1. Processing of personal data covered by this policy

This policy is provided – pursuant to Art. 13 of Regulation (EU) No. 2016/679 (hereinafter “GDPR”) and Arts. 13 and 122 of Legislative Decree No. 196/2003 as amended (“Privacy Code”) – to users who, by visiting the website visitsicily.info, provide their personal data explicitly or simply by browsing. The validity of this policy does not extend to other websites that may be reached via hyperlinks present on the site.

By using the site through any device (computer, tablet, smartphone, etc.), users are invited to read this policy in full before providing personal information of any kind.

Processing is carried out in accordance with the principles of lawfulness, fairness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, pursuant to Art. 5 of the GDPR.

2. Parties involved in data processing

Data Controller: Regione Siciliana – Assessorato del Turismo, dello Sport e dello Spettacolo, represented by the Assessore pro-tempore, at Via Notarbartolo n. 9, Palermo.

Email: assessore.turismo@regione.sicilia.it – PEC: assessorato.turismo@certmail.regione.sicilia.it – Tel. 0917078170

D1ata Processor: Dipartimento del Turismo, dello Sport e dello Spettacolo, represented by the Dirigente generale pro-tempore, at Via Emanuele Notarbartolo n. 9, Palermo.

Email: direzione.turismo@regione.sicilia.it – PEC: dipartimento.turismo@certmail.regione.sicilia.it – Tel. 0917078093

Sub-Processor: Dirigente pro-tempore of Servizio 1 – Comunicazione of the Dipartimento del Turismo, dello Sport e dello Spettacolo, at Via Beato Bernardo n. 5, Catania.

Email: servizio1.turismo@regione.sicilia.it – Tel. 0957477415

Technical Sub-Processor: Sicilia Digitale S.p.A., at Via Thaon de Revel 18/20, Palermo.

Email: protocollo@siciliaeservizi.it – PEC: siciliaeservizi@pec.it

Pursuant to Art. 28 GDPR, the parties listed above who process data on behalf of the Controller do so under specific data processing agreements.

3. The Data Protection Officer (DPO)

Information on the Data Protection Officer of the Regione Siciliana is available at: https://www.regione.sicilia.it/privacy/responsabile-protezione-dati

DPO email address: dpo@regione.sicilia.it

4. Types of data processed, purposes and legal basis of processing

4.1 Browsing data

The computer systems and software procedures used to operate the site automatically collect, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. These include, for example: IP addresses, domain names of the devices used, URIs of requested resources, system logs, device type and browser type.

This information is not collected to be associated with identified individuals, but solely to obtain anonymous statistical information on the use of the site and to verify its correct operation.

Legal basis: legitimate interest of the Controller pursuant to Art. 6(1)(f) GDPR, consisting in the need to ensure the correct functioning and security of the site.

4.2 Data voluntarily provided by the user (contact forms)

Through the site, users may send requests and communications to the contact addresses provided. Data entered in forms will be used exclusively to respond to the requests received. Data entered in forms and emails sent to published addresses will be stored only for the time necessary to handle the incoming requests.

Legal basis: consent of the data subject pursuant to Art. 6(1)(a) GDPR and, where applicable, performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR.

4.3 Data of Reserved Area users

Personal data relating to the logs of users registered and authorised to access the Reserved Area of the site are processed. This section is intended for the management of textual content and the modification of design and structural elements of the site (CMS). Data are collected on the CED servers at Sicilia Digitale and stored in accordance with the purposes of the section.

Legal basis: legitimate interest of the Controller pursuant to Art. 6(1)(f) GDPR, for the purposes of service provision and IT security.

4.4 Cookies

The site uses cookies, i.e. small text files sent to the user’s device and stored therein, to be retransmitted to the site on subsequent visits. In accordance with the Guidelines of the Italian Data Protection Authority of 10 June 2021 and Resolution No. 231 of 8 May 2014, the cookies used by the site are classified into the following categories:

  • Strictly necessary technical cookies: essential for the correct functioning of the site and for safe, efficient browsing. They do not require prior consent. They are deleted when the browser is closed (session cookies) or stored for a limited period.
  • Functional cookies: allow the site to remember user preferences (e.g. language) and to use third-party integrated features (e.g. Google Fonts). They require prior consent.
  • Analytical cookies: used to collect aggregate statistical information on the use of the site (number of visitors, pages visited, etc.). If provided by third parties without IP anonymisation, they require prior consent.
  • Profiling and advertising cookies: used to display advertisements in line with preferences expressed during browsing (including Facebook Pixel and DoubleClick/Google tools). They always require explicit prior consent pursuant to Art. 7 GDPR.

