Privacy

Privacy

Privacy Policy provided pursuant to Articles 13, 14 and 26 of the European General Data Protection Regulation 2016/679 (“GDPR”)

 

1.    WHO PROCESSES PERSONAL DATA?

Data controller
GS1 Italy, with registered office in Via P. Paleocapa n. 7, 20121 Milan (Italy), Fiscal Code 80140330152, represents in Italy GS1 which is the international body that administers and coordinates the correct implementation of the "GS1" system for the coding of products in the consumer goods sector, as well as the "ECR" system relating to the strategic and operational interfacing between industry and distribution and between these entities and the end consumers.
In carrying out its activities, GS1 Italy collects and processes personal data as Data Controller, and, in this capacity, ensures the application of appropriate organisational and technical measures for the protection of personal data in compliance with the provisions of the applicable laws and regulations.

With reference to certain processing operations, as specified below, GS1 Italy may process personal data as joint controller with GS1 Italy Servizi S.r.l., a sole shareholder company wholly owned by GS1 Italy, with registered office in Via P. Paleocapa n. 7, 20121 Milan (Italy), Fiscal Code 06166030962 (hereinafter referred to as "Main Joint Data Controller"), with whom goals and objectives are shared, aimed in particular at offering companies techniques, operational solutions, standards and tools to optimise the efficiency of processes related to the production and distribution system. GS1 Italy Servizi S.r.l. is in fact statutorily in charge of the provision, especially in the interests of GS1 Italy member companies, of services aimed at facilitating the implementation of rules, standards and specifications drawn up by GS1 Italy itself. 
In the light of the reasons of synergy and sharing of resources, the Main Joint Data Controllers may process personal data pursuant to and for the purposes of Article 26 of GDPR, in order to develop commercial and marketing strategies through initiatives, also for promotional purposes and carried out on the basis of the joint controllers’ legitimate interests, aimed at developing and/or consolidating relations with their member companies, customers and, in general, with users and to improve the knowledge of their respective services and products.
The joint control agreement in force between GS1 Italy and GS1 Italy Servizi S.r.l. is published on both parties' websites and is available in its full version for consultation.

With reference to some specific processing operations of personal data which are directly collected in the associative phase of the companies by A.D.M. - Associazione Distribuzione Moderna, with registered office in Via Paleocapa n. 7, 20121 Milan (Italy), Fiscal Code 97364340154 and/or by I.B.C. - Associazione Industrie Beni di Consumo, with registered office in Via Gabrio Serbelloni n. 5, 20122 Milan (Italy), Fiscal Code 97364440152 and VAT No. 09896540961, GS1 Italy may also process this personal data as joint controller with A.D.M. and I.B.C. (as well as with GS1 Italy Servizi S.r.l.) pursuant to and for the purposes of Article 26 of GDPR, for proven reasons of synergy and sharing of resources for the preparatory activities to the establishment of the contractual/associative relationship and for the subsequent execution and management of such relationship and those instrumental and functional activities to its performance, for the fulfilment of any other obligation arising from the contract, as well as for the purpose of being able to develop shared commercial and marketing strategies, through the performance of activities and initiatives, also for promotional purposes and carried out on the basis of the joint controllers’ legitimate interests, aimed at developing and/or consolidating relations with its member companies, customers and, in general, actual and potential users and at improving the knowledge and dissemination of their respective services and products, also in the perspective of the completeness of the service and of the expansion of the range of services offered to end users.
The joint data controller agreements in force between GS1 Italy and GS1 Italy Servizi S.r.l., on the one hand, and I.B.C. or A.D.M., on the other, are published on the parties' websites and are available in their full for consultation.

