Directive (EU) 2025/25: a digital corporate transition

With the implementation of the new Directive (EU) 2025/25 a digital corporate transition will take place across the European Union by July 31st, 2027.

Up to now, many procedures are overly bureaucratic and national differences in regulations make it difficult for companies to operate freely in the unified market. With the entry into force of the Directive, some processes will be simplified, while ensuring legal certainty.

The current situation: different bureaucracy, delays and procedures from State to State

Nowadays, the entrepreneur who wants to open a company in an EU Member State, must face several bureaucratic obstacles that differ from country to country.

Setting up a company, for example, often requires the physical presence of the founders at administrative offices, public notary’s offices or chambers of commerce. Even just forming a company branch in another Member State can turn into a lengthy and costly process, with the need to provide authenticated, translated and sometimes apostilled documents.

Collecting information on companies across borders is also not easy. Although the Business Registers Interconnection System (BRIS) exists, much information remains fragmented and not always reliable. This creates problems not only for entrepreneurs who want to expand their business, but also for investors and authorities who need up-to-date and reliable data.

Another major obstacle concerns transactions between entities placed in different Member States.

Companies are required to repeatedly submit the same sets of documents to different administrations, increasing costs and time. Moreover, for those wishing to operate across borders, the procedures of legalisation, sworn translation and obtaining apostilles are a significant burden and time-consuming.

Lastly, the lack of harmonised rules on the verification of corporate information creates disparities and potential risks of fraud. Currently each Member State decides independently how to verify the identity of the founders and directors of a company, with the risk that some jurisdictions are more vulnerable to abuse and white-collar crimes.

What will change with the new Directive?

With the new legislation, European corporate law is finally aligned with the objectives of digitisation and administrative simplification: costs for companies are reduced, transparency increases and controls become more effective.

Company formation and registration: all the process is online

👉 Now: in many States the physical presence of the founders is required, with long and different processing times.

✅ Next: companies will be able to be formed, registered and managed entirely online in all Member States (recital 2).

Thanks to digitisation, registration will be faster and will be possible without the need to go to a public notary or to public offices, except where national law requires specific checks. All documents will be digitally submitted and verified, drastically reducing time and costs.

EU Company Certificate: a single document to operate throughout the Union

👉 Now: proving the existence of a company in another Member State requires chamber of commerce searches, notarised and apostilled translations.

✅ Next: with the EU Company Certificate, companies will be able to validly prove their legal existence with a single electronic document valid throughout the Union (recital 24).

This company certificate, available in all official EU languages, will eliminate the need for legalisation and sworn translation of company documents, making it easier to open branches and participate in cross-border transactions.

End of costly formalities between Member States

👉 Now: every time a company operates in another Member State, it must resubmit the same documents, with expensive authentication procedures.

✅ Next: thanks to the “once-only” principle, information already available in a business register can be reused without the need for resubmission (recital 12).

Furthermore, the digital EU power of attorney, introduced by the Directive, will enable companies to delegate legal representatives to operate in several Member States without the need for notarisation or apostille (recital 27).

More transparency and stronger controls

👉 Now: each Member State has different rules on checks of company information, with risks of fraud and false registrations.

✅ Next: harmonised and mandatory checks will be introduced to ensure the reliability of the data contained in business registers (recital 6).

Enhanced cooperation between the Business Register Interconnection System (BRIS), the Beneficial Owners Interconnection System (BORIS) and the Insolvency Register Interconnection System (IRI) will thus enable more effective cross-checks in the fight against money laundering and tax evasion (recital 10).

Innovations for partnerships

An innovative aspect of the Directive concerns partnerships, which until now have been subject to less stringent transparency rules than corporations.

With the new Directive:

  • all Member States will have to publish the same basic information on partnerships, including the names of liable partners (recital 15).
  • information on partnerships will be accessible through the BRIS system, as is already the case for limited liability companies.
  • partnerships will receive a European Unique Identifier (EUID) that will allow them to be easily traced in public registers.

Personal data protection

The gathering and publication of more corporate information means that the protection of personal data also takes on a central role in the digitalisation process.

