Official Journal of the European Society of Gynecology
eISSN 2710-2580
Privacy Policy
Logo EGO
European Gynecology & Obstetrics
European Society of Gynecology

CONTENTS

  1. Scope and applicability
  2. Identity and contact details of the Data Controller
  3. Categories of data subjects
  4. Personal data processed and purposes of processing
  5. Legal bases for processing
  6. Data retention periods
  7. Recipients of personal data and data processors
  8. International transfers of personal data
  9. Cookies and other tracking tools
  10. Security of personal data
  11. Personal data breaches
  12. Rights of data subjects
  13. How to exercise your rights
  14. Changes to this policy
  15. Relationship to other editorial policies of the Journal
  16. Normative references

 

  1. SCOPE AND APPLICABILITY

1.1  This Privacy Policy describes how Edikta S.r.l., acting in its capacity as Data Controller and as publisher of European Gynecology and Obstetrics (EGO), collects, uses, stores, and otherwise processes personal data in connection with the editorial, publication, and website activities of the Journal.

1.2  This Policy applies to all personal data processed by Edikta S.r.l. in relation to: the submission, peer review, editorial management, and publication of manuscripts; the operation and administration of the Journal's editorial board and guest editorship arrangements; the management of the Journal website (https://egojournal.eu); communications with authors, reviewers, editorial board members, and other stakeholders; and any other activity connected with the publication of the Journal.

1.3  This Policy is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons about the processing of personal data and on the free movement of such data ("GDPR"), and in accordance with Italian Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018 ("Italian Privacy Code").

1.4  This Policy does not govern the processing of personal data of research participants or patients contained within manuscripts submitted to the Journal. That processing is the responsibility of the authors of those manuscripts, who are required to comply with applicable data protection legislation and the ethical standards described in the Research Ethics Policy and the Data Availability and Sharing Policy.

1.5  This Policy is reviewed at least every 2 years or whenever a material change occurs in the data processing activities of the Journal or in applicable legislation.

1.6  In accordance with the principle of data minimization under Article 5.1.c GDPR, Edikta S.r.l. processes only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Data subjects are not required to provide personal data beyond what is strictly necessary for their interaction with the Journal.

  1. IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER

2.1  The Data Controller for the personal data processed in connection with the Journal is:

Edikta S.r.l.

Via della Balduina 311, 00136 Roma, Italy

VAT No.: IT 17666401009

Email: edikta@edikta.it

Website: https://egojournal.eu

2.2  Edikta S.r.l. publishes the Journal on behalf of the European Society of Gynecology, which is the owning society of the Journal.

2.3  Edikta S.r.l. has assessed that the designation of a Data Protection Officer (DPO) is not mandatory under Article 37 GDPR for its current processing activities. Any questions or requests relating to personal data protection, including the exercise of data subject rights under Section 12, should be addressed to: edikta@edikta.it.

2.4  In accordance with Article 30 GDPR, Edikta S.r.l. maintains an internal record of processing activities carried out under its responsibility. This record is not publicly disclosed but is available to the competent supervisory authority upon request.

  1. CATEGORIES OF DATA SUBJECTS

The personal data processed by Edikta S.r.l. in connection with the Journal relate to the following categories of data subjects:

-  (a) Authors - individuals who submit manuscripts to the Journal, including corresponding authors, co-authors, and group authorship representatives.

-  (b) Peer reviewers - individuals invited to review manuscripts submitted to the Journal.

-  (c) Editorial board members and guest editors - individuals serving as Editor-in-Chief, Associate Editors, members of the Editorial Board or Advisory Board, or as Guest Editors of special issues.

-  (d) Website visitors and registered users - individuals who access the Journal website or register an account on the Journal's manuscript management platform.

-  (e) Complainants and reporters - individuals who submit formal complaints, appeals, or reports of potential publication misconduct to the Editorial Office.

-  (f) Correspondents - individuals who contact the Editorial Office for any other purpose not covered by the categories above.