 

2.    WHICH PERSONAL DATA ARE COLLECTED?

GS1 Italy collects and processes, through a centralised information system, personal data (mainly common personal data relating to the company contacts of its customers and users) such as, by way of example but not limited to, company name, first name, last name, fiscal code/VAT number, email address, professional landline and/or mobile phone number, company name where you work and covered role, IP address used in the possible navigation of the websites managed by and referable to the Data Controller or to GS1 Italy Servizi S.r.l., as well as data related to the commercial and/or professional activity of said company and its contact details (PEC address, legal office address) and bank details (for the payment of the membership fee and/or other fees, where applicable). Images, photos and/or videos of the data subject may also be collected during events or conferences. With respect to the processing of such data, the data subject may receive a supplement to this Privacy Policy and a specific waiver and request for the collection and processing of personal data.

In addition to the provisions of the Data Controller's Cookie Policy, the following data may also be collected and processed through the websites managed by and referable to the Data Controller or to the Main Joint Data Controller, the use of the relevant functionalities, the filling in of electronic forms and the use of services provided therein: 

  • browsing data: this data includes, by way of example, the data that the server automatically records each time the website is visited, such as the IP addresses of the computers used by the users who connect to the website, the URI (Uniform Resource Identifier) addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user's operating system and IT environment. This category of data also includes the "Social Buttons" that exclusively allow the connection and display of the Data Controller and Joint Data Controller social network profiles (created on social networks such as, for example, Facebook, Instagram, YouTube). These "buttons" exclusively allow users who are browsing the website to reach with a "click" the social networks referable to the Data Controller or to joint data controllers. The interactions that take place within the social networks are in any case subject to the rules and privacy settings of the respective social networks. A virtual AI assistant has been set up on the website https://gs1it.org which automatically generates informative answers by processing data and information generally available on the https://gs1it.org website itself. Before interacting with the virtual AI assistant, it is the user’s responsibility to carefully read the Disclaimer about its use and to always verify the accuracy of the information provided. The Disclaimer forms an integral part of this GS1 Italy Privacy Policy, and its use implies the user’s informed consent. In any case, as a general rule, the virtual assistant does not collect users’ personal data, unless the user expressly requests to be recontacted;
  • personal data voluntarily provided by users/visitors: this is data that is provided by users by filling in electronic forms in order to send information or contact requests or, where applicable, for the purpose of creating an account on the websites and/or for requesting, ordering and using the services made available therein. This category includes, by way of example, name and surname, company e-mail address and phone number, company name and covered role, further data and information that may be contained in messages sent to the addresses indicated on the websites or by filling in any electronic forms published therein.

 

3.    ON WHAT LEGAL BASES AND FOR WHAT PURPOSES ARE PERSONAL DATA PROCESSED?

Personal data is processed for the following purposes:


(i)    for the activities preparatory to the establishment of the contractual relationship with GS1 Italy and/or GS1 Italy Servizi S.r.l. as well as of the associative relationship with A.D.M. or I.B.C. for the subsequent execution and management of such relationships and for the activities related and functional to its performance, for the fulfilment of any other obligation arising from the contract, for the management of the websites referable to the Data Controller or the Main Joint Data Controller and of the services rendered through them, as well as to follow up on the request to receive information (Article 6, letter (b), GDPR);
(ii)    for the fulfilment of legal obligations (Article 6 (c), GDPR) or to enforce a right before a competent Authority. The processing of the data may be necessary or required by the fulfilment of obligations arising from the law or from national and/or EU legislation in force and applicable to the Data Controller, as well as from provisions issued by competent authorities and bodies;
(iii)    for statistical and security purposes, including IT security, and to manage requests from data subjects;
(iv)    to handle the process of browsing and collecting data from the Data Controller’s websites and social media platforms;
(v)    for the management of the access of visitors to the premises known as “Interno 1”, located in Milan (Italy), Via Paleocapa 7;
(vi)    to pursue a legitimate interest of the Data Controller (Article 6 (f) GDPR). In the context of relationships with data subjects there is a legitimate interest of Data Controller to process personal data for the legal defence of a right or interest before any competent authority or body, expressly including for debt recovery purposes or to proceed - also as a result of a partly automated, but not intrusive, "profiling" activity, which is proportionate and does not entail any negative or significant consequences for the data subject because it is carried out for statistical purposes and does not mainly concern personal data - to make a direct offer of products or services similar to those which were previously purchased, limited to the e-mail address provided in the context of the contractual relationship and unless the data subject objects to such processing (so-called soft spamming). For the purposes of this data processing, the Data Controller shall consider as “similar services” pursuant to Article 130(4) of Legislative Decree 196/2003, as amended, the services in the broadest sense intended which are provided by the Data Controller and the Main Joint Data Controller to third parties, as they are in any case connected to the GS1 standards.