Member States and the Commission will have to ensure that the processing of personal data is carried out in compliance with the EU Data Protection Regulation, limiting access and use to strictly necessary purposes (recital 38).

Final remarks

Directive (EU) 2025/25 is a decisive step towards a more modern and accessible single market. Thanks to digitalisation, new transparency measures and strengthened checks, businesses will be able to operate more easily without additional bureaucratic barriers.

At the same time, the focus on data security and privacy protection will ensure that the new system is not only more efficient, but also safer for all players in the market.

Our law firm’s professionals are ready to assist companies step by step in the digitalisation and innovation process that the entry into force of Directive (EU) 2025/25 will entail.

Telemarketing: the Italian Data Protection Authority sanctions SKY again

The decision of the Italian Data Protection Authority dated September 12, 2024, that sanctions Sky Italia S.r.l. (SKY) for unlawful telemarketing activities represents a pivotal moment in the field of personal data protection in Italy.

The decision in question stems from a series of complaints by users regarding alleged unlawful telemarketing activities and issues with consent management by SKY. We believe that our comment could help to identify the minimum guide lines to be followed by the operators in the marketing and communications sector.

The issues addressed to SKY by the Italian Data Protection Authority

Through this decision, the Italian Data Protection Authority issues a sanction against SKY’s conduct, which committed multiple violations of both European and national data protection regulations. In addition the Italian Data Protection Authority detects an evident breach of Article 130 of the Italian Privacy Code concerning the Public Opt-Out Register (RPO).

In particular, the Italian Data Protection Authority highlighted:

  • the failure to conduct a prior verification of the RPO. SKY contacted 644 phone numbers listed in the RPO. This conduct not only infringed the data subjects’ right to not receive unsolicited promotional communications, but also constituted a striking breach of Article 130 of the Italian Privacy Code. This conduct reflects significant negligence in managing internal compliance procedures.
  • A deficient blacklist management. Despite creating a shared blacklist between SKY and its suppliers, several users already listed in the RPO (or who had expressed their objection) were contacted again. This demonstrated inefficiency in updating and monitoring processes by the Data Controller.
  • The absence of valid legal base. SKY’s promotional activities were carried out without obtaining the informed and specific consent by the data subjects, pursuant to Articles 6 and 7 of the GDPR.
  • The weakness of the proof of acquisition of consent. The management of the data subject’s consent was carried out on excel files, which were judged to be bad practice. Because the details of the presumed consents recorded could be changed, they were not capable of being unequivocally granted. In other words, the data subject’s expressed will in relation to the processing of his or her personal data was not clearly recorded.
  • The collection of one consent for multiple processing. The registration to a web site or to any other service offered (such as the participation in a contest) is a separate processing in relation to the advertising activity that the owner intends to pursue. In SKY’s case, the Authority found that registration on the site was proposed as a service in exchange for the consent to the processing of data for marketing purposes.

Corrective measures and sanctions

In this decision, the Italian Data Protection Authority imposed a series of specific corrective measures on SKY to remedy the violations, including:

  • the obligation to search the RPO before every advertising campaign and a prohibition on “any further processing for commercial purposes without proper verification of compliance with information and consent requirements concerning the data subjects whose data have been included in the company’s database.”
  • The implementation of internal controls. The Data Controller is required to adopt rigorous procedures to promptly update the company’s blacklist. This procedure also ensures that no data subject is contacted in violation of applicable regulations. The Italian Data Protection Authority also imposes strict random checks and requires the prior acquisition of free, specific, unequivocal, documented, and informed consent from data subjects for the sending of advertising communications.
  • The adoption of more appropriate measures to ensure that each consent collected from data subjects serves a specific purpose with respect to a given processing of personal data.

In addition to these corrective measures, the Italian Data Protection Authority imposed a financial penalty of €842,062.00, equivalent to 1% of the maximum penalty by law, deemed proportionate to the seriousness of the infringements. The publication of the decision was also ordered as a deterrent.

Sanctions took into account both aggravating factors (such as recidivism, referencing a previous decision from 2021) and mitigating factors (particularly SKY’s cooperation during the investigation).

