Last updated: 3 August 2026
This Privacy Policy explains how Attorney Francesco Boschetti, with offices at Via dei Gracchi 151, 00192 Rome, Italy, Tax Code BSCFNC77R21H501A, VAT No. 09160721008, email
This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree No. 196/2003, as amended (the “Italian Privacy Code”).
1. Data Controller and Scope of this Privacy Policy
The Data Controller is Attorney Francesco Boschetti, Tax Code BSCFNC77R21H501A, VAT No. 09160721008, with professional offices at Via dei Gracchi 151, 00192 Rome, Italy, email:
The Firm has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR are not met.
This Privacy Policy applies to www.studiolegaleboschetti.com and to all interactions with the Firm, including online contact forms, email correspondence, telephone communications, WhatsApp communications, appointment booking platforms, and video consultations.
Any other websites operated by the Firm are subject to their own separate privacy policies. This Privacy Policy does not apply to third-party websites that may be accessed through links available on this website.
2. Categories of Personal Data Processed
Depending on the services requested, the Firm may process the following categories of personal data:
- Identification and contact data, including name, date and place of birth, nationality, tax identification number, identity document details, postal address, telephone number, and email address;
- Professional, tax, invoicing, and payment information, where necessary for establishing or performing the professional relationship. Payment card information is processed directly by the relevant payment service provider and is not accessible to the Firm;
- Data and documents relating to the legal matter, including civil status records, residence permits, judicial and administrative decisions, powers of attorney, correspondence with public authorities and private entities, and any other documentation relevant to the legal services requested;
- Technical browsing data automatically collected through the website, including IP address, device identifiers, browser type, operating system, date and time of access, pages visited, and system logs;
- Images, voice recordings, and documents shared during video consultations. Video consultations are not recorded, unless the data subject is informed in advance and all applicable legal requirements for recording are satisfied.
Where necessary for the establishment, exercise, or defence of legal claims, or for providing the requested legal assistance, the Firm may also process special categories of personal data pursuant to Article 9 GDPR and personal data relating to criminal convictions and offences pursuant to Article 10 GDPR and Article 2-octies of the Italian Privacy Code.
Data subjects are requested to provide only those documents and personal data that are strictly necessary in relation to their request.
3. Purposes of Processing, Legal Bases and Retention Periods
| Purpose of Processing | Legal Basis | Retention Period |
|---|---|---|
| Responding to requests for information, carrying out a preliminary assessment of a case, preparing fee quotations, and arranging appointments | Performance of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) GDPR) | 12 months from the last contact, unless the engagement is subsequently accepted |
| Performance of the professional engagement and management of the legal matter | Performance of a contract (Article 6(1)(b) GDPR); for special categories of personal data, Article 9(2)(f) GDPR; for criminal data, Article 2-octies of the Italian Privacy Code | For the duration of the engagement and thereafter for 10 years following its termination, including for the purposes of Article 31 of Legislative Decree No. 231/2007 where the engagement is subject to anti-money laundering legislation, without prejudice to any longer retention period required for the establishment, exercise or defence of legal claims |
| Compliance with tax, accounting, anti-money laundering, professional and ethical obligations | Compliance with a legal obligation (Article 6(1)(c) GDPR) | 10 years (Article 2220 of the Italian Civil Code and Legislative Decree No. 231/2007), or for any longer period required by applicable law |
| IT security, prevention of abuse and fraud, and the production of aggregated statistical analyses concerning website usage | Legitimate interests pursued by the Firm (Article 6(1)(f) GDPR) | Technical logs are retained for no longer than 12 months |
| Establishment, exercise or defence of the Firm’s legal rights in judicial or extrajudicial proceedings | Legitimate interests pursued by the Firm (Article 6(1)(f) GDPR) | Until the dispute has been finally resolved and all applicable limitation and appeal periods have expired |
| Sending newsletters, legal updates and promotional communications relating to the Firm’s services | Consent (Article 6(1)(a) GDPR) or, where permitted in relation to existing clients and similar services, Article 130(4) of the Italian Privacy Code (soft opt-in) | Until consent is withdrawn or the data subject objects to the processing |
| Non-essential cookies and other tracking technologies | Consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code) | As specified in the Cookie Policy |
Upon expiry of the applicable retention periods, personal data will be deleted or irreversibly anonymised, unless further retention is required to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
Provision of Personal Data
The provision of personal data is voluntary. However, it is necessary in order to respond to requests, establish and perform the professional engagement, and comply with applicable legal obligations. Failure to provide the requested information may prevent the Firm from providing the requested services.
The provision of personal data for informational and marketing purposes is entirely optional. Refusal to provide such consent will have no adverse consequences.
Data subjects may request further information regarding the balancing test carried out by the Firm in relation to processing activities based on its legitimate interests.
4. Personal Data Relating to Third Parties
In the course of providing legal services, the Firm may also process personal data relating to individuals other than the client, including family members, counterparties, heirs, witnesses, employees, or their representatives.
Such personal data may be provided directly by the client or obtained from public registers, official records, court files, administrative decisions, and other publicly available sources. The client warrants that they are legally entitled to disclose such personal data to the Firm.
Where Article 14 GDPR applies, the information required under that provision will be provided within the applicable time limits, unless doing so proves impossible or would involve a disproportionate effort, or where the personal data must remain confidential pursuant to the legal professional privilege and professional secrecy obligations binding upon lawyers (Article 14(5)(b) and (d) GDPR).