Specifically, the processing of personal data may also take place, by virtue of a legitimate interest of the Data Controller or the joint data controller, for the purpose of carrying out the following promotional activities


a.    for the sending of invitations and the subsequent management and organisation of data subject possible interest events, meetings, working groups for confrontation and cooperation purposes (such as, by way of example, the participation in the "ECR Italy" working area), events and educational courses, seminars, round tables, conventions and meetings (also aimed at training), organised and managed by the Data Controller and/or the joint data controllers or by third parties, autonomously or in collaboration with third parties from time to time identified in the invitations (brochures and/or presentations) that shall be transmitted or delivered to collect the possible participation (hereinafter referred to as "Event"/"Events");
b.    for the invitation to participate in surveys of various kinds, the creation and sending of newsletters, publications, studies, survey results, market analyses or analyses of specific industrial or commercial sectors, as well as any other kind of informative material, of possible interest, prepared, edited and/or published by the Data Controller and/or the joint data controllers, independently or in collaboration with third parties (hereinafter referred to as "Publications");
c.    to manage relations and interactions with the referents or "contact persons" of member companies, actual and potential clients and any other subjects with whom GS1 Italy and/or GS1 Italy Servizi S.r.l. and/or the further joint data controllers have established associative or contractual/commercial relations, in order to better understand their needs and expectations, improve and develop new services. In order to achieve these purposes, personal data of the "contact persons" will be storage and retained in special databases owned or managed by and/or available to the joint data controllers (in accordance with the specifications set out in the respective joint data controller agreements).

The above initiatives may be managed and implemented by email or in residual cases by telephone. 

With regard to said matters, we remind that the data subject may, at any time, object to the commercial communications received by e-mail and unsubscribe from marketing using the following alternative means: a) by e-mail, by clicking on the appropriate link of “unsubscribe” in the e-mails received, or b) by easily, freely and without cost revoking any consent previously given by sending a communication in the manner set out in the paragraph below "What are the rights under the GDPR?" 

 

4.    WHAT ARE THE SOURCES FROM WHICH PERSONAL DATA IS COLLECTED AND WHAT HAPPENS IN CASE OF FAILURE TO PROVIDE PERSONAL DATA? 

Personal data collected by the Data Controller or by joint data controllers may be provided:


a.    directly by the data subject or by a third party authorised by the data subject;
b.    by one joint data controller to the other joint data controllers;
c.    by providers of electronic communications systems.


The provision of personal data is not mandatory, but it is necessary to enable the management of the contractual relationship and the fulfilment of any legal obligations, with the consequence that failure to provide, partial or incorrect provision of the data will make impossible, as applicable, to fulfil the contractual relationship and to execute the related services and/or to implement and process specific requests made by the data subject. Failure to provide the data may affect the possibility of interacting with the Data Controller for associative or contractual purposes.