The Public Opt-Out Register (RPO)

The Italian Public Opt-Out Register has been set as a fundamental tool for protecting consumers from unsolicited promotional communications, even if it seems not to block completely the phenomenon.

According to the Italian law companies must verify in advance whether users are registered in the RPO before making calls or sending advertising SMS.

However, in SKY’s case, a significant deficiency in these checks was revealed, leading to numerous violations confirmed by the Italian Data Protection Authority.

Specifically, the Italian Data Protection Authority found that SKY contacted several people listed in the RPO for advertising purposes, in plain infringement of Article 130 of the Privacy Code and Articles 5 and 6 of the GDPR.

Additionally, some of the unsolicited communications were carried out by third-party suppliers engaged by SKY, who failed to consult their respective blacklists in advance. On this point, the Italian Data Protection Authority clarified that SKY remains jointly liable for failing to adequately supervise its partners.

Practical implications for companies

The decision against SKY provides valuable insights for companies, including those operating in the telemarketing field.

In another article, we have already highlighted the importance for companies to conduct their marketing campaigns responsibly.

Additionally, we highlight that, the prior check of the Public Opt-Out Register should not be seen as a mere formality during the development of each marketing campaign. Instead it should be an essential step to ensure regulatory compliance and protect the rights of data subjects as per Italian privacy law.

Consequently, companies must exercise a strict control over the suppliers entrusted to process personal data, ensuring they operate in compliance with current regulations. To this purpose, periodic audits can help to prevent similar violations and also allow companies to promptly identify potential issues in their processes.

Final Considerations

The SKY case is an emblematic example of the consequences of inefficient personal data management and non-compliance with data protection regulations in the field of marketing and communication.

The failure to adhere to the rules governing the Public Opt-Out Register highlights the need for companies to adopt a more rigorous approach. Because compliance is not only a legal obligation but also a strategic factor for building trust and reputation.

Finally, the decision of the Italian Data Protection Authority which sanctions SKY underscores the importance of strict application of personal data protection rules. It is fundamental to safeguard the rights of data subjects and to promote a responsible corporate culture. For companies, this case serves as a warning to review and strengthen their internal procedures. The respect for regulations and users’ fundamental rights has to be at the center of their marketing initiatives.

Digital Markets Act: the recipients of the new regulation

The reform of digital markets

On July 5th, 2022, the European Parliament approved the Digital Markets Act (introduced with Reg. EU 2022/1925) (DMA), the first European regulation for digital markets which, together with the Digital Services Act (DSA), is part of a bigger project aimed at strengthening the regulation of big tech entities.

The DMA’s primary goal is to promote fair competition and limit monopolistic practices by big online platforms, as well as contain abusive practices and dominant positions, in order to strengthen competition on the market and give more space to the “smaller” operators.

The recipients of the legislation

a) The gatekeepers

After the DMA’s entry into force (on November 1st, 2022), and within the adjustment time limit imposed by the European legislation (by March 6th, 2023), the so-called “gatekeeper” recipients must follow precise directions to avoid incurring in heavy penalties.

Gatekeepers are defined as those corporations which control a certain market sector, and in the digital world such gatekeepers are the LOPs – Large Online Platforms.

Pertaining to DMA articles 2 and 3, the word “gatekeeper” refers to a provider whose core platform services are:

  • Online search engines
  • Intermediation services
  • Social networking services
  • Video-sharing platform services
  • Operating systems
  • Number-independent interpersonal communication services
  • Cloud computing and advertisement services

b) The gatekeepers’ size limits

The new legislation specifies the requirements that such provider must satisfy in order to be classified as a gatekeeper according to the DMA Regulation.

Firstly, a Big Tech corporation will be considered a gatekeeper if it achieves an annual EU turnover equal to or above EUR 7,5 billion (in each of the last three financial years) or if its average market capitalisation or its equivalent fair market value amounted to at least EUR 75 billion (in the last financial year), and if it provides the same core platform service in at least three Member States (as per DMA, article 3, par. 2, point a).

