Diritto al Digitale is the must-listen podcast on innovation law, brought to you by Giulio Coraggio, data and technology lawyer at the global law firm DLA Piper. Each episode explores the cutting-edge legal challenges shaping our digital world—from data privacy and artificial intelligence to the Internet of Things, outsourcing, e-commerce, and intellectual property.
Join us as we illuminate the legal frameworks behind today’s breakthroughs and provide insider insights on how innovation is transforming the future of business and society.
You can contact us at the details available on dlapiper.com
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
5:08
In this episode of Legal Break, Giulio Coraggio, location head of the Italian Intellectual Property & Technology Law group at the law firm DLA Piper and the journalist Antonio Ravenna explain an important Italian court decision about DPO liability, GDPR, and cyber fraud.
A company lost €390,000 in a Business Email Compromise (BEC) attack: criminals sent fake payment instructions and the money went to the wrong bank account. The company tried to blame its external DPO, but the Court of Florence (Decision No. 3034 of 29 May 2026) said no.
Giulio and Antonio explain, in clear and simple words, why the DPO’s job under the GDPR is to advise and monitor, not to make security decisions, and why the duty to put real security measures in place stays with the company. They also share practical lessons: why good documentation is the DPO’s best defense, why ignoring the DPO’s advice can create liability for the company, and why naming a DPO is not a replacement for real cybersecurity.