Business unit transfers in Italy: legal insights for International Groups

The Firm recently advised an Italian company, wholly owned by a foreign holding company, on a business unit transfers in Italy (ramo d’azienda) carried out as part of a broader corporate reorganisation.
The transaction highlights the importance of understanding Italian business transfer law when foreign companies operate in Italy and engage in carve-out or disposal transactions governed by Italian civil law.

Business Unit Transfers under Italian Law

Under Italian law, the transfer of a business or business unit is a statutory transaction with effects that extend well beyond a traditional asset sale.
A business unit transfer involves the transfer of an organised and functionally autonomous business capable of carrying out an economic activity on an independent basis.

As a general rule, a transfer of business in Italy includes:

  • tangible and intangible assets forming part of the business unit;

  • ongoing commercial contracts connected with the transferred activity;

  • employees assigned to the business unit, with automatic continuation of employment relationships;

  • rights and certain liabilities related to the operation of the business.

Correctly defining the perimeter of the business unit is therefore essential to ensure consistency between the commercial objectives of the transaction and its legal consequences under Italian law.

Key Challenges for Foreign Companies Operating in Italy

A central aspect of the transaction was assisting the foreign parent company in navigating the mandatory rules of Italian civil law, which often differ significantly from common law frameworks.

In particular, Italian business transfer law provides for a number of effects that apply automatically by operation of law, including:

  • the automatic transfer of certain contracts without the need for individual counterparty consent, subject to statutory exceptions;

  • limitations on the contractual allocation of liability, with residual joint liability of the transferor vis-à-vis certain third parties;

  • extensive employee protection rules triggered by the transfer of a business or business unit;

  • formal execution and registration requirements that affect enforceability and third-party effectiveness.

For international groups accustomed to a more contract-driven approach, these constraints require early legal assessment and careful transaction planning.

A Practical and Transaction-Focused Legal Approach

The Firm provided hands-on legal support throughout the entire carve-out process, focusing on execution efficiency and risk management. In particular, the Firm:

  • advised on the non-waivable effects of a business unit transfer under Italian law;

  • supported the client in structuring the transaction in line with group strategy;

  • coordinated with foreign legal advisors and internal corporate stakeholders;

  • drafted and negotiated transaction documents fully compliant with Italian civil law requirements.

This pragmatic approach enabled the client to complete the transaction smoothly while mitigating legal, operational and post-closing risks.

Supporting International Investors in Italian Transactions

The Firm regularly advises international groups, foreign investors and multinational corporations on:

  • transfers of business and business units in Italy;

  • carve-out transactions and corporate reorganisations;

  • cross-border M&A transactions governed by Italian law.

By combining strong technical expertise with a deep understanding of cross-border deal dynamics, the Firm acts as a reliable legal partner for foreign companies operating in Italy, translating business objectives into effective and compliant legal solutions.

For further information on business unit transfers in Italy or assistance with similar cross-border transactions, our team is available to support clients at every stage of the process.

Directive (EU) 2025/25: a digital corporate transition

With the implementation of the new Directive (EU) 2025/25 a digital corporate transition will take place across the European Union by July 31st, 2027.

Up to now, many procedures are overly bureaucratic and national differences in regulations make it difficult for companies to operate freely in the unified market. With the entry into force of the Directive, some processes will be simplified, while ensuring legal certainty.

The current situation: different bureaucracy, delays and procedures from State to State

Nowadays, the entrepreneur who wants to open a company in an EU Member State, must face several bureaucratic obstacles that differ from country to country.

Setting up a company, for example, often requires the physical presence of the founders at administrative offices, public notary’s offices or chambers of commerce. Even just forming a company branch in another Member State can turn into a lengthy and costly process, with the need to provide authenticated, translated and sometimes apostilled documents.

Collecting information on companies across borders is also not easy. Although the Business Registers Interconnection System (BRIS) exists, much information remains fragmented and not always reliable. This creates problems not only for entrepreneurs who want to expand their business, but also for investors and authorities who need up-to-date and reliable data.

Another major obstacle concerns transactions between entities placed in different Member States.

Companies are required to repeatedly submit the same sets of documents to different administrations, increasing costs and time. Moreover, for those wishing to operate across borders, the procedures of legalisation, sworn translation and obtaining apostilles are a significant burden and time-consuming.

Lastly, the lack of harmonised rules on the verification of corporate information creates disparities and potential risks of fraud. Currently each Member State decides independently how to verify the identity of the founders and directors of a company, with the risk that some jurisdictions are more vulnerable to abuse and white-collar crimes.

What will change with the new Directive?

With the new legislation, European corporate law is finally aligned with the objectives of digitisation and administrative simplification: costs for companies are reduced, transparency increases and controls become more effective.