Another requirement is that the undertaking provides a core platform service that in the last financial year has at least 45 million monthly active end users established or located in the EU and at least 10.000 yearly active business users established in the EU (in order to correctly identify and calculate the active business/end users, the Regulation has set out a specific methodology and indicators in its Annex), as stated in DMA article 3, par. 2, point b).

Lastly, the undertaking must enjoy an entrenched and durable position (as per DMA article 3, par. 1, point c), which will be presumed when the thresholds mentioned above (turnover/impact on the internal market and gateway control/active users on a monthly basis) were met in each of the last three financial years (as per DMA article 3, par. 2, point c).

Businesses can challenge the result of the calculation, reasoning on exceptional circumstances that might justify their exclusion from the aforementioned category.

c) “Emerging” businesses

The gatekeeper qualification might also apply, shall the European Commission see fit, to so-called “emerging” businesses, meaning those undertakings that have all the requirements to become gatekeepers. However, these undertakings will not have to comply with all the requirements imposed on “consolidated” gatekeepers.

The Commission’s job will be to periodically (or at least every three years) monitor the gatekeepers’ status, and it is therefore empowered to request, at any time, all the information it deems necessary from Big Tech corporations whenever a merger, or an acquisition of an “emerging” business by a domineering one occurs.

By going over the DMA legislation, it is clear that the EU’s goal is to reduce the power of big digital platforms and to promote a digital environment that is more open, innovative and competitive for businesses and European consumers.

Gatekeepers according to the EU Commission

The European Commission has already identified the first six gatekeepers (Meta, Amazon, Apple, Microsoft, Alphabet, ByteDance), and their related Core Platform Services (or CPS), as follows:

  • 6 intermediary platforms (Amazon Marketplace, Google Maps, Google Play, Google Shopping, iOS App Store, Meta Marketplace)
  • 4 social networks (Facebook, Instagram, LinkedIn, TikTok)
  • 3 online advertisement services (Amazon, Google, and Meta)
  • 3 widespread operating systems (Google Android, iOS, SO Windows PC)
  • 2 web browsers (Chrome and Safari)
  • 2 big interpersonal communication services (Facebook Messenger and WhatsApp, both owned by Meta)
  • 1 video-sharing platform (YouTube)
  • 1 search engine (Google)

New obligations and prohibitions for gatekeepers

According to the new legislation, gatekeepers must comply with several obligations and respect the related prohibitions.

One of the obligations the Regulation imposes is to allow end users to cancel their subscription to the platform’s main services as easily as they have subscribed.

Amongst the prohibitions, it is forbidden to track end users outside of the platform’s main service for targeted advertisement purposes, if consent to such tracking has not been obtained. Valid consent from the user will have to be obtained before their personal data is gathered or utilized through the gatekeepers’ platforms and services used by third parties.

In many cases, these businesses will be asked to express their consent to the gatekeepers in order to keep having access to their platforms, for example they may do so through Google’s consent process (Google Consent Mode, which will be the topic of an in-depth analysis in a separate, soon-to-be published article on our website).

Moreover, gatekeepers will be prohibited from using access to their platforms or services to show any preference or positioning towards other businesses. They will also have an obligation to make transferring a user’s data from their platform to other services as simple as possible.

Ultimately, the ambitious goal the European Union is aiming for with this reform is to grant more openness to digital platforms, allowing “smaller” businesses equal access to the crowd of web users and the respective data that platforms produce, while trying to limit the unfair competition practices that Big Tech corporations have carried out until today thanks to their controlling position.

What are SME Srls in Italy?

When Srls qualify as SMEs?

Limited Liability Companies (Srl – società a responsabilità limitata) may qualify also  as Small and Medium-sized Enterprises (SME).

As of the date of this article, the requirements for a business to be classified as an SME are as follows:

  1. employing fewer than 250 employees, and
  2. having an annual turnover not exceeding EUR 50 million, or
  3. having an annual balance sheet total not exceeding EUR 43 million.

What are the advantages of SME Srls?