Under no circumstances will browsing data collected via technical cookies be used for user profiling.

Users may manage their cookie preferences at any time through the consent panel on the site or by configuring their browser to:

  • accept all cookies;
  • receive notifications when a cookie is sent;
  • reject all or certain categories of cookies.

Disabling technical cookies may impair the correct functioning of the site. Disabling third-party cookies does not affect access to the public part of the site.

For the detailed table of cookies active on the site, please refer to the Cookie Policy downloadable at the bottom of this page.

4.5 Social buttons and social platforms

The site incorporates buttons (social buttons) displaying the icons of the social networks Facebook, X (formerly Twitter), YouTube, Instagram and Pinterest. These buttons allow users to visit the site’s social profiles with a single click. The site does not share any browsing information with these social networks; however, social platforms are set up to acquire data relating to the user’s visit in accordance with their respective privacy policies, available on their respective websites.

4.6 Transfers to third countries

The use of third-party tools such as Facebook Pixel, Google DoubleClick and Google Fonts may involve the transfer of personal data to third countries (in particular the United States of America). Such transfers are carried out in accordance with the safeguards provided for under Arts. 44 et seq. of the GDPR and, where applicable, in compliance with the EU-US Data Privacy Framework adopted by the European Commission with an adequacy decision of 10 July 2023 (C(2023) 4745). For more information on the safeguards adopted by individual providers, please refer to their respective privacy policies.

5. Methods of processing

Data are processed primarily by electronic means and, where necessary, also in paper form, in compliance with the principles set out in Art. 5 of the GDPR, so as to ensure adequate security, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage, through appropriate technical and organisational measures pursuant to Art. 32 of the GDPR.

Based on the data covered by this policy, the Controller will not make any decision through fully automated processing pursuant to Art. 22 GDPR, nor will any automated profiling be carried out.

6. Communication and disclosure of data

Data collected may be processed, for the purposes of this policy, by the parties referred to in point 2 and by the natural persons authorised by them to process data pursuant to Art. 29 GDPR.

Data may be communicated to third parties only in the cases and in the manner provided for by law. Data will not be disclosed.

Third-party service providers (e.g. Sicilia Digitale, Meta Platforms, Google LLC) that process data on behalf of the Controller act as Data Processors pursuant to Art. 28 GDPR, under specific contractual agreements.

7. Data retention

Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the storage limitation principle pursuant to Art. 5(1)(e) GDPR, and in particular:

  • Browsing data and logs: retained as a rule for a maximum of 12 months, unless required for establishing liability in judicial proceedings.
  • Contact form data: retained for the time necessary to respond to the request and, in any case, no longer than 24 months from receipt, unless different legal obligations apply.
  • Reserved Area data: retained for the entire duration of the collaboration and for the subsequent period required by applicable law.
  • Cookies: in accordance with the durations indicated in the detailed table in the Cookie Policy.

Where data are required for any investigation of liability, their deletion is suspended for the necessary time, as required by law.

8. Rights of the data subject

Pursuant to Arts. 15–22 of the GDPR, users may exercise the following rights at any time:

  • Right of access (Art. 15): obtain confirmation as to whether personal data concerning them are being processed and, if so, receive a copy.
  • Right to rectification (Art. 16): obtain rectification of inaccurate or incomplete personal data.
  • Right to erasure (“right to be forgotten”) (Art. 17): obtain the erasure of personal data concerning them, where one of the conditions provided for by the GDPR is met.
  • Right to restriction of processing (Art. 18): obtain restriction of processing in the cases provided for by the GDPR.
  • Right to data portability (Art. 20): receive personal data in a structured, commonly used and machine-readable format, and transmit them to another controller, where technically feasible.
  • Right to object (Art. 21): object at any time to the processing of personal data concerning them on grounds relating to their particular situation, where processing is based on the legitimate interest of the Controller.
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint (Art. 77): lodge a complaint with the Italian Data Protection Authority.

To exercise the above rights, the data subject may send a communication to the Data Controller at one of the addresses given in point 2.

Complaints may be lodged with: Garante per la protezione dei dati personali, Piazza Venezia n. 11, 00187 Roma – email: protocollo@gpdp.it – PEC: protocollo@pec.gpdp.it

The Controller will respond to requests for the exercise of rights without undue delay and, in any event, within one month of receipt of the request, extendable by a further two months in cases of particular complexity, pursuant to Art. 12(3) GDPR.

Last updated: 19/05/2026

Data Controller:

Regione Siciliana

Assessorato Regionale del Turismo, dello Sport e dello Spettacolo

Assessore pro-tempore

On. Elvira Amata