Company formation and registration: all the process is online

👉 Now: in many States the physical presence of the founders is required, with long and different processing times.

✅ Next: companies will be able to be formed, registered and managed entirely online in all Member States (recital 2).

Thanks to digitisation, registration will be faster and will be possible without the need to go to a public notary or to public offices, except where national law requires specific checks. All documents will be digitally submitted and verified, drastically reducing time and costs.

EU Company Certificate: a single document to operate throughout the Union

👉 Now: proving the existence of a company in another Member State requires chamber of commerce searches, notarised and apostilled translations.

✅ Next: with the EU Company Certificate, companies will be able to validly prove their legal existence with a single electronic document valid throughout the Union (recital 24).

This company certificate, available in all official EU languages, will eliminate the need for legalisation and sworn translation of company documents, making it easier to open branches and participate in cross-border transactions.

End of costly formalities between Member States

👉 Now: every time a company operates in another Member State, it must resubmit the same documents, with expensive authentication procedures.

✅ Next: thanks to the “once-only” principle, information already available in a business register can be reused without the need for resubmission (recital 12).

Furthermore, the digital EU power of attorney, introduced by the Directive, will enable companies to delegate legal representatives to operate in several Member States without the need for notarisation or apostille (recital 27).

More transparency and stronger controls

👉 Now: each Member State has different rules on checks of company information, with risks of fraud and false registrations.

✅ Next: harmonised and mandatory checks will be introduced to ensure the reliability of the data contained in business registers (recital 6).

Enhanced cooperation between the Business Register Interconnection System (BRIS), the Beneficial Owners Interconnection System (BORIS) and the Insolvency Register Interconnection System (IRI) will thus enable more effective cross-checks in the fight against money laundering and tax evasion (recital 10).

Innovations for partnerships

An innovative aspect of the Directive concerns partnerships, which until now have been subject to less stringent transparency rules than corporations.

With the new Directive:

  • all Member States will have to publish the same basic information on partnerships, including the names of liable partners (recital 15).
  • information on partnerships will be accessible through the BRIS system, as is already the case for limited liability companies.
  • partnerships will receive a European Unique Identifier (EUID) that will allow them to be easily traced in public registers.

Personal data protection

The gathering and publication of more corporate information means that the protection of personal data also takes on a central role in the digitalisation process.

Member States and the Commission will have to ensure that the processing of personal data is carried out in compliance with the EU Data Protection Regulation, limiting access and use to strictly necessary purposes (recital 38).

Final remarks

Directive (EU) 2025/25 is a decisive step towards a more modern and accessible single market. Thanks to digitalisation, new transparency measures and strengthened checks, businesses will be able to operate more easily without additional bureaucratic barriers.

At the same time, the focus on data security and privacy protection will ensure that the new system is not only more efficient, but also safer for all players in the market.

Our law firm’s professionals are ready to assist companies step by step in the digitalisation and innovation process that the entry into force of Directive (EU) 2025/25 will entail.

Telemarketing: the Italian Data Protection Authority sanctions SKY again

The decision of the Italian Data Protection Authority dated September 12, 2024, that sanctions Sky Italia S.r.l. (SKY) for unlawful telemarketing activities represents a pivotal moment in the field of personal data protection in Italy.

The decision in question stems from a series of complaints by users regarding alleged unlawful telemarketing activities and issues with consent management by SKY. We believe that our comment could help to identify the minimum guide lines to be followed by the operators in the marketing and communications sector.

The issues addressed to SKY by the Italian Data Protection Authority

Through this decision, the Italian Data Protection Authority issues a sanction against SKY’s conduct, which committed multiple violations of both European and national data protection regulations. In addition the Italian Data Protection Authority detects an evident breach of Article 130 of the Italian Privacy Code concerning the Public Opt-Out Register (RPO).

In particular, the Italian Data Protection Authority highlighted:

  • the failure to conduct a prior verification of the RPO. SKY contacted 644 phone numbers listed in the RPO. This conduct not only infringed the data subjects’ right to not receive unsolicited promotional communications, but also constituted a striking breach of Article 130 of the Italian Privacy Code. This conduct reflects significant negligence in managing internal compliance procedures.
  • A deficient blacklist management. Despite creating a shared blacklist between SKY and its suppliers, several users already listed in the RPO (or who had expressed their objection) were contacted again. This demonstrated inefficiency in updating and monitoring processes by the Data Controller.
  • The absence of valid legal base. SKY’s promotional activities were carried out without obtaining the informed and specific consent by the data subjects, pursuant to Articles 6 and 7 of the GDPR.
  • The weakness of the proof of acquisition of consent. The management of the data subject’s consent was carried out on excel files, which were judged to be bad practice. Because the details of the presumed consents recorded could be changed, they were not capable of being unequivocally granted. In other words, the data subject’s expressed will in relation to the processing of his or her personal data was not clearly recorded.
  • The collection of one consent for multiple processing. The registration to a web site or to any other service offered (such as the participation in a contest) is a separate processing in relation to the advertising activity that the owner intends to pursue. In SKY’s case, the Authority found that registration on the site was proposed as a service in exchange for the consent to the processing of data for marketing purposes.