The Italian law grants several exemptions to SME Srls compared to the codified discipline of limited liability companies. Among these, we recall:

  • the possibility to issue special categories of shares (quotas) with different rights, the determination of which – quite open, subject to the non-derogable limits of the law, such as the leonine pact – is left to the articles of association
  • the possibility to issue “standardized” shares, meaning shares of equal value (divided into units of measurement like the shares of joint stock companies) and conferring equal rights among them
  • the possibility to carry out transactions on its own quotas, provided they are framed within the scope of plans to incentivize the company’s collaborators that envisage the allocation to them of shares of capital
  • the possibility to carry out public offerings of quotas also through equity crowdfunding portals
  • the possibility to dematerialize the quotas, provided they are standardized quotas and the shareholders’ register is kept

This last possibility was introduced by the “legge capitaliw” (act of 5 March 2024, no. 21, art. 3) which amended art. 26 of the decree of 18 October 2012, no. 179, converted, with amendments, by the act of 17 December 2012, no. 221.

In essence, it will be possible for SME Srls to issue dematerialized and therefore electronic quotas and manage them through a centralized management system, exactly as is the case for listed joint stock companies.

Is your e-commerce compliant with the Omnibus Directive?

Omnibus Directive protects consumers rights in online purchases

With the entry into force of Legislative Decree no. 26 of March 7, 2023, known as the “Omnibus Decree,” Italy transposed Directive Omnibus (EU) 2019/2161 of November 27, 2019. Such decree introduced significant amendments to the Italian Consumer Code (Legislative Decree no. 206/2005) to ensure a better  protection to consumers in online purchases.

How to fairly communicate price reductions in the web shops?

One of the most significant innovations concerns transparency in communicating discounted prices. According to Article 17 bis, para. 1 of the Italian Consumer Code, as amended by the Omnibus Decree, professionals must indicate not only the percentage discount but also the lowest price applied in the thirty days preceding the reduction. This provision aims to provide consumers with clear and complete information about the true benefits offered by promotions.

However, exceptions are provided for perishable food products to avoid excessive complexity in commercial communications concerning such products.

Fighting unfair competition practices and online reviews

The  European Omnibus Directive has introduced new provisions to fight deceptive commercial practices. Among these is the regulation of “Dual Quality,” which prohibits the promotion of goods as identical if there are significant differences between them in composition and characteristics.

Furthermore, stricter rules have been established for managing online reviews. As a consequence, it is now mandatory to indicate whether reviews come from consumers who have actually purchased the product, and sellers must take measures to verify the authenticity of such reviews.

Finally, the decree introduces harmonized sanctions at the European level for unfair commercial practices, ensuring greater uniformity in the application of sanctions among the Member States of the European Union.

On one hand the Omnibus Directive protects consumers online purchases, on the other hand it imposes the adoption of fair communications in order to push the e-commerce market.

Harmonized monetary sanctions

Monetary sanctions have been harmonized at the European level, with an increase in the maximum fine up to 10 million euros for violations of unfair commercial practices.

The sanctions are calculated considering various parameters, such as the nature and seriousness of the violation, the efforts of the professional to remedy the damage, and previous infringements.

Moreover, greater protections for consumers have been introduced, including the possibility of recourse to the ordinary judge to obtain proportionate and effective remedies in case of injuries suffered, such as compensation for damages or contract termination.

In conclusion, the Omnibus Decree represents a significant step forward in protecting consumers in online purchases, introducing clearer and stricter rules to counter unfair commercial practices and ensure greater transparency and fairness in the relationships between sellers and buyers.

Impact and compliance of the metadata collection by employers through email applications

Introduction

On December 21, 2023, the Italian Data Protection Authority issued a provision with significant implications for employers using email applications to manage internal communications. This provision focuses on the collection and retention of metadata relating to employees’ email accounts. In this article, we will examine the impact of this provision and the compliance requirements imposed on employers to adhere to said provisions.

What are metadata?

