Member Policy

Privacy notice on the processing of personal data pursuant to Art. 13 of EU Regulation 2016/679 (GDPR)

Last updated: July 2026

1. Data Controller

WECANCHANGEIT S.R.L.S.
Manager of the CIO Club Italia® trademark
Via Toledo 156 — 80134 Naples (NA), Italy
VAT no. 09503671217 — SDI: M5UXCR1
Legal Representative: Pasquale Testa
Email: p.testa@cioclubitalia.it

2. Data processed

In connection with the membership relationship, CIO Club Italia processes the following personal data of members:

  • Personal details: first name, last name
  • Contact details: professional email address
  • Professional data: role held (CIO, CTO, IT Manager, etc.), company of employment
  • Payment data: amount of the membership fee (card data is not stored by the association)
  • Data related to participation in events and association initiatives

3. Purposes and legal bases

a) Management of the membership relationship

Registration, renewal, fee management, sending of institutional communications. Legal basis: performance of a contract (Art. 6.1.b GDPR).

b) Newsletter and industry communications

Sending updates, events, networking opportunities. Legal basis: consent (Art. 6.1.a GDPR), revocable at any time.

c) Legal and tax obligations

Data retention for accounting and tax obligations. Legal basis: legal obligation (Art. 6.1.c GDPR).

d) Promotion of the association

Publication of names and professional roles in association materials (e.g. member directory, publications). Legal basis: explicit consent (Art. 6.1.a GDPR).

4. Retention

Data is retained for the entire duration of the membership relationship. Upon termination of the relationship, data is retained for 10 years to comply with tax and accounting obligations (Presidential Decree 600/1973). Data processed on the basis of consent is deleted within 30 days of withdrawal.

5. Data disclosure

Data may be disclosed to:

  • Technical service providers (event platforms, hosting, newsletter) acting as Data Processors
  • The association's accountant and auditor
  • Public authorities in cases provided for by law

Data is not sold or disclosed to third parties for marketing purposes.

6. Rights of the data subject

Members have the right to:

  • Access their data (Art. 15 GDPR)
  • Rectify inaccurate data (Art. 16 GDPR)
  • Obtain erasure, within the limits of legal obligations (Art. 17 GDPR)
  • Restrict processing (Art. 18 GDPR)
  • Object to processing for communication purposes (Art. 21 GDPR)
  • Withdraw consent to the newsletter at any time

To exercise your rights or for any request regarding personal data, write to p.testa@cioclubitalia.it. You may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it.