Corrective measures and sanctions

In this decision, the Italian Data Protection Authority imposed a series of specific corrective measures on SKY to remedy the violations, including:

  • the obligation to search the RPO before every advertising campaign and a prohibition on “any further processing for commercial purposes without proper verification of compliance with information and consent requirements concerning the data subjects whose data have been included in the company’s database.”
  • The implementation of internal controls. The Data Controller is required to adopt rigorous procedures to promptly update the company’s blacklist. This procedure also ensures that no data subject is contacted in violation of applicable regulations. The Italian Data Protection Authority also imposes strict random checks and requires the prior acquisition of free, specific, unequivocal, documented, and informed consent from data subjects for the sending of advertising communications.
  • The adoption of more appropriate measures to ensure that each consent collected from data subjects serves a specific purpose with respect to a given processing of personal data.

In addition to these corrective measures, the Italian Data Protection Authority imposed a financial penalty of €842,062.00, equivalent to 1% of the maximum penalty by law, deemed proportionate to the seriousness of the infringements. The publication of the decision was also ordered as a deterrent.

Sanctions took into account both aggravating factors (such as recidivism, referencing a previous decision from 2021) and mitigating factors (particularly SKY’s cooperation during the investigation).

The Public Opt-Out Register (RPO)

The Italian Public Opt-Out Register has been set as a fundamental tool for protecting consumers from unsolicited promotional communications, even if it seems not to block completely the phenomenon.

According to the Italian law companies must verify in advance whether users are registered in the RPO before making calls or sending advertising SMS.

However, in SKY’s case, a significant deficiency in these checks was revealed, leading to numerous violations confirmed by the Italian Data Protection Authority.

Specifically, the Italian Data Protection Authority found that SKY contacted several people listed in the RPO for advertising purposes, in plain infringement of Article 130 of the Privacy Code and Articles 5 and 6 of the GDPR.

Additionally, some of the unsolicited communications were carried out by third-party suppliers engaged by SKY, who failed to consult their respective blacklists in advance. On this point, the Italian Data Protection Authority clarified that SKY remains jointly liable for failing to adequately supervise its partners.

Practical implications for companies

The decision against SKY provides valuable insights for companies, including those operating in the telemarketing field.

In another article, we have already highlighted the importance for companies to conduct their marketing campaigns responsibly.

Additionally, we highlight that, the prior check of the Public Opt-Out Register should not be seen as a mere formality during the development of each marketing campaign. Instead it should be an essential step to ensure regulatory compliance and protect the rights of data subjects as per Italian privacy law.

Consequently, companies must exercise a strict control over the suppliers entrusted to process personal data, ensuring they operate in compliance with current regulations. To this purpose, periodic audits can help to prevent similar violations and also allow companies to promptly identify potential issues in their processes.

Final Considerations

The SKY case is an emblematic example of the consequences of inefficient personal data management and non-compliance with data protection regulations in the field of marketing and communication.

The failure to adhere to the rules governing the Public Opt-Out Register highlights the need for companies to adopt a more rigorous approach. Because compliance is not only a legal obligation but also a strategic factor for building trust and reputation.

Finally, the decision of the Italian Data Protection Authority which sanctions SKY underscores the importance of strict application of personal data protection rules. It is fundamental to safeguard the rights of data subjects and to promote a responsible corporate culture. For companies, this case serves as a warning to review and strengthen their internal procedures. The respect for regulations and users’ fundamental rights has to be at the center of their marketing initiatives.

Digital Markets Act: the recipients of the new regulation

The reform of digital markets

On July 5th, 2022, the European Parliament approved the Digital Markets Act (introduced with Reg. EU 2022/1925) (DMA), the first European regulation for digital markets which, together with the Digital Services Act (DSA), is part of a bigger project aimed at strengthening the regulation of big tech entities.

The DMA’s primary goal is to promote fair competition and limit monopolistic practices by big online platforms, as well as contain abusive practices and dominant positions, in order to strengthen competition on the market and give more space to the “smaller” operators.