Metadata are data that provide information about the characteristics of other information. In other words, they are descriptions or additional information that provide context or structure to the main data. Here are some examples of metadata in different contexts:

  • Email Metadata: In emails, metadata includes information such as the sender, recipient, subject, date and time sent, transmission path, and other technical information that helps manage and organize emails.
  • Photo Metadata: For digital photos, metadata can include the date and time of capture, camera settings, GPS coordinates of where the photo was taken, and other information about the camera and shooting conditions.
  • Document Metadata: In digital documents, metadata can include information such as the document author, creation date, last modification date, document title, and other formatting and structure-related information.
  • Audio/Video File Metadata: In digital audio and video files, metadata can include information such as the song title, artist, album, year of release, duration, file format, and other recording-related information.

Metadata can be useful because it allows for the organization, search, retrieval, and better understanding of the main data. It can be used for various purposes such as digital content management, information retrieval, cybersecurity, regulatory compliance, and more. However, it is also important to consider privacy and security implications when managing metadata, as it can contain sensitive or confidential information.

Impact of the Authority’s guidance on metadata collection by employers

The Authority’s provision highlighted the risk associated with the preventive and generalized collection of metadata from email applications used by employees. Such metadata includes information such as sender, recipient, subject, date, and email size. The primary concern is that some computer programs and services may collect this metadata by default, without the employer’s ability to disable this functionality or limit the period of information retention.

Required Compliance

In response to this risk, the Data Protection Authority has mandated employers to adopt certain compliance measures to ensure compliance with privacy regulations and the protection of employees’ personal data. The following are the main compliance requirements:

  • Verification of Metadata Collection: Employers must diligently verify whether the computer programs and services used for email management collect metadata from employees’ accounts. This verification must be thoroughly documented to demonstrate compliance with the provisions of the provision.
  • Modification of Basic Settings: In case metadata collection is confirmed, employers must be able to modify the basic settings of computer programs and services to prevent the collection of metadata or limit the retention period to a maximum of 7 days, save the possibility of extending this period by an additional 48 hours in exceptional cases.
  • Labor safegards: If limiting metadata is not possible due to proven organizational or productive needs, employers must follow some safeguard procedures provided by sector regulations. This may include entering into a labour agreement with unions or obtaining authorization from the labor inspectorate. The aim is to ensure that extending the metadata retention period does not result in remote monitoring of employees’ activities.
  • Employee Information: It remains essential to provide employees with correct information regarding the processing of their personal data, including the collection and retention of metadata related to email.

Practical advice for metadata collection by employers

The Data Protection Authority’s provision represents a significant step forward in protecting employees’ privacy and regulating the use of metadata by employers. It is crucial for employers to take appropriate measures to comply with the established provisions while ensuring transparency and respecting employees’ rights.

Check of metadata collection, modification of email program settings, and adherence to labor safeguard procedures are essential steps to ensure compliance and mitigate risks associated with the management of employees’ personal data.

 

 

 

E-commerce = Cybersecurity, compliance to GDPR and ethics

In the digital age we live in, cybersecurity management, GDPR compliance and web ethics are important elements for any website, but when it comes to offering products and services, they become milestones.

In our law firm we have been assisting companies and professionals who approach e-commerce for years, accompanying them on a virtuous path towards maximum data security, compliance with data protection legislation and the offer of an ethically correct user experience, avoiding the use of dark patterns.

Cybersecurity: The Priority

Cybersecurity is a key pillar to protect your website, personal data, and business reputation. The design of the website for the e-commerce business must necessarily deal with an armoring of the IT system underlying the platform, including the front-end, through some fundamental steps:

  • Context study: examination of the sales project, study of the market and known relevant risks in the target market.
  • Selection of assets and suppliers with proven reliability.
  • Functional analysis of the supply cycle and vulnerabilities: In-depth assessment to identify possible security flaws and weaknesses in the site.
  • Security planning: creating customized strategies to protect the site from online threats, human error, supply chain risk.
  • Incident response: Prepare for and assist in the event of a data breach or cyberattack.
  • Recovery: design of a system for the rapid and effective recovery of the site and its contents in the event of an incident.
  • Staff training: Security education and culture to ensure that all team members are aware of cybersecurity best practices and remain sensitive to any signs of anomaly.

GDPR compliance: protecting data and complying with the regulation is a duty but it can be also a nice business card!

