Member Voices: Stefano Mele

Published on Sep 3, 2026


 

Stefano Mele  
Upcoming Speaker on Data Protection, Cybersecurity & Technology Regulation 
Gianni & Origoni (Italy) 
Connect on LinkedIn



Briefly describe your role.


I am a Partner at Gianni & Origoni, where I lead the Cybersecurity, Data Privacy & Space Economy Law Department. I advise Italian and international clients on cybersecurity, privacy and data governance, artificial intelligence, and space law, often where these areas intersect with national security. My work includes helping organizations comply with EU and Italian requirements, including the GDPR, the Italian Privacy Code, Network and Information Systems Directive 2 (NIS 2) as implemented in Italy, and the EU AI Act, as well as guiding them through major cyber incidents, including ransomware attacks, and the regulatory, contractual, and reputational issues that follow.


You’ll be speaking during our September 8 virtual session, "Navigating the Evolving Landscape of Data Protection, Cybersecurity & Technology Regulation,” to share the Italian perspective. What developments are having the greatest practical impact on how you advise clients today, particularly as privacy, cybersecurity, and AI regulation continue to evolve?


The most significant change is the move from preparation to implementation. Many of the EU and Italian rules that businesses have spent the past few years preparing for must now be put into practice. In Italy, the implementation of NIS 2 through Legislative Decree No. 138/2024 has brought cybersecurity firmly into the boardroom for organizations within its scope. Management bodies are expected to understand the risk, approve the organization’s approach, and oversee its implementation. Cybersecurity can no longer be treated as a matter for IT or security teams alone. 


Digital Operations Resilience Act (DORA) is prompting a similar shift in the financial sector through a directly applicable EU framework that applies to Italian banks, investment firms, insurers, and other covered financial entities.


At the same time, companies are adopting artificial intelligence at a pace that requires them to consider the EU AI Act alongside the GDPR and the Italian Privacy Code, as well as existing contractual, employment, intellectual property, and cybersecurity rules. This has changed the nature of our advice. The focus is increasingly on practical decisions. Who owns an AI use case? Who accepts residual cyber risk? How are suppliers assessed? When should an issue be escalated internally or reported to the relevant Italian or EU authority? And how can the organization demonstrate that its controls actually work? Clients do not need a separate compliance project for every new regulation. They need a governance structure that allows the different EU and Italian requirements to work together.


Having worked extensively with companies navigating major regulatory frameworks (such as NIS 2, DORA, and the AI Act) as well as with organizations responding to complex cyberattacks, where are you seeing clients encounter the greatest challenges in navigating these increasingly interconnected regulatory requirements across jurisdictions?


Most clients can understand each regulatory framework in isolation. The real difficulty begins when several regimes apply to the same organization, system, or incident. A multinational company may have to reconcile NIS 2 as implemented in Italy and other Member States with DORA, the GDPR, the EU AI Act, and additional Italian national or sector-specific requirements. In Italy, this may also involve engagement with the Italian National Cybersecurity Agency (ACN) and, where personal data is involved, the Italian Data Protection Authority (Garante per la protezione dei dati personali). The definitions, thresholds, reporting procedures, and deadlines do not always align.


This becomes particularly challenging during a cyberattack. The facts are still emerging; business operations may be under pressure; and the company may nevertheless need to assess its notification obligations under the GDPR and applicable cybersecurity rules, including the Italian NIS 2 framework, while also informing insurers and contractual counterparties, preserving evidence, and briefing management bodies across multiple jurisdictions. Legal, cybersecurity, IT, risk, procurement, communications, and business teams must work from the same facts and make decisions in the right order. In my experience, the main problem is rarely a lack of rules. It is the absence of a clear operating model for applying EU and Italian requirements together when time is limited, and the consequences of a mistake can be significant.


You also have a particularly interesting practice in the space economy. What drew you to the legal and regulatory questions surrounding space, and what do you find most compelling about this rapidly developing area?


I was drawn to space law and the legal issues raised by the space economy because, much like cybersecurity law, they lie at the intersection of technology, international law, geopolitics, and national security. Legal questions in this field are also closely connected to scientific progress, economic development, and strategic competition. In Italy and across the EU, these questions are shaped by national space policies, EU space programs, and the growing role of private operators, alongside the international treaties and principles governing outer space activities.


What makes this area especially compelling today is that space-based services have become integral to everyday economic life and to countries’ critical infrastructure. Communications, navigation, financial services, transport, and defense all depend on them, while private operators in Italy, Europe, and elsewhere now carry out activities that were once almost exclusively governmental. This raises complex questions about security, resilience, liability, data governance, dual-use technologies, and the relationship between public authority and private enterprise. It also requires companies to consider how EU and Italian cybersecurity, data protection, and critical infrastructure rules may apply to space-related activities and services. The legal framework is still developing, which gives lawyers both the opportunity and the responsibility to help shape it rather than simply interpret an established one.


Outside of your work, what is something that has been energizing or inspiring you lately?


Outside work, I have recently been enjoying rediscovering Rome on foot. Even after five years in the city, I still come across streets, buildings, and small details that I had never noticed before. Walking without a particular destination gives me time to slow down, clear my mind, and regain perspective after a demanding week. Rome has a way of reminding me that the present is only one layer of a much longer story.