 

5.    WHO CAN ACCESS TO PERSONAL DATA?

The following entities may be recipients and may therefore process the personal data collected by the Data Controller in their capacity as autonomous data controllers, joint data controllers, external data processors or persons authorised to process data:

  • GS1 Italy Servizi S.r.l., in its capacity as Main Joint Data Controller, and I.B.C. and A.D.M. in their capacity as joint controllers;
  • employees, outside staff and consultants of the Data Controller and the joint data controllers, as persons authorised to process data pursuant to Article 29 of the GDPR;
  • legal or supervisory authorities, general government and other authorities, public bodies and organisations (domestic and foreign) in fulfilment of regulatory obligations, which will process them as autonomous data controllers;
  • companies, professionals and consultants, appointed by the Data Controller and/or by the joint data controllers to carry out activities related to the management of the organisation and/or the management of professional assignments or the possible defence in court, including, by way of example, auditing and financial statement certification companies, quality surveying and certification companies, banking institutions for the management of payments supervisory and control bodies, accounting and tax consultants, legal consultants, credit recovery and consulting companies, IT assistance and data processing companies (e.g. web hosting, data entry, management and maintenance of IT infrastructures and services, etc.), press offices, postal service and mailing companies; all in their capacity, as applicable, as authorised entities, data processors or autonomous data controllers;
  • Universities and other educational institutions, acting, depending on the circumstances, as authorised entities, data processors or autonomous data controllers;
  • GS1 AISBL (with registered office in Avenue Louise 326, b.10, 1050 Brussels, Belgium), an entity governed by Belgian law which is the world's leading organisation in the definition of standards for the supply chain and is represented in Italy by GS1 Italy, as autonomous data controller, as well as the network of national GS1 Member Organisations (as better identified on the following website https://www.gs1.org/contact/overview/alphabetical) for the possible publication and sharing of data (company name, email address and telephone number of company contact persons) in the global registries (GS1 Registry Platform) where the data is stored and retained. These organisations are all subject to the same privacy compliance obligations;
  • companies providing IT services, cloud infrastructure and similar or related services, acting as external data processors or authorized entities;
  • any partners or contractual party connected or related to the Events or Publications as well as partners in projects referable to GS1 Italy and/or GS1 Italy Servizi S.r.l. and/or to joint data controllers or participants in initiatives managed and coordinated by them (e.g. the Solution Partner Program or similar) as well as third parties carrying out outsourcing activities in the interest of the Data Controller and/or the joint data controllers, for the performance of activities and services functional to the organisation and/or management of the Event or the sending of the Publications; all in their capacity as data processors;
  • subject to prior consent, business partners and trade associations which are third parties in relation to the joint data controllers;
  • in the context of extraordinary transactions, the Data Controller may transfer personal data to third parties within the limits permitted by the applicable legislation.

With reference to the purposes described above, certain personal data may be made accessible through the GS1 Registry Platform as part of the related services rendered.
More generally, any international transfer of personal data to countries outside the European Union and/or the European Economic Area ("EEA") will only take place in compliance with the limits and conditions set forth in the GDPR and, therefore, only to countries that guarantee an adequate level of protection of personal data, where such adequacy is established by a decision of the European Commission or guaranteed on the basis of contractual instruments and specific clauses that ensure the implementation of technical and organisational security measures suitable for the protection of personal data. In any event, personal data will not be disclosed or disseminated, except where they are required and in accordance with the law, to law enforcement, legal authorities, information and security bodies or other public entities and for purposes of defence or State security or for the prevention, detection or prosecution of criminal offences.

 

6.    HOW PERSONAL DATA ARE PROCESSED?

Personal data is processed through electronic and paper-based means and tools made available to persons acting under the authority of the Data Controller and, as applicable, of the joint data controllers who are authorised and trained for this purpose. The paper and electronic archives are protected by adequate security measures to counter the risk of violation.
Specifically, personal data is also processed through the GS1 Registry Platform, which allows GS1 organisations to access to such data.