The GDPR is a legal obligation that affects any website that collects, processes or stores personal data of European citizens. Non-compliance, in addition to exposing you to heavy penalties by the supervisory authorities, denotes an attitude of neglect and lack of respect for users’ rights.

The right approach to compliance goes through:

  • Specific risk analysis and possible impact assessment: whatever the method used, ISO standards, ENISA method or other, the risk associated with the processing carried out by the website is the basis for the adoption of appropriate technical and organizational measures.
  • A compliance assessment: identification of areas where the site may not be in line with the provisions of the GDPR and planning of the activities to be carried out, also based on the evolutionary developments of the site.
  • Legal documentation: drafting of privacy notices, privacy policies and agreements with data processors.
  • The management of cookies: identification and categorization of cookies, drafting of the policy in compliance with the guidelines of the Supervisory Authority.
  • Management of consents: correct collection of consents from data subjects for marketing and profiling activities and management of their valid archiving or revocation.
  • Breach management: Inclusion of the site in the perimeter of the incident response report.

Web ethics: no Dark Patterns

The online sales activity, however, does not “only” require compliance with the law, it assumes that, in the opinion of our law firm, ethical design as an essential requirement to build a relationship of trust with users. Dark patterns, deceptive practices that negatively affect the user experience, damage the reputation of the site.

The support provided by our firm to operators promotes web ethics in an attempt to have a correct, transparent and respectful approach towards users who are the engine and the most valuable asset of online business.

We have already had the opportunity to deal with dark patterns previously, but it is worth remembering that the direction outlined by the European legislator with the REGULATION (EU) 2022/2065 is a clear fight to dark patterns and their use does not go unnoticed either by users, consumer associations or the various authorities of control, from the Data Protection Authority to the AGCM (Italian Competition Authority).

In conclusion, cybersecurity, GDPR compliance, and web ethics are critical pillars for the success of your website. Users’ trust is your most valuable asset online, and following best practices in security and ethics is the best way to build it.

Kinds of companies in Italy

There are several kind of companies by which you can carry out a business in Italy and we thought that it could be useful for a foreign reader to find some initial information about that. Please consider that this short note is only meant to provide a very limited set of basic information that we will be glad to discuss with you in more details in case of interest.

Ways to carry out a business in Italy

In Italy, businesses can be carried out either by one person (who is known as an imprenditore individuale, a sole trader) or by two or more persons putting resources together with the view of profit (società). There are several kinds of companies in Italy, but let us start from the beginning…

When two or more persons agree to carry out a business by putting resources together, they are starting either:

  • a partnership (società di persone) or
  • a company (società di capitali).

Partnerships (società di persone)

As a general rule, with limited exceptions concerning only the società in accomandita, partners in a partnership do not enjoy limited liability and therefore are jointly and severally liable with the partnership for its obligations. Although very unusual, partnerships can be set up by oral agreement and there is no minimum amount of money or assets required to start them.

Companies (società di capitali)

In order to enjoy limited liability, the partners have to set up either:

  • a società a responsabilità limitata (srl, a private limited company) or
  • a società per azioni (spa, a public limited company).

The srl is a multi-purpose vehicle that can fit the needs of SMEs in most cases. It easier to run than a spa, which is the model company generally used to run larger businesses.

Both srls and spas, as a general rule with some limited exceptions, have to be set up by means of a notarial deed.

While srls can be started with as little as one-euro initial corporate capital, the minimum amount required to start a spa is euro 50.000.

It is important to add that the law allows to start companies in Italy with a sole shareholder, who still enjoys limited liability.

For more information about the kinds of companies in Italy, visit this link or contact us at this link.

Setting up a business in Italy

In this short article we will rapidly review the options available to foreign entities willing to set up a business in Italy.

Available options

Generally speaking, most foreign citizens are allowed to set up a business in Italy. We will limit this paper to the case of foreign companies willing to start operating in Italy.

Basically, there are three ways by which such aim can be reached:

  1. establishing a branch office
  2. incorporating a subsidiary company
  3. purchasing an existing company

Branch office

Firstly, iorder to start operating in Italy, a company based abroad could simply open a branch office. Once the premises have been found, the company is required to appear, through its legal representatives or an attorney, before a notary in Italy in order to sign a deed of incorporation of the branch.