  1. PERSONAL DATA PROCESSED AND PURPOSES OF PROCESSING

4.1  Authors

4.1.1  Edikta S.r.l. processes the following personal data of authors:

-  Full name, institutional affiliation, professional title, and country of residence;

-  Email address and, where provided, postal address and telephone number;

-  ORCID iD and ROR identifier (where provided or requested);

-  Manuscript content as submitted (including cover letter, main text, tables, figures, supplementary files, and revision documents);

-  Submission history, correspondence with the editorial office, reviewer recommendations, and editorial decisions;

-  Declarations of conflict of interest (ICMJE form or equivalent);

-  Declarations regarding authorship contributions (CRediT taxonomy);

-  Funding acknowledgments and grant numbers;

-  Financial information required for any contractually agreed services.

4.1.2  This data is processed for the following purposes:

-  Receiving, processing, and evaluating submitted manuscripts;

-  Managing the peer review process;

-  Communicating editorial decisions (desk rejection, peer review outcome, acceptance, revision requests);

-  Publishing accepted articles and associated metadata (name, affiliation, ORCID iD, abstract, keywords, conflict of interest declaration, and funding information are made publicly available upon publication);

-  Maintaining the integrity of the published scientific record, including post-publication corrections, retractions, or expressions of concern in accordance with the Corrections, Retractions and Expressions of Concern Policy;

-  Registering article metadata and DOIs with Crossref;

-  Depositing articles in digital preservation services (PKP PN, CLOCKSS) and open access repositories (OpenAIRE, Europe PMC) as required by the Open Access Policy;

-  Compliance with applicable legal and contractual obligations.

4.2  Peer reviewers

4.2.1  Edikta S.r.l. processes the following personal data of peer reviewers:

-  Full name, institutional affiliation, professional title, and country of residence;

-  Email address;

-  Subject area expertise and publication history (used to assess suitability for review assignments);

-  Conflict of interest declarations in relation to specific manuscripts;

-  Review history with the Journal, including dates of review invitations, acceptance or decline, and submission of review reports;

-  Review reports and associated editorial correspondence.

4.2.2  This data is processed for the following purposes:

-  Identifying and inviting suitably qualified reviewers;

-  Managing the double-anonymized peer review process in accordance with the Peer Review Policy;

-  Maintaining reviewer acknowledgment records (published annually on the Journal website);

-  Detecting conflicts of interest;

-  Maintaining the integrity of the peer review process.

4.2.3  Reviewer identities are not disclosed to authors without the reviewer's explicit consent. Review reports are treated as confidential editorial communications.

4.3  Editorial board members and guest editors

4.3.1  Edikta S.r.l. processes the following personal data of editorial board members and guest editors:

-  Full name, institutional affiliation, professional title, country of residence, and biographical information;

-  Email address and, where applicable, postal address;

-  ORCID iD (where provided);

-  Annual conflict of interest declarations (ICMJE form);

-  Correspondence relating to editorial duties;

-  Performance review data (in accordance with the Editorial Board Charter of the Journal).

4.3.2  This data is processed for the following purposes:

-  Administering the editorial board and assigning manuscripts for editorial handling;

-  Publishing editorial board information on the Journal website (name, affiliation, country, and ORCID iD are made publicly available);

-  Managing conflict of interest compliance;

-  Conducting annual editorial performance reviews.

4.4  Website visitors and registered users

4.4.1  Edikta S.r.l. processes the following data in connection with the Journal website:

-  Technical data automatically collected when visiting the website: IP address, browser type, device type, operating system, pages visited, date and time of visit, referring URL;

-  Account registration data entered by users of the manuscript management platform (OJS): username, password (in encrypted form), email address, affiliation, and any other information entered voluntarily in the user profile.

4.4.2  This data is processed for the following purposes:

-  Ensuring the technical functionality and security of the website;

-  Producing aggregate usage statistics for published content by means of records held on the servers of the Journal, without the use of third-party analytics tools;

-  Managing user accounts on the manuscript management platform.

4.5  Complainants and reporters

4.5.1  Where individuals submit formal complaints, appeals, or misconduct reports to the Editorial Office, the personal data contained in such communications, including the identity of the reporter where disclosed, is processed exclusively for the purposes of investigating and resolving the matter, in accordance with the Complaints, Appeals and Whistleblowing Policy, in particular its Section 15 (Confidentiality, anonymity, and data protection) and Section 16 (Anti-retaliation provisions and protection of reporters).