 

7.    HOW LONG PERSONAL DATA ARE RETAINED?

Personal data processed by the Data Controller is retained for the time necessary to carry out the activities connected to the management of the associative or contractual relationship and for the related legal obligations and, for the period following its termination, for the fulfilment of any obligations necessary for the proper performance of the contractual or business relationship. 
Specifically, the main personal data collected are retained for the following periods (subject to justified extensions):


a)    in the case of the management of a contractual relationship (of any kind and nature), for ten years following its termination or from the time when the rights arising therefrom may be enforced (pursuant to Articles 2935 and 2947 of the Italian Civil Code);
b)    in case of consent granted for commercial purposes, personal data will be retained for a period of two years from the date the consent has been given;
c)    for processing based on the legitimate interest of the Data Controller (or joint data controllers), personal data will be retained for as long as that interest exists and, in any event, provided that there is an existing relationship with the data subject, without prejudice to the data subject’s right to object such processing at any time. Upon termination of the contractual relationship or upon the end of the access to the premises known as “Internal 1”, personal data will be retained for a period of two years commencing: i) from the date of termination of the contract, in the case of a contract of ongoing performance; ii) from the date of completion of the individual purchase transaction, in the case of a contract of one-off performance; or iii) in the case of access to the premises known as “Interno 1” (prior to which the specific check-in procedure has been completed), from the date of the data subject’s last authorised access to “Interno 1”;
d)    for processing involving photographic and audio/video material, for the period specified in the relevant consent form provided to the data subject or, in the absence of such a form, for a period of ten years from the date on which such material has been recorded.
When the purposes justifying the retention of personal data have been fulfilled, such data will be deleted or anonymised.

 

8.    WHAT ARE THE RIGHTS UNDER THE GDPR?

In accordance with the provisions of GDPR, the data subject has the right to:

  • access to personal data, i.e. to obtain confirmation of the existence of the processing of his/her personal data and to obtain specific information on the processing, such as, the purposes, the categories of data being processed and the existence of the other rights set out below;
  • obtain the correction of personal data, i.e. obtaining the rectification/integration of his/her personal data;
  • obtain the cancellation of personal data, i.e. obtaining the deletion of his/her data if (i) such data is no longer necessary for the purposes for which it was collected, (ii) the data subject objects to the processing of his/her personal data and there is no other overriding reasons for the processing, (iii) the personal data must be deleted due to legal obligation. This right does not apply if the processing is necessary for the fulfilment of a legal obligation or for the judicial ascertainment or exercise of a right;
  • obtain the restriction of processing of personal data, i.e. obtaining the restriction of the processing of his/her personal data, which means that data processing will be suspended for a certain period of time;
  • obtain the portability of personal data, i.e. the right to receive personal data in a structured, commonly used and machine-readable format and to transmit them to another data controller in the case of automatic processing based on consent or the performance of contractual obligations;
  • oppose to processing of personal data, i.e. objecting to the processing based on legitimate interest, unless the Data Controller or the joint data Controllers demonstrate the existence of legitimate grounds for processing which prevail on the rights of the data subject;
  • withdrawal of consent, i.e. the right to revoke at any time any consent previously given to the processing of personal data (for commercial or other purposes): the withdrawal of consent does not affect the lawfulness of processing based on consent previously given;
  • lodge a complaint to the competent supervisory authority in the cases provided for in Article 77 of the GDPR. In Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali (http://www.garanteprivacy.it/).

The above-mentioned rights, together with any request for clarification regarding the assessment of the existence of legitimate interest and related soft-spamming activities or the profiling activity, may be exercised by making a request to the Data Controller by writing to the above addresses or by sending an email to privacy@gs1it.org. A reply will be reasonably provided within five working days.
The Data Protection Officer appointed by the Data Controller can be contacted at the following email address:
DPO@gs1it.org.

The updated version of this Privacy Policy can be found on the web page: https://gs1it.org/privacy-policy/
Any amendments or updates will be brought to the user's attention by publication on the mentioned web page of the site and will be applicable and binding from that moment on. For this reason, this privacy policy shows below the date of its most recent update and publication.


[Last update: 15/07/2026]