Several pieces of information must be included in the deed: name of the company, registered office, name and address of the branch office, person in charge of the branch office, etc.

A copy of the company’s articles of association must be attached to the deed (the copy must be stamped with the apostille, translated in Italian and sworn in court). Satisfactory evidence of the powers of the representatives/attorneys must be provided to the notary.

Then the notary will file the deed to the relevant company register office (called in Italy “Registro delle Imprese”, a register held by the Camera di Commercio). Company register fees and taxes are to be paid.

Subsidiary company

Moreover, you could consider forming a subsidiary company. When incorporating a company, the first step is defining the kind of company that suits most the needs of the parent: a public company or a limited company are the most commonly used kinds.

Then the articles of association must be drawn up in the form that, in accordance with the law, suits the needs of the business. Share capital amount, registered office, directors and, in some circumstances, auditors have to be defined at this stage.

Once again, in order to incorporate the company, a notary is needed: he or she will witness the memorandum of association that will be signed as a deed by the parent’s company representatives or by their attorneys.

Satisfactory evidence of the powers of the representatives/attorneys must be provided to the notary. Then the notary will file the memorandum of association and the articles of association to the company register.

Purchasing an existing company

Finally, purchasing the share capital of an existing company can be an option.

In this case, after a due diligence process, aimed at evaluating the target company as well as at highlighting any critical aspect/risk of the acquisition, lawyers draft a sale and purchase agreement that has to be negotiated by the purchaser and the seller and their lawyers. This step can take time, depending on the value of the transaction and its complexity.

After the contract has been negotiated in its final text, normally, the parties sign it before a notary as a deed. Once again, satisfactory evidence of the powers of the representatives/attorneys of the parties must be provided to the notary.

Further information can be found on the Italian Trade Agency website, at this link, or by contacting us.

Independent bank guarantee in Italy

Is the independent bank guarantee issued under the URDG 758 valid in Italy?

Business clients dealing with international trade frequently asked us whether an independent bank guarantee issued under the URDG 758 (the ICC Uniform Rules for Demand Guarantees 2010) is valid, binding and enforceable under the Italian law or not and, if not, whether and how it can be amended in order to ensure it is valid, binding and enforceable as an independent bank guarantee under the Italian law.

Any major transaction nowadays does not take place without this kind of guaranty support. The principal feature of this kind of guarantee is its autonomy from the principal contract of the transaction.

The guarantee is a contract between a guarantor/bank and the beneficiary and underneath there is always a contractual relationship (the “principal” or “underlying” contract) between a creditor and a debtor which includes the obligation of providing a guarantee in favor of the creditor in case of debtor’s default in performing its obligations.

Its purpose is to indemnify the beneficiary from the possible default of the debtor in the underlying relationship: the beneficiary’s right to claim the payment is to be determined only with reference to the guarantee and the bank has to pay with no right to remedies arising out from the underlying contract.

First demand guarantee

The most used is the “first demand” guarantee which entitles the beneficiary to receive the payment from the bank when the conditions of the guarantee are met, without any proof of the debtor’s default.

Independent guarantee issued under the URDG 758

In general terms, according to the Italian statutory law and Italian Courts’ rulings, an independent guarantee issued under the URDG 758 will be considered a valid, binding and enforceable independent guarantee, provided that it includes a clause binding the guarantor to pay any amount demanded under the guaranty notwithstanding any contestation concerning the underlying contract and by which it waives the right to require exhaustion of remedies against the debtor, any right to withhold performance, any right of retention, any right of avoidance, any right to offset, and the right to assert any other claims which the debtor or any third party may have under the principal contract or in connection with it or on any other grounds (such clause being known as “senza eccezioni”).

Anyway, a deep analysis of the text guarantee is always recommended.

 

DISCLAIMER: This summary is intended for general information purposes only. It is not to be considered accurate, updates, complete or a legal opinion. It is neither an offer nor a binding lawyer / client contract or relationship.