4.5.2  Access to data relating to complaints and misconduct investigations is strictly limited to the persons directly responsible for the examination of the submission. No person involved in the investigation may disclose the reporter's identity to the respondent or any third party without the reporter's express and documented consent, except as required by a competent judicial or regulatory authority pursuant to a binding legal obligation. No reporter who submits a good-faith complaint, appeal, or misconduct report is subjected to any form of retaliation or professional disadvantage as a consequence of such submission, in accordance with the anti-retaliation provisions of the Complaints, Appeals and Whistleblowing Policy, Section 16.

  1. LEGAL BASES FOR PROCESSING

All processing of personal data by Edikta S.r.l. is carried out on one or more of the following legal bases under Article 6 GDPR:

Processing activity

Legal basis (GDPR)

Manuscript submission and peer review management

Art. 6.1.b - processing necessary for the performance of a contract to which the data subject is party, or to take steps at their request before entering into a contract

Publication of articles and associated metadata

Art. 6.1.b - performance of the publishing agreement; Art. 6.1.f - legitimate interest of the Journal in maintaining an accurate and accessible scientific record

Long-term retention of submission records for research integrity purposes

Art. 6.1.f - legitimate interest in protecting the integrity of the published scientific record

Editorial board administration

Art. 6.1.b - performance of the service relationship; Art. 6.1.f - legitimate interest in the governance of the Journal

Compliance with tax and accounting obligations

Art. 6.1.c - compliance with a legal obligation

Essential website and platform functionality (technical cookies; see the Cookie Policy of the Journal)

Art. 122.1 of the Italian Privacy Code (exemption from the consent requirement) and Art. 6.1.f GDPR - legitimate interest in ensuring the technical operation and security of the website and of the manuscript management platform

Processing of sensitive personal data, where applicable

Art. 9.2.a (explicit consent) or Art. 9.2.j (scientific research purposes under Article 89 GDPR), where applicable

  1. DATA RETENTION PERIODS

Personal data processed by Edikta S.r.l. is retained for no longer than necessary for the purposes for which it was collected, in accordance with the storage limitation principle (Article 5.1.e GDPR).

Category of data

Retention period

Rationale

Accepted and published manuscripts - author data linked to publication

Indefinite

Integrity of the scientific record; publicly accessible via published article

Rejected manuscript data (submission files, review correspondence)

5 years from final rejection decision

Research integrity and potential appeals; aligned with COPE guidance

Peer reviewer data - review history and reports

10 years from completion of review

Research integrity purposes; aligned with leading publishers' practice

Editorial board member data (active)

Duration of mandate plus 2 years

Operational and governance purposes

Editorial board member data (inactive)

5 years after end of mandate

Historical governance record

Website usage records held on the servers of the Journal

12 months

Security and technical operations of the service; no third-party analytics tools are used. Retention periods applicable to cookies are set out in the Cookie Policy of the Journal.

OJS user account data

Duration of active account plus 3 years after last login

Platform administration

Tax and accounting records

10 years

Italian law (art. 2220 Civil Code; D.P.R. 600/1973)

Complaint and misconduct investigation records

10 years from closure of the case

Research integrity and potential legal proceedings

       7. RECIPIENTS OF PERSONAL DATA AND DATA PROCESSORS

7.1  Personal data processed by Edikta S.r.l. may be shared with the following categories of recipients:

(a) Data processors acting on behalf of Edikta S.r.l. - entities that process personal data solely on the instructions of Edikta S.r.l. pursuant to written data processing agreements compliant with Article 28 GDPR:

-  Quoll (Italy) - website hosting and server infrastructure provider;

-  Public Knowledge Project (PKP) - developer and support provider for the OJS manuscript management platform;

-  Clarivate Analytics / Editorial Manager (USA) - manuscript submission and peer review management system, used on a transitional basis for submissions received before the migration to OJS (Vol. 1/2026 only);

-  Crossref (USA) - DOI registration and metadata services;

-  PKP Private LOCKSS Network (PKP PN) and CLOCKSS - digital preservation services;

-  OpenAIRE and Europe PMC - open access repository deposit services.