5. Recipients of Personal Data
Personal data are processed by the Firm’s lawyers, trainees, employees and administrative staff who have been duly authorised and instructed pursuant to Article 29 GDPR and Article 2-quaterdecies of the Italian Privacy Code, and who are bound by statutory duties of confidentiality and legal professional privilege.
Personal data may also be disclosed to:
- IT service providers, including hosting providers, cloud service providers, email providers, videoconferencing platforms, CRM systems, law practice management software, appointment booking platforms and newsletter service providers, acting as Data Processors pursuant to Article 28 GDPR;
- professionals and service providers involved in handling the legal matter, including accountants, technical experts, translators, interpreters, licensed private investigators, notaries, local counsel, domiciliary counsel and foreign correspondent law firms;
- judicial and administrative authorities, law enforcement agencies, public authorities, diplomatic missions, consular authorities and social security institutions, where disclosure is required by law or pursuant to an order issued by a competent authority;
- banks, financial institutions and payment service providers for the processing of payments;
- law firms and professional advisers established outside Italy, where necessary for the performance of legal services involving an international element.
Personal data are never disclosed to the public.
6. International Transfers of Personal Data
Some of the Firm’s service providers may process personal data outside the European Economic Area (“EEA”).
Where this occurs, personal data are transferred only where one of the safeguards provided for under Chapter V of the GDPR applies, including:
- an adequacy decision adopted by the European Commission pursuant to Article 45 GDPR;
- the European Commission’s Standard Contractual Clauses (“SCCs”), supplemented, where necessary, by additional technical, organisational or contractual safeguards pursuant to Article 46 GDPR; or
- where applicable and only for occasional transfers, one of the derogations provided for in Article 49 GDPR.
Where service providers are established in the United States, the Firm verifies, where applicable, that they participate in the EU–U.S. Data Privacy Framework.
Data subjects may obtain a copy of the safeguards adopted for international data transfers by contacting the Firm using the details set out in Section 10.
7. Security of Processing
Personal data are processed by electronic, digital and, where necessary, paper-based means in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in the GDPR. The Firm applies the principles of privacy by design and privacy by default throughout its processing activities.
Pursuant to Article 32 GDPR, the Firm implements appropriate technical and organisational measures to protect personal data, including, where appropriate:
- access control and audit logging;
- authentication of authorised users;
- encryption of communications;
- backup and business continuity procedures;
- regular updating of software and IT systems;
- procedures for detecting and managing security incidents;
- periodic staff training on data protection and information security;
- access restrictions based on the need-to-know principle.
Although the Firm adopts appropriate security measures, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure. Data subjects are therefore encouraged to exercise appropriate caution when transmitting personal data electronically.
8. Rights of the Data Subject
Subject to the conditions and limitations provided for by the GDPR, data subjects have the right to:
- obtain confirmation as to whether their personal data are being processed;
- access their personal data and obtain a copy thereof;
- request the rectification of inaccurate or incomplete personal data;
- request the erasure of personal data where the legal requirements are met;
- request the restriction of processing in the circumstances provided for by Article 18 GDPR;
- receive their personal data in a structured, commonly used and machine-readable format and request its transmission to another controller, where applicable (data portability).
Data subjects also have the right:
- to object, on grounds relating to their particular situation, to processing based on the Firm’s legitimate interests;
- to object at any time, without providing any justification, to the processing of personal data for direct marketing purposes;
- to withdraw any consent previously given, without affecting the lawfulness of any processing carried out prior to such withdrawal.
The Firm does not carry out solely automated decision-making, including profiling, producing legal or similarly significant effects within the meaning of Article 22 GDPR.
Requests concerning the exercise of the above rights should be submitted using the contact details provided in Section 10. The Firm will respond free of charge and, as a general rule, within one month of receipt of the request, subject to any extension permitted under Article 12 GDPR.
The exercise of these rights may be restricted, to the extent and for the period strictly necessary, where this is required to avoid actual and concrete prejudice to defensive investigations, the establishment, exercise or defence of legal claims, or where granting access would prejudice legal professional privilege or the rights and freedoms of third parties, in accordance with Article 2-undecies of the Italian Privacy Code.
Without prejudice to any other administrative or judicial remedy, data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it) or with the supervisory authority of the EU Member State in which they habitually reside or work.
9. Cookies, Children and Changes to this Privacy Policy
Cookies
This website uses cookies and similar technologies.
Strictly necessary cookies do not require the user’s consent. Non-anonymised analytics cookies and profiling cookies are activated only with the user’s prior consent, which may be withdrawn at any time through the cookie preference management panel.
Further information is available in the Cookie Policy.
Children
The services offered through this website are not intended for children.
The Firm processes personal data relating to children only in connection with a specific professional engagement and in compliance with the applicable legal framework.
Should the Firm become aware that it has collected personal data relating to a child without a valid legal basis, it will promptly delete such data or otherwise regularise the processing where permitted by law.
Changes to this Privacy Policy
The Firm may update this Privacy Policy from time to time in order to reflect changes in applicable legislation, decisions of supervisory authorities, technological developments, or the introduction of new services.
The current version is always available on this page and indicates the date of the latest update.
Where any amendments materially affect the rights of data subjects, the Firm will provide appropriate notice through suitable means.
10. Contact Details
Attorney Francesco Boschetti
Via dei Gracchi 151
00192 Rome, Italy
Email:
Certified Email (PEC):