The recipients of the legislation

a) The gatekeepers

After the DMA’s entry into force (on November 1st, 2022), and within the adjustment time limit imposed by the European legislation (by March 6th, 2023), the so-called “gatekeeper” recipients must follow precise directions to avoid incurring in heavy penalties.

Gatekeepers are defined as those corporations which control a certain market sector, and in the digital world such gatekeepers are the LOPs – Large Online Platforms.

Pertaining to DMA articles 2 and 3, the word “gatekeeper” refers to a provider whose core platform services are:

  • Online search engines
  • Intermediation services
  • Social networking services
  • Video-sharing platform services
  • Operating systems
  • Number-independent interpersonal communication services
  • Cloud computing and advertisement services

b) The gatekeepers’ size limits

The new legislation specifies the requirements that such provider must satisfy in order to be classified as a gatekeeper according to the DMA Regulation.

Firstly, a Big Tech corporation will be considered a gatekeeper if it achieves an annual EU turnover equal to or above EUR 7,5 billion (in each of the last three financial years) or if its average market capitalisation or its equivalent fair market value amounted to at least EUR 75 billion (in the last financial year), and if it provides the same core platform service in at least three Member States (as per DMA, article 3, par. 2, point a).

Another requirement is that the undertaking provides a core platform service that in the last financial year has at least 45 million monthly active end users established or located in the EU and at least 10.000 yearly active business users established in the EU (in order to correctly identify and calculate the active business/end users, the Regulation has set out a specific methodology and indicators in its Annex), as stated in DMA article 3, par. 2, point b).

Lastly, the undertaking must enjoy an entrenched and durable position (as per DMA article 3, par. 1, point c), which will be presumed when the thresholds mentioned above (turnover/impact on the internal market and gateway control/active users on a monthly basis) were met in each of the last three financial years (as per DMA article 3, par. 2, point c).

Businesses can challenge the result of the calculation, reasoning on exceptional circumstances that might justify their exclusion from the aforementioned category.

c) “Emerging” businesses

The gatekeeper qualification might also apply, shall the European Commission see fit, to so-called “emerging” businesses, meaning those undertakings that have all the requirements to become gatekeepers. However, these undertakings will not have to comply with all the requirements imposed on “consolidated” gatekeepers.

The Commission’s job will be to periodically (or at least every three years) monitor the gatekeepers’ status, and it is therefore empowered to request, at any time, all the information it deems necessary from Big Tech corporations whenever a merger, or an acquisition of an “emerging” business by a domineering one occurs.

By going over the DMA legislation, it is clear that the EU’s goal is to reduce the power of big digital platforms and to promote a digital environment that is more open, innovative and competitive for businesses and European consumers.

Gatekeepers according to the EU Commission

The European Commission has already identified the first six gatekeepers (Meta, Amazon, Apple, Microsoft, Alphabet, ByteDance), and their related Core Platform Services (or CPS), as follows:

  • 6 intermediary platforms (Amazon Marketplace, Google Maps, Google Play, Google Shopping, iOS App Store, Meta Marketplace)
  • 4 social networks (Facebook, Instagram, LinkedIn, TikTok)
  • 3 online advertisement services (Amazon, Google, and Meta)
  • 3 widespread operating systems (Google Android, iOS, SO Windows PC)
  • 2 web browsers (Chrome and Safari)
  • 2 big interpersonal communication services (Facebook Messenger and WhatsApp, both owned by Meta)
  • 1 video-sharing platform (YouTube)
  • 1 search engine (Google)

New obligations and prohibitions for gatekeepers

According to the new legislation, gatekeepers must comply with several obligations and respect the related prohibitions.

One of the obligations the Regulation imposes is to allow end users to cancel their subscription to the platform’s main services as easily as they have subscribed.

Amongst the prohibitions, it is forbidden to track end users outside of the platform’s main service for targeted advertisement purposes, if consent to such tracking has not been obtained. Valid consent from the user will have to be obtained before their personal data is gathered or utilized through the gatekeepers’ platforms and services used by third parties.

In many cases, these businesses will be asked to express their consent to the gatekeepers in order to keep having access to their platforms, for example they may do so through Google’s consent process (Google Consent Mode, which will be the topic of an in-depth analysis in a separate, soon-to-be published article on our website).

Moreover, gatekeepers will be prohibited from using access to their platforms or services to show any preference or positioning towards other businesses. They will also have an obligation to make transferring a user’s data from their platform to other services as simple as possible.

Ultimately, the ambitious goal the European Union is aiming for with this reform is to grant more openness to digital platforms, allowing “smaller” businesses equal access to the crowd of web users and the respective data that platforms produce, while trying to limit the unfair competition practices that Big Tech corporations have carried out until today thanks to their controlling position.