(b) Independent data controllers - entities that receive personal data and process it for their own purposes under their own privacy policies:

-  European Society of Gynecology (ESG) - as the journal's owning society, may receive aggregate or anonymized reporting data; any sharing of personal data with ESG is subject to a separate agreement;

-  ORCID and ROR - where authors or editors provide their identifiers and consent to linkage;

-  Supervisory authorities - where disclosure is required by law.

7.2  Personal data is not sold, rented, or disclosed to third parties for commercial or marketing purposes.

  1. INTERNATIONAL TRANSFERS OF PERSONAL DATA

8.1  The primary hosting infrastructure for the Journal website and manuscript management platform is located in Italy, within the European Economic Area (EEA). No transfer of personal data outside the EEA is associated with these services, nor with the cookies described in the Cookie Policy of the Journal.

8.2  The following services involve the transfer of personal data to third countries outside the EEA:

(a) Editorial Manager (Clarivate Analytics, USA):

Editorial Manager is used on a transitional basis to manage submissions received before the Journal's full migration of the editorial workflow to OJS. Clarivate Analytics operates this system with servers located in the United States. Transfers to this system are carried out in accordance with the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46.2c GDPR.

(b) Crossref (USA):

Article metadata, including author names, affiliations, and ORCID iDs, is transmitted to Crossref for DOI registration. Crossref is a not-for-profit organization; transfers are carried out in accordance with Standard Contractual Clauses.

8.3  Upon completion of the full transition to OJS, the use of Editorial Manager will be discontinued and the associated international transfer will cease. This Policy will be updated accordingly.

  1. COOKIES AND OTHER TRACKING TOOLS

9.1  The Journal uses technical cookies only. Cookies are classified as technical where they are used for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or where they are strictly necessary to provide a service explicitly requested by the user, within the meaning of Article 122.1 of the Italian Privacy Code and Article 5.3 of Directive 2002/58/EC.

9.2  The following table lists every cookie placed on the terminal equipment of the user, both on the public pages of the Journal website and on the manuscript management platform:

Name

Category

Provider and party

Purpose

Duration

Consent

OJSSID

Technical

Edikta S.r.l. - first party

Stores the user session identifier and enables navigation, authentication, and access to the reserved areas of the manuscript management platform. It is set with the HttpOnly and Secure attributes and stores no personal data other than the session identifier.

Session, extended to a maximum of 30 days where the user selects the option to remain signed in

Not required

9.3  The legal basis for the use of the cookie listed in Section 9.2 is Article 122.1 of the Italian Privacy Code, which exempts from the consent requirement any cookie strictly necessary to provide a service explicitly requested by the user, read together with Article 6.1.f GDPR, namely the legitimate interest of Edikta S.r.l. in ensuring the technical operation and the security of the Journal website and of the manuscript management platform.

9.4  The Journal does not use analytics cookies or analytics tools operated by third parties, does not use profiling cookies, does not construct user profiles, does not carry out behavioral advertising, and does not perform cross-device analysis of user behavior. It does not use social media plug-ins, embedded social sharing widgets, tracking pixels, tracked URLs, web beacons, software development kits, device fingerprinting techniques, browser local storage or session storage. No script supplied by a third party is loaded by the Journal website or by the manuscript management platform.

9.5  Usage statistics relating to the published content of the Journal are generated from records held on the servers of the Journal and from the statistical functions native to the manuscript management platform. Those functions operate without placing any cookies on the user's terminal equipment or transmitting information to third parties.

9.6  Because only technical cookies are used, no consent banner is displayed. This is consistent with paragraph 7.1 of the Italian Data Protection Authority's guidelines of 10 June 2021, according to which, where only technical cookies or analogous tools are used, information about them may be provided in the general information notice without the need to display a banner that the user must dismiss. The absence of a banner is a consequence of the configuration described in Sections 9.2 and 9.4, and not a derogation from the consent requirement.

9.7  Should the Journal introduce any cookie or tracking tool other than a technical one, that tool will not be placed on the terminal equipment of any user before a consent mechanism satisfying the requirements set out in Section 8 of the Cookie Policy of the Journal has been implemented and both that Policy and this Policy have been updated. Such an introduction constitutes a material change within the meaning of Section 14.2.

