equipped with a control pod, a QR scanner and a camera. The passenger’s data are sent to the database to request the encrypted template, which is then checked locally on the pod and/or user’s device.

The opinion concludes that such processing could be considered in principle compatible with article 5(1)(e)(f), 25 and 32 of the GDPR subject to appropriate safeguards. In fact, the intrusiveness from such processing through a centralized system can be counterbalanced by the involvement of the passengers, who hold control of the key to their encrypted data.

  • Scenario 3: centralized storage of an enrolled biometric template in a database within the airport, under the control of the airport operator and Scenario 4: centralized storage of an enrolled biometric template in a cloud, under the control of the airline company or its cloud service provider.

The enrolment is done either in a remote mode or at airport terminals.

At the airport passengers go through dedicated control pods equipped with a camera. Biometric data is sent to the centralized database or to the cloud server – where the matching of the data is processed. The biometric matching is only performed when the passengers present themselves at pre-defined control points at the airport, but the data processing itself is done in the cloud or in centralized databases.

The EDPB considers that the use of biometric data for identification purposes in large central databases, as in Scenarios 3 and 4, interfere with the fundamental rights of data subjects and could possibly entail serious consequences. As such, Scenarios 3 and 4 are not compatible with article 25 of the GDPR because they imply the search of passengers within a central database, by processing each biometric sample captured. Also, taking into account the state of the art, the measures envisaged in such Scenarios would not ensure an appropriate level of security under article 5(1)(f) of the GDPR.

In conclusion, the EDPB regards with suspicion the processing (through matching-and-authenticating process) of biometric templates of the passengers when it happens in centralized storage tools (databases or clouds). The EDPB regards that this increases risks for the security of data, requires the processing of much more data and does not leave passengers in control of the data.

A New European Digital Identity

On March 26, 2024 the Council adopted a new framework for a European digital identity (eID).

Background. In June 2021, the Commission proposed a framework for a eID that would be available to all EU citizens, residents, and businesses, via a European digital identity wallet (EDIWs). The new framework amends the 2014 regulation on electronic identification and trust services for electronic transactions in the internal market (eIDAS regulation n. 910/2014), which laid the foundations for safely accessing public services and carrying out transactions online and across borders in the EU. According to the Commission, the revision of the regulation is needed since only 14% of key public service providers across all Member States allow cross-border authentication with an e-Identity system.

Entry into Force.  The revised regulation will be published in the EU’s Official Journal and will enter into force 20 days after its publication. The regulation will be fully implemented by 2026.

Digital Wallets.  Member States will have to offer citizens and businesses digital wallets that will be able to link their national digital identities with proof of other personal attributes (e.g., driving license, bank account). Citizens will be able to prove their identity simply using their mobile phones.

EU-wide Recognition.  The new EDIWs will enable all citizens to access online services with their national digital identification, which will be recognised throughout the EU. Uses of EDIWs include: opening a bank account, checking in in a hotel, filing tax returns, storing a medical prescription, signing legal documents.

The Right to Digital Identity.  The fundamental purpose of the regulation is to establish the right to a digital identity for Union citizens and to enhance their privacy.

Main features of EDIWs.  According to the new regulation:

• the use of EIDWs shall be voluntary and shall be provided directly, under mandate or recognition by a Member State;

• EDIWs shall enable the user to (1) securely request, store, delete, share person identification data and to authenticate to relying parties; (2) generate pseudonyms and store them encrypted; (3) access a log of all transactions and report to the national authority any unlawful or suspicious request for data; (4) sign or seal by means of qualified electronic signatures; (5) exercise the rights to data portability.

Privacy.  Privacy will be safeguarded through different technologies, such as cryptographic methods allowing to validate whether a given statement based on the person’s identification data is true without revealing any data on which that statement is based. Moreover, EDIWswillhave a dashboard embedded into the design to allow users to request the immediate erasure of any personal data pursuant to Article 17 of the Regulation (EU) 2016/679.

Paola Sangiovanni to Speak on Artificial Intelligence

Our firm will be attending the EMEA Regional Meeting of Ally Law in Malta next week and on Friday November 15th I will be speaking at a panel discussion titled “Keeping an Eye on AI: Ethical and Regulatory Considerations.” 

Artificial intelligence is a hot topic, also in the med-tech field, and poses exciting legal, ethical and regulatory questions. I am sure this will be an interesting opportunity to discuss them with legal and technical experts.