9.8  The user may configure the browser to block or delete cookies, in whole or by category. Blocking or deleting cookies prevents authentication on the manuscript management platform and may impair certain functions on the Journal website, while reading the Journal's published content remains unaffected. Instructions from the suppliers of the most widely used browsers are listed in the Journal's Cookie Policy.

9.9  No transfer of personal data outside the European Economic Area takes place in connection with the cookie listed in Section 9.2. The information it contains is processed by Edikta S.r.l. and by the supplier of the Journal's hosting and platform services, appointed as data processor pursuant to Article 28 GDPR, and is retained for the duration stated in that table.

9.10  The Cookie Policy of the Journal constitutes the extended information notice referred to in the guidelines of the Italian Data Protection Authority of 10 June 2021, sets out the classification criteria adopted, and is available at https://egojournal.eu/legal/cookie. In respect of cookies and other tracking tools, the provisions of that Policy prevail over this Policy.

  1. SECURITY OF PERSONAL DATA

10.1  Edikta S.r.l. implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with Article 32 GDPR and taking into account the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.

10.2  Measures in place include, but are not limited to: encrypted connections (HTTPS/TLS) for all data transmitted to and from the Journal website and manuscript management platform; access controls and role-based access management limiting access to personal data to authorized personnel strictly on a need-to-know basis; multi-factor authentication (MFA) for administrative access to the Journal's editorial systems, where technically supported by the platform; periodic review of access rights to ensure that authorizations remain appropriate and proportionate; regular software updates and security patches applied to the hosting infrastructure and OJS platform; secure storage of passwords in hashed form using current cryptographic standards.

10.3  Edikta S.r.l. requires all data processors acting on its behalf to implement equivalent security measures, as set out in the written data processing agreements concluded pursuant to Article 28 GDPR.

  1. PERSONAL DATA BREACHES

11.1  In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, Edikta S.r.l. will notify the competent supervisory authority (the Italian Garante per la protezione dei dati personali) within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.

11.2  Where a breach is likely to result in a high risk to the rights and freedoms of the affected data subjects, Edikta S.r.l. will communicate the breach to the affected individuals without undue delay, in accordance with Article 34 GDPR, unless one of the exceptions provided in that Article applies.

11.3  All actual or suspected personal data breaches must be reported immediately to edikta@edikta.it.

  1. RIGHTS OF DATA SUBJECTS

In accordance with Chapter III GDPR, data subjects whose personal data is processed by Edikta S.r.l. in connection with the Journal have the following rights:

-  (a) Right of access (Art. 15 GDPR) - the right to obtain confirmation as to whether personal data concerning them is being processed and, if so, to receive a copy of that data and information about the processing.

-  (b) Right to rectification (Art. 16 GDPR) - the right to obtain correction of inaccurate personal data and completion of incomplete personal data.

-  (c) Right to erasure (Art. 17 GDPR) - the right to obtain erasure of personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected. This right is subject to limitations where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defense of legal claims, or for the performance of a task carried out in the public interest, including the maintenance of the integrity of the scientific record.

-  (d) Right to restriction of processing (Art. 18 GDPR) - the right to obtain restriction of processing in certain circumstances, including while the accuracy of the data is contested or an objection to processing is pending.

-  (e) Right to data portability (Art. 20 GDPR) - the right to receive personal data provided to Edikta S.r.l. in a structured, commonly used, and machine-readable format, where processing is based on consent or on a contract.

-  (f) Right to object (Art. 21 GDPR) - the right to object to processing based on the legitimate interests of the Data Controller (Art. 6.1.f GDPR). Upon receipt of an objection, Edikta S.r.l. will cease processing unless it can demonstrate compelling legitimate grounds that override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.

-  (g) Right to withdraw consent (Art. 7.3 GDPR) - where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. No processing carried out via cookies is currently based on consent, as stated in the Journal's Cookie Policy.

-  (h) Right not to be subject to automated decision-making (Art. 22 GDPR) - Edikta S.r.l. does not use automated decision-making, including profiling, in a manner that produces legal or similarly significant effects on data subjects.

-  (i) Right to lodge a complaint (Art. 77 GDPR) - the right to lodge a complaint with the competent supervisory authority.

The competent supervisory authority for complaints under (i) is:

Garante per la protezione dei dati personali

Piazza Venezia 11, 00187 Roma, Italy

Tel.: +39 06 696771

Email: garante@gpdp.it

Website: https://www.garanteprivacy.it

  1. HOW TO EXERCISE YOUR RIGHTS

13.1  Requests for the exercise of any of the rights listed in Section 12 should be submitted in writing to: edikta@edikta.it

13.2  The request should include sufficient information to identify the data subject and the specific right being exercised. Edikta S.r.l. may request additional information to verify the requester's identity before processing the request.

13.3  Edikta S.r.l. will respond to requests without undue delay and in any event within 1 month of receipt of the request. This period may be extended by a further 2 months where the request is complex or numerous, in which case the data subject will be informed of the extension and the reasons for it within 1 month of receipt of the request, in accordance with Article 12.3 GDPR.

13.4  Where requests are manifestly unfounded or excessive, Edikta S.r.l. reserves the right to charge a reasonable fee or refuse to act on the request, and will state the reasons for doing so.

13.5  Responses and data provided in response to access requests will be provided free of charge for the first copy. Subsequent copies may be subject to a reasonable administrative fee.

  1. CHANGES TO THIS POLICY

14.1  Edikta S.r.l. may update this Policy from time to time to reflect changes in its data processing activities, applicable legislation, or regulatory guidance. The date of the most recent update is stated beneath the title of this Policy.

14.2  Material changes to this Policy will be communicated to data subjects via a notice on the Journal website and, where appropriate and feasible, by direct notification to affected individuals. Where changes require a new legal basis or significantly affect the rights of data subjects, Edikta S.r.l. will obtain fresh consent where required.

14.3  The current version of this Policy is always available at: https://egojournal.eu/legal/privacy

  1. RELATIONSHIP TO OTHER EDITORIAL POLICIES OF THE JOURNAL

15.1  This Policy governs the processing of personal data by Edikta S.r.l. in its capacity as Data Controller and publisher of the Journal. It does not govern the processing of personal data of research participants within submitted manuscripts, which is the responsibility of authors and is addressed in:

-  Research Ethics Policy, in particular Section 19 (Data protection in research);

-  Data Availability and Sharing Policy, in particular Section 19 (GDPR provisions applicable to data sharing).

15.2  Processing of personal data in the context of conflict of interest declarations is further addressed in the Conflict of Interest Policy.

15.3  Processing of personal data in the context of misconduct investigations, complaints, and whistleblowing is further addressed in the Corrections, Retractions and Expressions of Concern Policy, the Complaints, Appeals and Whistleblowing Policy, in particular its Section 15 (Confidentiality, anonymity, and data protection) and Section 16 (Anti-retaliation provisions and protection of reporters), and the Conflict of Interest Policy.

15.4  Processing of personal data in the context of artificial intelligence tools is further addressed in the Artificial Intelligence Policy.

15.5  The use of cookies and other tracking tools is governed by the Cookie Policy, which forms part of the same cluster of this editorial policy framework and constitutes the extended information notice required by the guidelines of the Italian Data Protection Authority of 10 June 2021.

15.6  The Terms of Use govern access to and use of the Journal website.

  1. NORMATIVE REFERENCES

-  Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation - GDPR): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

-  Italian Legislative Decree No. 196 of 30 June 2003 (Privacy Code), as amended by Legislative Decree No. 101 of 10 August 2018, in particular Article 122

-  Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 (ePrivacy Directive), as amended by Directive 2009/136/EC, in particular Article 5.3

-  Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequacy of the EU-US Data Privacy Framework

-  European Data Protection Board (EDPB) Guidelines 05/2020 on consent under Regulation 2016/679 (adopted 4 May 2020)

-  European Data Protection Board (EDPB) Guidelines 2/2023 on the technical scope of Article 5.3 of the ePrivacy Directive (adopted 7 October 2024)

-  EDPB Guidelines 1/2026 on the processing of personal data for scientific research purposes (adopted 15 April 2026 - currently under public consultation; will be incorporated upon finalization)

-  Italian Garante per la protezione dei dati personali - Linee guida cookie e altri strumenti di tracciamento (10 giugno 2021)

-  DOAJ Transparency and Best Practice Checklist (2024)

-  COPE Core Practices (2024 edition)